Prudential regulators propose revised third-party risk management guidance, issue core provider statement
On September 11, the FDIC, the Fed, the OCC and the NCUA requested comment on proposed guidance to assist banks and credit unions in managing risks associated with third-party relationships. The proposed guidance, which the agencies say takes a “principles-based” approach and is non-binding, would replace the 2023 interagency third-party risk management framework (previously covered by InfoBytes here) and its supplemental resources upon finalization.
The agencies said the 2023 framework had frequently been interpreted in an “overly broad” and prescriptive manner, incentivizing “check-the-box” exercises rather than risk-based oversight tailored to individual institutions. According to the proposal, banks reported difficulties understanding which of the 2023 framework’s considerations applied to specific contexts, such as relationships with fintechs versus other types of vendors. The proposed guidance emphasizes risk identification and assessment as the foundation of third-party risk management, enabling the focus on more principles-based risk management and encouraging institutions to align oversight with the assessed risk levels of each relationship and the institution’s size, complexity and risk profile. The guidance also aims to encourage “responsible innovation” by removing language that may have “unduly impede[d]” banks from partnering with fintechs. Comments are due by November 16.
Separately, the FDIC, the Fed and the OCC issued a joint statement on community banks’ engagement with core service providers — third parties that provide the critical systems and infrastructure supporting a bank’s essential functions. The statement outlined factors the agencies will consider in making supervisory and enforcement decisions related to core providers, including the provider’s transparency in sharing due diligence information, contract features that may impede a bank’s ability to exit or supplement a relationship, and the provider’s technological investments and capabilities. The agencies noted that core providers may qualify as “institution-affiliated parties” under the FDI Act and could be held liable for the practices or violations of a bank.
Additionally, the Fed separately requested comment on a proposed third-party risk management guide specifically for community banks with less than $30 billion in assets, intended to serve as a companion to the proposed interagency guidance and focus on specific risks related to operational and financial resiliency and information security. Comments on the guide must be submitted by November 16.