The Office of the Comptroller of the Currency (OCC), Board of Governors of the Federal Reserve System, Federal Deposit Insurance Corporation (FDIC) and the National Credit Union Administration (NCUA) – together, the agencies – recently released proposed guidance on third-party risk management practices for banking organizations and credit unions. If finalized, the proposal would rescind and replace the 2023 Interagency Guidance on Third-Party Relationships: Risk Management (2023 guidance) along with related supplemental resources. Comments are due by November 16, 2026.
Noting that the 2023 guidance has often been “interpreted in an overly broad manner and with an insufficient focus on tailoring its risk management principles,” the agencies proposed revised guidance that would focus third party oversight on risk identification and assessment instead of the category of activity involved.
2023 guidance
Issued by the Federal Reserve, FDIC and OCC, the 2023 guidance sets out risk management principles for banking organizations to apply across all stages of a third-party relationship – planning, due diligence and selection, contract negotiation, ongoing monitoring and termination – together with governance topics, such as board and management oversight, independent reviews and documentation. The guidance called for risk management practices scaled to each institution’s “size, complexity, and risk profile and the nature of the third-party relationship.” It also directed banks to apply more stringent oversight to relationships supporting “critical activities,” i.e. activities that could pose significant risk if the third party failed to meet expectations, have significant customer impacts, or significantly affect the institution’s financial condition or operations.
Proposed guidance
The proposed guidance, which the NCUA joined, moves away from the 2023 guidance’s “critical activities” framework, toward a broader risk-tiering approach that assesses risk based on the magnitude and likelihood of harm stemming from a third-party relationship. The agencies emphasized that the updated guidance is designed to be less prescriptive and to encourage relationships with innovative third parties by moving from risk elimination to risk management.
In that vein, the guidance introduces a “residual risk acceptance” concept, which states that institutions are not expected to eliminate all third-party risk and may accept risk that remains after mitigation, including where mitigation is not practicable, consistent with the institution’s risk appetite and tolerances. It also condenses the prior guidance’s detailed, lettered list of due diligence factors into a shorter description of factors to consider. Finally, the proposal adds an express statement that the guidance is nonenforceable, meaning that deviation from the guidance or its examples would not, on its own, support supervisory action. However, the agencies could still act on violations of law, unsafe or unsound practices, or other material risks tied to inadequate third-party risk management.
What’s next
Alongside the proposed guidance, the FDIC, Federal Reserve and OCC issued a joint statement addressing community banks’ engagement with core service providers – the third parties that provide the critical systems and infrastructure supporting a bank’s essential functions, such as payments processing, online banking and compliance. The statement outlines factors the agencies will weigh in supervisory and enforcement decisions relating to core providers. These factors include:
- The level of transparency exhibited by third-party service providers, such as in responding to bank diligence requests and disclosure of incidents.
- Contract terms that may hinder bank oversight and/or negotiating power.
- Investment in technology and data security.
The statement also notes that core providers may qualify as “institution-affiliated parties” under the Federal Deposit Insurance Act and could be held liable for the practices or violations of a bank.
Separately, the Federal Reserve is seeking comment on a proposed third-party risk management guide specifically for community banks with less than $30 billion in assets, intended to serve as a companion resource to the interagency proposed guidance and to focus on risks related to operational and financial resiliency and information security. Comments on that guide are due by November 16.
Banks and credit unions may consider reviewing their risk management practices to shift focus from evaluating risks based on the type of services provided by third parties to assessing the actual likelihood and severity of harm each relationship could cause.
They may also consider submitting comments on the proposal to identify potential issues or gaps in the guidance, including, for example, a list of specific characteristics that the agencies view as indicative of a high-risk relationship.