Agencies Seek Comment on Third-Party Risk Guidance
Federal banking agencies are inviting public comment on proposed guidance for managing risks tied to third-party relationships. The effort reflects growing regulatory attention to how banks oversee vendors and service providers that support critical operations.
In a related move, the agencies issued a statement addressing community bank engagement with core service providers. Core providers supply essential technology and processing services, and community banks often have fewer resources to negotiate or manage those relationships. The statement appears intended to clarify supervisory expectations without imposing new burdens.
Third-party risk management guidance typically focuses on due diligence, contract terms, ongoing monitoring and contingency planning. Those issues matter as banks rely on outside firms for cloud computing, payments, data processing and other functions. Regulators have stressed that banks cannot outsource responsibility for managing risk, even when activities are performed by third parties.
The agencies are seeking feedback from banks, trade groups, technology providers and other stakeholders before finalizing the proposal. Comments could shape how detailed the expectations become and how they apply to institutions of different sizes. The separate community bank statement signals a tailored approach for smaller lenders that depend heavily on core service providers.
Source: Federal Reserve
