Who this applies to: Chief Financial Officers, Chief Operating Officers, and Chief Compliance Officers at financial institutions.
Financial institutions rely heavily on third-party service providers to deliver critical technology, payment processing, online banking, compliance support, and other essential services. Recognizing the challenges many institutions face in managing these relationships, federal regulators recently issued a joint statement on core service providers and proposed updated third-party risk management guidance.
Focus on risk, not checklists
A central theme of the proposed guidance is that third-party risk management should be tailored to an institution's size, complexity, and risk profile. Regulators emphasize that not all vendor relationships present the same level of risk and that oversight should be tailored to the risks posed by each relationship. Instead, institutions are encouraged to focus resources on relationships that pose the greatest operational, financial, compliance, or customer impact. The regulators also reiterate that the guidance is principles-based rather than prescriptive, and that supervisory findings would be based on unsafe or unsound practices or legal violations rather than deviations from the guidance itself.
The agencies also emphasize that effective risk management is about managing and understanding risk, not eliminating it entirely. Institutions may accept residual risks when doing so is consistent with their risk appetite and business objectives.
Regulators clarify their approach to core service providers
In a separate joint statement, regulators highlighted concerns about the market dynamics surrounding core service providers. Many financial institutions depend on a small number of large providers and often face challenges obtaining due diligence information, negotiating contracts, monitoring performance, or changing providers.
To address these concerns, regulators indicated they will consider several factors when determining the level of supervisory attention directed toward core providers, including:
- Transparency in sharing due diligence and performance information
- Timely disclosure of operational issues and cybersecurity incidents
- Use of clear service-level agreements
- Opaque pricing and billing practices
- Contract provisions that restrict an institution's ability to switch providers or integrate with other vendors
- Technology investments and operational resilience capabilities
Accountability for core service providers may increase
Another noteworthy aspect of the regulators' joint statement is the reminder that, under certain circumstances, employees or agents of a core service provider may be considered Institution-Affiliated Parties (IAPs) of an institution. If an individual meets the statutory definition of an IAP, banking regulators may have authority to pursue enforcement actions directly against that individual for misconduct affecting a financial institution. The statement does not create new authority, but it signals regulators' willingness to consider existing enforcement tools when evaluating concerns involving third-party service providers.
For institutions, this development could ultimately strengthen accountability within the vendor ecosystem. While institutions remain responsible for managing risks associated with outsourced activities, the statement suggests regulators are focused not only on how institutions oversee their core providers, but also on whether core providers and their personnel are meeting their own obligations to operate in a safe, sound, and transparent manner.
What financial institutions should do now
Financial institutions may wish to review their third-party risk management programs with an eye toward ensuring oversight efforts are aligned with actual risk levels. Institutions should also evaluate key core-provider contracts, service-level agreements, incident notification processes, and contingency plans for critical services.
The proposals suggest regulators are seeking to maintain a strong focus on material risks while encouraging a more tailored and efficient approach to third-party risk management. For institutions, that could mean more flexibility in managing lower-risk vendors while placing greater emphasis on understanding and managing relationships with critical service providers.
Bottom line for financial institutions
Regulators appear to be moving toward a more practical, risk-based supervisory framework that recognizes the realities institutions face when working with core providers and other third parties. Institutions should use this as an opportunity to ask whether their current vendor oversight is appropriately scaled to actual risk. In some cases, financial institutions may be applying the same level of documentation, review, and monitoring to lower-risk vendors as they do to critical service providers, creating unnecessary burden without meaningfully reducing risk. Vendors deemed to be low risk likely warrant a scaled-back oversight approach, allowing institutions to focus their oversight activities on vendors that truly represent the highest risk to the institution. Financial institutions that can demonstrate thoughtful risk assessment, proportional oversight, and sound governance should be well positioned under the evolving guidance and should use the guidance as an opportunity to level set their third-party risk management program.
Key takeaways
- Align third-party oversight activities with the actual risk posed by each vendor relationship rather than applying the same level of scrutiny across all providers.
- Focus risk management resources on third parties that present the greatest operational, financial, compliance, or customer impact.
- Evaluate contracts, service-level agreements, incident notification processes, and contingency plans for critical service providers.
- Recognize that regulators are increasing their focus on core service providers, including transparency, operational resilience, and accountability for misconduct.
- Use the proposed guidance as an opportunity to reassess vendor risk classifications and scale oversight efforts appropriately for lower- and higher-risk relationships.
About BerryDunn
Our dedicated audit, tax, and consulting professionals understand the financial services industry and its challenges and are committed to helping you meet and exceed regulatory requirements. We partner with you to bring tailored approaches to fit your needs and operations and provide guidance on best practices and recommendations that make sense for you. Learn more about our services and team.