US Banks Face New Vendor Risk Guidance

Four US financial regulators have proposed new third-party risk management guidance aimed at helping banks and credit unions tailor vendor oversight to the actual risks posed by individual third-party relationships.

The proposal was issued by the Office of the Comptroller of the Currency (OCC), Federal Reserve, Federal Deposit Insurance Corporation (FDIC) and National Credit Union Administration (NCUA). It would replace the interagency guidance issued in 2023. Public comments are due by November 16, 2026.

The proposed framework responds to supervisory experience suggesting that the 2023 guidance was sometimes applied too broadly. Banks reportedly struggled to determine which considerations were relevant to different types of relationships, including core service providers, fintech partners and facilities vendors. Regulators also found that some institutions interpreted the earlier guidance as requiring heightened oversight across third parties regardless of their actual risk.

Four-Part Risk Framework

The proposed guidance organises third-party risk management around four areas:

  • Risk identification and assessment
  • Risk oversight
  • Residual risk acceptance
  • Governance

The central principle is that the intensity of due diligence, contractual controls and ongoing monitoring should correspond to the reasonably assessed risk level of each third-party relationship. Banks should also consider their own size, complexity and risk profile.

The regulators emphasise that there should be no one-size-fits-all approach. A critical cloud or core banking provider may require substantially greater oversight than a lower-risk supplier.

Residual Risk Can Be Accepted

An important feature of the proposal is its treatment of residual risk.

The guidance recognises that third-party risk cannot always be eliminated completely. Banks may accept some residual risk where mitigation is impractical or alternatives are limited, provided the risk is properly understood and governed.

The proposal also addresses subcontractor oversight, consortium and standard-setting organisations, insurance and indemnification provisions, and operational resilience planning.

Implications for Banks and Fintechs

The proposed approach is particularly relevant as banks increasingly depend on external providers for cloud infrastructure, technology, payments, data processing and other critical services.

For banks, the key issue is therefore not simply whether a service is outsourced, but what could happen if that third party fails, suffers a cyberattack or becomes unavailable.

The framework could encourage institutions to concentrate their strongest controls on relationships capable of creating the greatest potential harm rather than applying identical procedures to every vendor.

The proposal is also intended to support responsible innovation. Regulators said the earlier approach could discourage relationships with newer and innovative third parties by creating an assumption that such relationships automatically involved elevated risk.

The proposed guidance would remain principles-based and non-binding. Non-compliance with the guidance itself would not trigger supervisory action. If finalised, it would rescind and replace the 2023 interagency third-party risk guidance and related resources.

For risk professionals, the broader lesson is clear: effective third-party risk management is moving towards risk-based oversight, proportional controls and continuous assessment of critical dependencies rather than a uniform compliance checklist.

Want to deepen your expertise beyond today’s news?

Explore practical certification courses designed for banking, risk, insurance, compliance, ESG, AI, and emerging technologies professionals.

Learn from industry experts and earn certifications from RMAI and BFSI Sector Skill Council of India.

#Riskmanagementnews

author avatar
RMA INDIA

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.