What's Happening?
The Federal Deposit Insurance Corporation (FDIC), Office of the Comptroller of the Currency (OCC), Federal Reserve Board, and National Credit Union Administration (NCUA) have jointly proposed new, more prescriptive guidance for managing third-party relationships
within the banking sector. This proposed framework aims to replace existing interagency guidance and mandates specific elements for board-approved policies and programs throughout the lifecycle of third-party engagements. These elements include due diligence, contracting, ongoing monitoring, documentation, remediation, and termination. Concurrently, the FDIC, OCC, and Federal Reserve issued a statement acknowledging the unique challenges community banks face when dealing with core service providers, such as those offering core banking and data-processing platforms. The Federal Reserve also separately proposed a guide tailored for traditional community banking organizations.
Why It's Important?
This proposed guidance is significant for the U.S. financial industry as it moves beyond general principles to establish a more detailed and explicit framework for third-party risk management. The increased prescriptiveness means that banks, particularly smaller institutions, will likely need to formalize and enhance their existing risk management programs. This could lead to substantial operational changes and potentially increased compliance costs. The acknowledgment of community banks' limited leverage with large core service providers highlights a critical practical issue, suggesting that while banks remain responsible for outsourced activities, regulators recognize the difficulties in obtaining necessary information or negotiating terms. This framework aims to strengthen the resilience of the financial system by ensuring that risks associated with third-party vendors are rigorously identified, assessed, and controlled, thereby protecting consumers and maintaining financial stability.
What's Next?
The proposed guidance is currently open for public comment, providing an opportunity for the banking industry to address practical concerns and suggest modifications. The final guidance will significantly shape how U.S. banks manage their relationships with external service providers. Furthermore, this initiative is being viewed in conjunction with the FDIC's reported consideration of establishing a Banking Industry Standards Development Organization (BISDO) for third-party service providers. If BISDO materializes, it could introduce standardized industry practices, assessments, and certifications, potentially reducing the duplicative due diligence efforts currently undertaken by individual banks. The interplay between the final prescriptive guidance and the development of a potential BISDO will determine whether the new framework effectively reduces the burden of third-party risk management or merely formalizes and redistributes it across the industry.
Beyond the Headlines
The deeper implication of this regulatory shift lies in its potential to reshape the ecosystem of financial technology (fintech) providers and other third-party vendors serving the banking sector. While the new guidance aims to enhance risk management, it could also create a higher barrier to entry for smaller or newer fintech companies that may struggle to meet stringent due diligence requirements from numerous banks. Conversely, a successful BISDO could standardize expectations, making it easier for compliant fintechs to demonstrate their credibility and reduce their compliance burden. This dual approach—more explicit expectations for banks and potential standardization for providers—reflects a growing recognition that the interconnectedness of the financial system through third-party relationships poses systemic risks. The long-term success of this framework will depend on its ability to foster a more secure and resilient financial system without stifling innovation or disproportionately burdening smaller institutions.













