Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

Federal Regulators Propose Risk-Based Overhaul of Third-Party Management Guidance

Federal Regulators Propose Risk-Based Overhaul of Third-Party Management Guidance

By
Key Takeaways
  • New Third-Party Guidance Proposed: The Federal Reserve, FDIC, NCUA and OCC are seeking comment on principles-based guidance designed to help banks and credit unions tailor third-party risk management to the risks of individual relationships.
  • Existing Guidance Could Be Replaced: Once the proposal is finalized, the federal banking agencies plan to rescind their existing third-party risk management guidance and replace it with the new framework.
  • Community Bank Challenges Get Separate Attention: The federal banking agencies issued a statement addressing community banks’ relationships with core service providers, including challenges involving due diligence, ongoing monitoring and contract terms.
  • Federal Reserve Proposes Community Bank Guide: The Fed separately proposed a companion third-party risk management guide specifically for Federal Reserve-supervised community banks.
Deep Dive

The Federal Reserve Board, Federal Deposit Insurance Corporation, National Credit Union Administration, and Office of the Comptroller of the Currency on Friday requested comment on proposed guidance for managing risks associated with third-party relationships. The proposal draws on the agencies’ supervisory experience and what they have learned examining financial institutions’ third-party risk management practices.

At its center is a fairly practical idea. The amount of attention a third party receives should correspond to the risk that particular relationship presents. The agencies said the proposed guidance would help banks and credit unions better align and tailor their third-party risk management practices to individual relationships. The approach is principles-based and, like other supervisory guidance, non-binding.

The OCC put the point more plainly in its own announcement. Banks would be able to focus their resources according to the magnitude and likelihood of potential harm posed by a relationship, while adjusting their practices for the institution’s size, complexity and risk profile. The agency said the proposal would move away from overly broad, process-driven approaches and make clear that there is no single model for third-party risk management.

That may sound like a modest distinction. In practice, it goes to one of the recurring difficulties of third-party risk management: a vendor inventory can contain relationships that bear little resemblance to one another. What matters is not simply that an outside company is involved, but what could happen to the institution if that relationship fails or otherwise causes harm.

The proposal would put more weight on making that judgment. If finalized, the federal banking agencies plan to rescind their existing third-party risk management guidance and replace it with the new framework. The agencies said the change is intended to promote consistency and prudent innovation in the banking industry.

Comments will be due 60 days after the proposal is published in the Federal Register.

The Core Provider Problem

The broader proposal arrived alongside a second action aimed more directly at community banks. The federal banking agencies issued a statement addressing community banks’ engagement with core service providers and the factors regulators will consider when making supervisory and enforcement decisions related to those providers.

The issue is not an abstract one. Community banks can depend on core providers for important services while finding themselves with limited leverage over the terms of those relationships. The OCC specifically pointed to challenges involving due diligence, ongoing monitoring and contract terms.

The agencies’ statement gives those circumstances a more explicit place in the supervisory conversation. According to the OCC, the purpose is to provide community banks greater clarity about regulators’ risk-based supervision and enforcement of core service providers when those difficulties arise.

That distinction matters. A requirement that a bank manage third-party risk does not, by itself, give a small institution greater bargaining power over a provider. The agencies are now spelling out that the realities of the relationship can be relevant when supervisory and enforcement decisions are made.

The OCC presented both actions as part of its larger effort to reduce regulatory burden on community banks. The agency said the combination should give those institutions greater flexibility to manage risk and provide products and services.

Comptroller of the Currency Jonathan V. Gould described the proposal as an effort to cut what he called unnecessary regulatory friction while tailoring supervision more closely to actual risk. The OCC also pointed to a series of other recent changes affecting community banks, including revisions to examination practices, model risk management guidance, licensing requirements, Bank Secrecy Act and anti-money laundering examination procedures, reporting requirements and eligibility for longer examination cycles.

A Separate Federal Reserve Guide

The Federal Reserve is also proposing something more specific for the community banks under its supervision. Separately from the joint agency proposal, the Board requested comment on a proposed third-party risk management guide for Federal Reserve-supervised community banks. The document is intended to accompany the broader guidance rather than replace it.

The result is a proposal operating at two levels. The agencies are seeking to establish common principles for banks and credit unions while recognizing that applying those principles at a community institution may look different from applying them elsewhere.

For third-party risk teams, the practical consequence would be greater emphasis on judgment. A process built around treating every provider alike would sit awkwardly with guidance expressly designed around differences in risk. Institutions would instead need to determine which relationships present the greatest potential harm and tailor their risk management accordingly. That flexibility does not make the work disappear. It makes the quality of the underlying judgment more important.

The proposal has not been finalized, and the agencies will first take public comments. But the documents released Friday make the direction of travel fairly plain. The regulators are asking financial institutions to spend less effort proving that every third party has passed through the same process and more effort concentrating their attention on the relationships where failure would actually matter.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong