
On a Friday morning in July 2024, a single software update, pushed by a single vendor, applied automatically across customer environments, took the operational layer of more financial institutions offline simultaneously than any single bank failure in modern history. Airports stopped boarding. Hospitals reverted to paper. Customer service platforms inside Asian banks went dark for hours.
The CrowdStrike outage was resolved within days. The lesson it taught was not.
After fifteen years inside risk functions across Indonesian banking, insurance, and multifinance, I have come to believe the most consequential systemic risk in ASEAN’s financial system is no longer the one our supervisors are best equipped to assess. It is what I think of as the outsourced perimeter, the operational layer that used to live inside an institution and now lives at a vendor, sometimes several layers of vendors deep. The next significant financial disruption in this region is more likely to begin outside an institution than inside one.
The shift that quietly happened
For most of the last century, banks ran themselves on infrastructure they owned. Core banking systems sat in their own data centres. Risk models ran on internal servers. Compliance reporting was assembled by internal teams.
That stopped being true in the last decade. Modernisation, driven by cost, talent scarcity, and regulatory pressure to digitise, moved successive operational layers outside the institution. Core banking platforms migrated to cloud-hosted vendors. Risk and compliance tooling moved to SaaS. Identity verification, fraud detection, customer onboarding, AI capabilities, even some second-line functions now sit inside third-party systems.
Each migration looked sensible in isolation. The aggregate is something the institutions and their supervisors are still catching up to.
What concentration looks like in 2026
Three layers of the ASEAN financial stack now show concentration severe enough to matter.
Cloud infrastructure. The major financial institutions across Indonesia, the Philippines, Vietnam, Thailand, and Malaysia run their critical workloads on a small number of hyperscale cloud providers. If any single provider experiences a regional outage, a meaningful share of the financial sector goes with it.
Identity and verification rails. Customer onboarding and identity checks across ASEAN financial services flow through a handful of regional and global vendors. The failure of one, operational or commercial, would prevent new account openings and customer due diligence refreshes across multiple institutions simultaneously.
AI and intelligence services. As generative AI moves into credit decisions, fraud detection, and customer service, an increasing share of those workloads is served by a small number of foundation model providers. Most institutions cannot run their AI systems if those upstream providers are down.
Why this is more dangerous than people think
Three risk vectors compound.
Cascading correlation. The vendors financial institutions depend on are often the same vendors other critical sectors depend on. The same cloud provider that hosts an Indonesian bank also hosts the hospital network, the payment switch, and the government identity service. A failure does not just affect financial services. It affects the systems financial services depend on to function.
Limited substitutability. The migration paths off a major cloud provider, a core banking vendor, or an identity rail are measured in years, not weeks. The lock-in is structural. Institutions cannot reroute around a failing vendor in real time the way they can re-paper a syndicated loan or call in a backup credit line.
Asymmetric oversight. Banks are stress-tested. Insurers are stress-tested. Their critical vendors are not, at least not by anyone supervising the financial sector. The vendor sits one regulatory step removed from the supervisor that ultimately bears the consequences of its failure.
What is starting to work
A few institutions are responding ahead of regulation.
Multi-cloud architectures. The largest Indonesian banks now run mission-critical workloads across at least two hyperscale providers, with automated failover. The cost is high. So is the alternative.
Vendor stress testing. Some risk committees have begun running tabletop exercises against vendor failure scenarios — what happens if our identity provider goes down for forty-eight hours? What happens if our core banking vendor announces a price increase we cannot absorb? — and identifying the gaps in their continuity plans before they appear in production.
Concentration disclosure to boards. The institutions that handle this best require their CIOs and CTOs to report quarterly on vendor concentration in the critical operational stack. The number alone is often clarifying.
What regulators should be doing
Three actions would meaningfully reduce systemic exposure.
Define critical third parties. Supervisors in ASEAN should formally designate the vendors whose failure would have systemic consequences, and bring them inside the supervisory perimeter, much as the United Kingdom’s Critical Third Parties regime under the Financial Services and Markets Act 2023 has done for the UK financial system.
Also Read: Finance doesn’t have a math problem, it has an ego problem.
Require concentration disclosure. Institutions should disclose, in regulatory filings, the share of critical operational workload running through each major vendor. The information would surface concentration that is currently invisible.
Stress-test the dependencies. Annual supervisory stress tests already model credit shocks, liquidity shocks, and market shocks. They should now model vendor shocks, the operational impact of a major cloud, identity, or AI provider becoming unavailable for forty-eight to ninety-six hours.
The macro stakes
ASEAN’s financial system has spent the last decade moving its operational infrastructure outside the institutions themselves. That migration was rational. It has also produced a regional financial sector whose stability now depends on a small number of vendors, most headquartered outside the region, and none supervised by the regulators that bear the consequences of their failure.
The next significant financial disruption in ASEAN is unlikely to look like 1997, or 2008, or any of the crises the region’s supervisors have spent decades preparing for. It is more likely to look like a Friday morning when a vendor most customers had never thought about pushed a bad update, and the consequences cascaded across the institutions that depended on it.
The window to build the supervisory infrastructure for that scenario is closing, not opening.
—
Editor’s note: e27 aims to foster thought leadership by publishing views from the community. You can also share your perspective by submitting an article, video, podcast, or infographic.
The views expressed in this article are those of the author and do not necessarily reflect the official policy or position of e27.
Join us on WhatsApp, Instagram, Facebook, X, and LinkedIn to stay connected.
The post Why concentration disclosure is key to ASEAN’s financial stability appeared first on e27.
