Final Guidance on Third-Party Risk Management
Final Guidance on Third-Party Risk Management
AGENCY: The Board of Governors of the Federal Reserve System (Board), the Federal
Deposit Insurance Corporation (FDIC), and the Office of the Comptroller of the Currency
(OCC), Treasury.
SUMMARY: The Board, FDIC, and OCC (collectively, the agencies) are issuing final
guidance on managing risks associated with third-party relationships. The final guidance
offers the agencies’ views on sound risk management principles for banking
organizations when developing and implementing risk management practices for all
stages in the life cycle of third-party relationships. The final guidance states that sound
third-party risk management takes into account the level of risk, complexity, and size of
the banking organization and the nature of the third-party relationship. The agencies are
each agency’s existing general guidance on this topic and is directed to all banking
Board: Kavita Jain, Deputy Associate Director, (202) 452-2062, Chandni Saxena,
Manager, (202) 452-2357, Timothy Geishecker, Lead Financial Institution and Policy
1
Analyst, (202) 475-6353, or David Palmer, Lead Financial Institution and Policy Analyst,
(202) 452-2904, Division of Supervision and Regulation; Matthew Dukes, Counsel, (202)
Senior Counsel, (202) 452-2552, Evans Muzere, Senior Counsel, (202) 452-2621, or
Alyssa O’Connor, Senior Attorney, (202) 452-3886, Legal Division, Board of Governors
of the Federal Reserve System, 20th and C Streets NW, Washington, DC 20551. For
Telecommunications Relay Services (TRS), please call 711 from any telephone,
OCC: Kevin Greenfield, Deputy Comptroller for Operational Risk Policy, Tamara Culler,
Governance and Operational Risk Policy Director, Emily Doran, Governance and
Operational Risk Policy Analyst, or Stuart Hoffman, Governance and Operational Risk
Policy Analyst, Operational Risk Policy Division, (202) 649-6550; or Eden Gray,
2
Counsel’s Office, (202) 649-5490, Office of the Comptroller of the Currency, 400 7th
Street SW, Washington, DC 20219. If you are deaf, hard of hearing, or have a speech
SUPPLEMENTARY INFORMATION:
Table of Contents
I. Introduction
F. Subcontractors
I. Introduction
services, and other activities (collectively, activities). The use of third parties can offer
banking organizations significant benefits, such as quicker and more efficient access to
1
For a description of the banking organizations supervised by each agency, refer to the definition of
“appropriate Federal banking agency” in section 3(q) of the Federal Deposit Insurance Act (12 U.S.C.
1813(q)). This guidance is relevant to all banking organizations supervised by the agencies.
3
technologies, human capital, delivery channels, products, services, and markets. Banking
organizations’ use of third parties does not remove the need for sound risk management.
On the contrary, the use of third parties, especially those using new technologies, may
operational, compliance, and strategic risks. Importantly, the use of third parties does not
performed in a safe and sound manner and in compliance with applicable laws and
regulations, including but not limited to those designed to protect consumers (such as fair
lending laws and prohibitions against unfair, deceptive or abusive acts or practices) and
The agencies have each previously issued general guidance for their respective
third-party relationships, each of which is rescinded and replaced by this final guidance:
the Board’s 2013 guidance, 2 the FDIC’s 2008 guidance, 3 and the OCC’s 2013 guidance
and its 2020 frequently asked questions (herein, OCC FAQs). 4 By issuing this
interagency guidance, the agencies aim to promote consistency in their third-party risk
management guidance and to clearly articulate risk-based principles for third-party risk
management. Further, the agencies have observed an increase in the number and type of
2
SR Letter 13-19/CA Letter 13-21, “Guidance on Managing Outsourcing Risk” (December 5, 2013,
updated February 26, 2021).
3
FIL-44-2008, “Guidance for Managing Third-Party Risk” (June 6, 2008).
4
OCC Bulletin 2013-29, “Third-Party Relationships: Risk Management Guidance,” and OCC Bulletin
2020-10, “Third-Party Relationships: Frequently Asked Questions to Supplement OCC Bulletin 2013-29.”
Additionally, the OCC also issued foreign-based third-party guidance, OCC Bulletin 2002-16, “Bank Use
of Foreign-Based Third-Party Service Providers: Risk Management Guidance,” which is not being
rescinded but instead supplements the final guidance.
4
intended to assist banking organizations in identifying and managing risks associated
with third-party relationships and in complying with applicable laws and regulations. 5
On July 19, 2021, the agencies published for comment proposed guidance on
managing risks associated with third-party relationships (proposed guidance). 6 The 60-
day comment period initially ended on September 17, 2021. In response to commenters’
requests for additional time to analyze and respond to the proposal, the agencies extended
The agencies invited comment on all aspects of the proposed guidance. To help
solicit feedback, the agencies posed 18 questions within the request for comment,
organized across the following themes: General, Scope, Tailored Approach to Third-
Arrangements, Subcontractors, Information Security, and the OCC’s 2020 FAQs. The
5
These include the “Interagency Guidelines Establishing Standards for Safety and Soundness,” and the
“Interagency Guidelines Establishing Information Security Standards,” which were adopted pursuant to the
procedures of section 39 of the Federal Deposit Insurance Act and section 505 of the Graham Leach Bliley
Act, respectively. See 12 CFR part 30, appendices A and B (OCC); part 208, appendices D-1 and D-2
(Board); and part 364, appendices A and B (FDIC).
6
“Proposed Interagency Guidance on Third-Party Relationships: Risk Management,” 86 FR 38182 (July
19, 2021).
7
“Proposed Interagency Guidance on Third-Party Relationships: Risk Management,” 86 FR 50789
(September 10, 2021).
8
Comments can be accessed at: [Link]
(OCC); [Link]
(Board); and [Link]
[Link] (FDIC).
5
General Support for the Proposed Guidance
based guidance on third-party risk management. Commenters agreed with the proposal’s
risk management practices that are commensurate with the level of risk and complexity
to third-party risk management can be adapted to a wide range of relationships and scaled
There were varying views among commenters on the level of detail included in
the proposed guidance. While some commenters found the language to be too
prescriptive, others noted that it had the right level of detail to enable banking
perspectives on whether or how to incorporate the concepts from the OCC FAQs. 9
guidance does not have the force and effect of law and does not impose any new
processes tailored to the risk profile and complexity of their third-party relationships.
9
The agencies included the OCC’s 2020 FAQs as an exhibit when issuing the proposed guidance and
sought comment on whether any of the concepts in the OCC FAQs should be incorporated into the
interagency guidance. See 86 FR 38196.
10
See 12 CFR part 4, appendix A to subpart F (OCC); 12 CFR part 262, appendix A (Board); and 12 CFR
part 302, appendix A (FDIC).
6
Terminology and Scope
Relationship”
Some commenters suggested that the term “business arrangement” is overly broad
and inconsistent with the risk-based approach of the guidance. For example, some
commenters believed that without narrowing the term, banking organizations may face an
undue burden when implementing their risk management processes. Several commenters
and limiting arrangements to only those that are continuous and/or governed by a written
contract.
was overly broad and may divert banking organizations from focusing sufficiently on
those relationships that present higher risk. These commenters suggested applying a
materiality standard (for example, those third parties supporting critical activities) or
to-bank relationships).
discussions from OCC FAQs 1 and 2 elaborating on and providing examples of “business
7
With respect to these comments, the agencies believe the scope of the term
“business arrangement” in the proposed guidance captures the full range of third-party
relationships that may pose risk to banking organizations, and the final guidance does not
change that scope. These relationships have evolved, and may continue to evolve, over
time to encompass a large range of activities, justifying the use of broad terminology.
The agencies have incorporated concepts from OCC FAQs 1 and 2. Although the terms
“business arrangement” and “third-party relationship” are broad, the guidance does not
suggest that all relationships require the same level or type of oversight or risk
management, since different relationships present varying levels of risk. The guidance
states that, as part of sound risk management, a banking organization analyzes the risks
associated with each third-party relationship and adjusts its risk management practices,
commensurate with the banking organization’s size, complexity, and risk profile and with
the nature of its third-party relationships. The agencies have removed from the final
guidance the proposed text, which stated that the term “business arrangement” generally
Commenters expressed views on the term “critical activities,” suggesting that the
higher risk and critical in nature or requested clarification on or limitation of the scope
and application of the term. Some commenters requested the agencies provide further
8
examples of critical activities or clarify whether banking organizations could employ
Commenters provided other suggestions that they thought would improve the
• Incorporating the concept from OCC FAQ 8 that not every relationship
concepts in existing, related guidance (for example, the definitions for “critical
operations” and “core business line” used in the Interagency Paper on Sound Practices to
The agencies considered the range of comments on the term “critical activities”
and have made certain revisions to improve clarity and emphasize flexibility. The
11
“Proposed Interagency Guidance on Third-Party Relationships: Risk Management”, 86 FR 38182, at
38187 (July 19, 2021); [Link]
interagency-guidance-on-third-party-relationships-risk-management.
12
“Interagency Paper on Sound Practices to Strengthen Operational Resilience,” Federal Reserve SR 20-
24 (November 2, 2020); OCC Bulletin 2020-94 (October 30, 2020); and FDIC FIL-103-2020 (November 2,
2020).
9
revised term eliminates imprecise concepts like “significant investment” and “significant
activities that could cause significant risk to the banking organization if the third party
fails to meet expectations or that have significant impacts on customers or the banking
from OCC FAQs 7, 8, and 9, recognizing that an activity that is critical for one banking
organization may not be critical for another. Some banking organizations may assign a
criticality or risk level to each third-party relationship, while others may identify critical
activities and those third parties associated with such activities. Regardless of a banking
third-party relationships receive more comprehensive oversight is key for effective risk
management.
agencies note that this guidance is intended to provide examples of considerations that
may be helpful to all banking organizations, regardless of size. It is important for each
banking organization to assess risks presented by each of its third-party relationships and
tailor its risk management processes accordingly. To the extent that specific laws and
and approaches in those laws and regulations when developing and implementing third-
party risk management, such as identifying third-party relationships that that support
higher-risk activities, including critical activities. Moreover, to the extent that other
13
See 12 CFR part 243 (Regulation QQ); 12 CFR part 30, Appendix E.
10
guidance may be relevant to certain banking organizations, such as the Sound Practices
Paper, which is intended for the largest and most complex banking organizations, 14 such
organizations may choose to reference relevant terms and concepts contained in those
principles discussed in the guidance to meet the different needs of individual banking
commenters asserted that smaller, less complex banking organizations do not need to
adopt the same risk management approaches adopted by larger, more complex banking
organizations. As such, they asked that the guidance include language either to clarify
the flexibility of the guidance with respect to the size of banking organizations or to the
risk presented by certain third-party relationships. Some commenters suggested that the
guidance make allowances for banking organizations to explicitly accept the risk of the
relationship, in lieu of establishing full due diligence practices, based on the banking
appropriate practices specific to smaller banking organizations or of the specific risks that
certain categories of third parties or critical activities may pose to smaller banking
smaller banking organizations may lack the necessary resources to thoroughly vet third
14
The practices are addressed to domestic banks with more than $250 billion in total consolidated assets or
banks with more than $100 billion in total assets and other risk characteristics. See note 12.
11
parties, and thus should be afforded some form of “safe harbor” relating to third-party
for example, that banking organizations may have limited negotiating power, that there is
no one way for banks to structure their third-party risk management processes, and that
not all relationships warrant the same level of oversight or risk management).
In response to these comments, the agencies reiterate that the guidance is relevant
to all banking organizations. The agencies have incorporated concepts from OCC FAQ
processes based on risk. The guidance notes that not all third-party relationships present
the same level or type of risk and therefore not all relationships require the same extent of
oversight or risk management. It also states that as part of sound risk management, it is
the responsibility of each banking organization to analyze the risks associated with each
with the banking organization’s size, complexity, and risk profile and with the nature of
posed by each third-party relationship and deciding the relevance of the considerations
discussed in the guidance. To reinforce this flexibility and provide clarity on third-party
agencies have streamlined and simplified certain sections of the guidance. The agencies
12
have also incorporated into the final guidance concepts from OCC FAQs 5, 6, and 7
discussed above.
discussed a banking organization’s use of third parties for technological advances and
records. 15 In addition, some commenters expressed concern that the discussion in OCC
asked for additional flexibility for banking organizations to manage relationships with
example.
Some commenters also noted that third-party risk management processes may be
applied differently, based on the specific type of relationship. For example, several
commenters stated that arrangements with affiliates may present different or lower risks
than those with unaffiliated third parties, and suggested that, as a result, a banking
organization’s third-party risk management may differ for affiliates and non-affiliates.
15
See 12 U.S.C. 5533. As required by the Dodd-Frank Wall Street Reform and Consumer Protection Act,
the agencies are participating in consultations with the CFPB related to the rulemaking.
13
Certain commenters also suggested that third parties that are already supervised or
guidance on foreign-based third parties, including clearly explaining this term, describing
typical risks and accompanying risk management strategies, and addressing the
the agencies have included a footnote to address questions surrounding the term “foreign-
based third party” and have retained applicable considerations for foreign-based third
agencies recognize that some banking organizations are forming relationships with
performed, such relationships may introduce new or increase existing risks to a banking
organization, such as those risks identified by some commenters. For example, in some
organization and a third party may differ from those in other third-party relationships.
organization and the third party each may have varying degrees of interaction with
guidance are applicable to all third-party relationships, including those with fintech
14
companies. Therefore, it is important for a banking organization to understand how the
arrangement with a third party, including a fintech company, is structured so that the
banking organization may assess the types and levels of risks posed and determine how to
manage those third-party relationships accordingly. The agencies did not incorporate
concepts from OCC FAQ 4, opting to provide broad risk management guidance.
relationships but decided not to exclude any specific third-party relationships from the
scope of the guidance; rather, the guidance is relevant to managing all third-party
relationships. Because third-party relationships present varying levels and types of risk,
the guidance notes that not all relationships require the same level or type of oversight or
risk management.
party risk management that can be adjusted to the unique circumstances of each third-
alternative approaches or to broadly assume lower levels of risk based solely on the type
of a third party. For example, while a third-party relationship with an affiliate may have
different characteristics and risks as compared to those with non-affiliated third parties,
affiliate relationships may not always present lower risks. The same is true for third
The agencies also incorporated concepts from OCC FAQs 7 and 9, reiterating that
analyze the risks associated with each third-party relationship and to calibrate its risk
15
management practices, commensurate with the banking organization’s size, complexity,
and risk profile and with the nature of its third-party relationships.
Commenters made a wide range of suggestions in the risk management life cycle
section of the proposed guidance. Commenters expressed mixed views on the level of
detail provided with respect to the various aspects of the risk management life cycle as
well as the meaning of certain concepts. Some commenters raised concerns that the level
of detail made the guidance overly burdensome on smaller banks. Other commenters
recommended that the agencies expand the discussion to include additional stages within
the risk management life cycle; a risk management matrix; or practical, illustrative
In response to these comments, the agencies have clarified and streamlined the
guidance and removed details that were duplicative, not useful, or that could be
interpreted as prescriptive. The agencies also reiterate that the guidance is principles-
based. Examples of considerations are merely illustrative, not requirements, and may not
The agencies support a risk-based approach for banking organizations to assess the risk
posed by a third-party relationship and tailor their third-party risk management processes
accordingly.
stages of the risk management life cycle, which are addressed below:
16
1. Due Diligence and Collaborative Arrangements
The due diligence and third-party selection stage of the risk management life
cycle drew particular attention from commenters. Some raised concerns with the
feasibility of banking organizations performing the full range of due diligence outlined in
the proposal, noting that third parties or their related subcontractors may be unable or
unwilling to disclose certain information. These commenters stated that the extent of due
fully applicable for most relationships. Other commenters suggested that banking
organizations could engage in less stringent due diligence for certain types of third
parties. Suggestions to address these concerns included revising the guidance to scale
due diligence to the risk posed by the third party, limiting the burden of certain due
example, many commenters expressed support for proposed language on shared due
and the ability to meet due diligence needs in a shared framework. Some commenters
recommended solutions, such as joint data collections and assessments across banking
organizations and third parties. Other commenters asked the agencies to incorporate and
expand upon the discussions in OCC FAQs 14 and 24 that banking organizations may
17
Commenters also suggested that the guidance address due diligence options when
due diligence and audits. Several commenters recommended that the guidance be
tailored for or scope out certain third parties that may be resistant to due diligence efforts.
Banking organizations may not be able to seek out alternatives to these third parties,
especially where the industry is particularly concentrated. Another commenter noted that
the use of on-site audits or visits has declined over time and could be inefficient and
costly, especially for third parties with operations in several physical locations (such as
agencies reiterate that relationships present varying levels of risk and not all relationships
require the same level or type of oversight or risk management. However, the agencies
do not believe it would be appropriate for banking organizations to conduct reduced due
diligence, including collaboration with other banking organizations and engaging with
third parties that specialize in conducting due diligence, the agencies note that such
collaborative efforts could be beneficial and reduce burden, especially for community
banking organizations, and have made certain clarifying revisions to the guidance in that
regard. However, use of any collaborative efforts does not abrogate the responsibility of
banking organizations to manage third-party relationships in a safe and sound manner and
consistent with applicable laws and regulations (including antitrust laws). It is important
for the banking organization to evaluate the conclusions from such collaborative efforts
18
based on the banking organization’s own specific circumstances and performance criteria
for the activity. A banking organization engaging an external party to supplement risk
risk management processes. The agencies have incorporated into the final guidance
acknowledge challenges in some circumstances. Consistent with the concepts from OCC
FAQs 1, 5, and 17, the guidance provides that in such circumstances, banking
organizations should consider taking steps to mitigate the risks or, if the risks cannot be
mitigated, to determine whether the residual risks are acceptable. The guidance also
states that when assessing the risk of a third-party relationship, banking organizations
may consider information available from various sources. For example, the agencies
incorporated concepts from OCC FAQs 14 and 24, recognizing that banking
organizations may consider public regulatory disclosures when considering the risks
presented by the specific third party. If the banking organization has concerns that the
relationship falls outside of its risk appetite, it should consider making alternative
choices.
identify and evaluate the risks associated with each third-party relationship and to tailor
its risk management practices, commensurate with the banking organization’s size,
complexity, and risk profile, as well as with the nature of its third-party relationships. As
19
such, the agencies have not excluded any specific third-party relationships from the scope
of the guidance.
2. Contract Negotiation
contract negotiations. Several commenters expressed concern that the section was overly
detailed, that many contracts may not contain all of the contractual considerations
discussed in the proposed guidance, and that such considerations might be treated as a
mandatory checklist. Other commenters found the nature and extent of contractual
Several commenters stated that the guidance should acknowledge the need for
requested that the guidance recognize that banking organizations may lack sufficient
leverage in negotiations with larger third parties and may struggle to get certain “typical”
support to smaller institutions to increase their collective negotiating power with respect
negotiations. Some commenters proposed that the guidance include language from
OCC FAQs 5 and 13, acknowledging that a banking organization may have limited
20
negotiating power in certain instances and should understand any resulting limitations.
As the guidance states, many of the same considerations for collaborative arrangements
The agencies have streamlined some of the considerations in this section but
believe that the overall scope of the discussion would be useful to banking organizations
3. Ongoing Monitoring
Several commenters recommended that the agencies revise the proposed guidance
to encourage banks to adopt active, continuous, real-time monitoring, arguing that this
The agencies are not encouraging any specific approach to ongoing monitoring.
Rather, the guidance continues to state that a banking organization’s ongoing monitoring,
like other third-party risk management processes, should be appropriate for the risks
organization’s size, complexity, and risk profile and with the nature of its third-party
relationships. Additionally, the guidance states that banking organizations may consider
monitoring.
Subcontractors
with subcontractors. These comments largely focused on whether the guidance could be
21
clarified to promote additional flexibility in how banking organizations manage the risks
associated with subcontractors, which pose challenges not necessarily present in a direct
third-party relationship.
subcontractors, especially those that are material to a service being provided to a banking
organization; those with access to sensitive, nonpublic information; those that perform
higher-risk activities, including critical activities; those with access to the banking
manage its subcontractors. Commenters also suggested that, in line with OCC FAQ 11, a
banking organization could require a third party to bind its subcontractors to any
With respect to these comments, the agencies acknowledge the risks and added
complexity that may be involved with respect to a third party’s use of subcontractors.
The agencies also recognize concerns by commenters interpreting the guidance to mean
party. Accordingly, consistent with the concepts in OCC FAQ 11, the agencies have
22
third party’s own processes for overseeing subcontractors and managing risks. As the
guidance clarifies, relationships with a third party, including a third party’s use of
subcontractors, should be evaluated based on the risk the relationship poses to the
banking organization, which may include assessing whether a third party’s use of
subcontractors may heighten or raise additional risk to the banking organization and
applying mitigating factors, as appropriate. The agencies have also made streamlining
changes to improve clarity and promote flexibility, including by removing use of the term
“critical subcontractor.”
board of directors and management with respect to effective third-party risk management.
Some commenters, for example, stated that the proposed guidance implied excessive
guidance could further clarify the role of the board of directors in risk management
similarly suggested the guidance clarify the authority of management to establish policies
granularity on the types, depth, and frequency of information necessary for board review,
incorporating into the guidance and elaborating upon OCC FAQs 6 and 26, which discuss
the board’s responsibility for overseeing the development of an effective third-party risk
management process, and its role in contract approval. Some commenters also requested
23
“Oversight and Accountability” and its related subsections in the proposed guidance be
better differentiated from the phases of the risk management life cycle, as the concepts
and related activities occur throughout the risk management life cycle.
The agencies have incorporated concepts from OCC FAQs 6 and 26, reorganizing
the guidance to make clear that oversight and accountability happens throughout the risk
management life cycle and is not a specific stage. Further, the agencies have made
responsibilities and to avoid the appearance of a prescriptive approach to the board’s role
in the risk management life cycle, while still emphasizing that the board has ultimate
oversight responsibility to ensure that the banking organization operates in a safe and
Commenters also offered other thoughts and suggestions relating to the guidance.
Commenters noted that it would be helpful to have a period prior to the guidance taking
commenters also recommended that the agencies leverage, refer to, or combine recent,
Notification rule,” 16 “Third-Party Due Diligence Guide for Community Banks,” 17 and the
“Model Risk Management” booklet of the Comptroller’s Handbook 18) as part of any final
16
12 CFR part 53 (OCC); 12 CFR 225, subpart N (Board); 12 CFR 304, subpart C (FDIC).
17
“Conducting Due Diligence on Financial Technology Companies A Guide for Community Banks,”
Board, FDIC, OCC (August 2021), available at: [Link]
releases/2021/[Link].
18
“Comptroller’s Handbook: Model Risk Management,” OCC (August 2021), available at:
[Link]
management/[Link].
24
third-party risk management guidance. A few commenters made reference to the FDIC’s
2016 proposed examination guidance for third-party lending, 19 stating that, although not
finalized, the 2016 proposed guidance set forth meaningful concepts about third-party
processes. Some commenters suggested that any final guidance include a separate
section outlining specific examination procedures to set clear and consistent expectations
section rather than incorporating them throughout any final guidance, complementing
Others thought that the existence of a separate set of FAQs would create unnecessary
confusion for examiners and the industry. In response, the agencies have not
incorporated issue-specific FAQs where it was determined the matters are adequately
reflected in other issuances published since the OCC FAQs were last updated.
suggested that other federal government agencies, such as the National Credit Union
Administration, join the agencies in issuing this guidance. Another commenter urged the
19
FDIC FIL-50-2016, “Examination Guidance for Third-Party Lending” (July 29, 2016). This proposed
examination guidance was not finalized.
25
agencies to support federal legislative proposals that would clarify the authority of state
Some commenters suggested that the agencies develop additional guidance and
third-party risk management processes could touch upon, such as consumer protection
issues, artificial intelligence, alternative data uses, and other novel developments, citing
improperly used by non-bank third parties to preempt state usury laws. Multiple
commenters requested that the agencies update the guidance to warn or discourage
banking organizations about certain risks, such as high-interest loans or conflicts with
state laws. Several commenters also suggested that the agencies use their existing
authorities (such as under the Bank Service Company Act 20) to address the risks of what
commenters suggested the agencies and the CFPB provide for automatic sharing of
guidance, the agencies have not revised the guidance to address specific topics or types of
20
12 U.S.C. 1861 et seq.
26
types of specific guidance issuances, unless expressly rescinded, would remain
unaffected by this guidance. While certain topics (including those raised by commenters)
are not explicitly discussed in the final guidance, the broad-based scope of the guidance
captures the full range of third-party relationships. With respect to requests that would
require statutory or regulatory changes, or may be outside the authority of the agencies,
The agencies actively monitor trends and developments in the financial services
necessary and appropriate to convey the agencies’ views. The agencies plan to develop
managing relevant third-party risks. The agencies will continue to coordinate closely
about risk management matters, including third-party risk management, to help promote
management, each agency has its own processes and procedures for conducting
supervisory activities, including examination work. The final guidance includes a brief
discussion of the agencies’ supervisory reviews, the scope of which is tailored to evaluate
The Paperwork Reduction Act of 1995 (44 U.S.C. 3501–3521) (PRA) states that
no agency may conduct or sponsor, nor is the respondent required to respond to, an
27
information collection unless it displays a currently valid Office of Management and
The guidance does not revise any existing, or create any new, information
activities mentioned in the guidance are usual and customary and should occur in the
A. Overview
B. Risk Management
1. Planning
3. Contract Negotiation
4. Ongoing Monitoring
5. Termination
D. Governance
2. Independent Reviews
21
5 CFR 1320.3(b)(2).
28
OVERVIEW
The Board of Governors of the Federal Reserve System (Board), the Federal
Deposit Insurance Corporation (FDIC), and the Office of the Comptroller of the Currency
(OCC) (collectively, the agencies) have issued this guidance to provide sound risk
and implementing risk management practices to assess and manage risks associated with
third-party relationships. 2
organizations are required to operate in a safe and sound manner 3 and in compliance with
applicable laws and regulations. 4 A banking organization’s use of third parties does not
diminish its responsibility to meet these requirements to the same extent as if its activities
were performed by the banking organization in-house. To operate in a safe and sound
manage the risks arising from its activities, including from third-party relationships. 5
1
For a description of the banking organizations supervised by each agency, refer to the definition of
“appropriate Federal banking agency” in section 3(q) of the Federal Deposit Insurance Act (12 U.S.C.
1813(q)). This guidance is relevant to all banking organizations supervised by the agencies.
2
Supervisory guidance does not have the force and effect of law and does not impose any new
requirements on banking organizations. See 12 CFR 4, Subpart F, Appendix A (OCC); 12 CFR 262,
Appendix A (FRB) 12 CFR 302, Appendix A (FDIC).
3
See 12 U.S.C. 1831p-1. The agencies implemented section 1831p-1 by regulation through the
“Interagency Guidelines Establishing Standards for Safety and Soundness.” See 12 CFR part 30, appendix
A (OCC), 12 CFR part 208, appendix D-1 (Board); and 12 CFR part 364, appendix A (FDIC).
4
References to applicable laws and regulations throughout this guidance include but are not limited to
those designed to protect consumers (such as fair lending laws and prohibitions against unfair, deceptive or
abusive acts or practices) and those addressing financial crimes.
5
This guidance is relevant for all third-party relationships, including situations in which a supervised
banking organization provides services to another supervised banking organization.
29
This guidance addresses any business arrangement 6 between a banking
but are not limited to, outsourced services, use of independent consultants, referral
subsidiaries, and joint ventures. Some banking organizations may form third-party
relationships with new or novel structures and features – such as those observed in
relationships with some financial technology (fintech) companies. The respective roles
and responsibilities of a banking organization and a third party may differ, based on the
the provision of products or services to, or other interaction with, customers, the banking
organization and the third party may have varying degrees of interaction with those
customers.
The use of third parties can offer banking organizations significant benefits, such
as access to new technologies, human capital, delivery channels, products, services, and
markets. However, the use of third parties can reduce a banking organization’s direct
control over activities and may introduce new risks or increase existing risks, such as
operational, compliance, and strategic risks. Increased risk often arises from greater
potential inferior performance by the third party. A banking organization can be exposed
6
The term “business arrangement” is meant to be interpreted broadly and is synonymous with the term
“third-party relationship.”
30
fails to appropriately manage the risks associated with third-party relationships.
The principles set forth in this guidance can support effective third-party risk
management for all types of third-party relationships, regardless of how they may be
with a particular third party is structured so that the banking organization may assess the
types and levels of risks posed and determine how to manage the third-party relationship
accordingly.
RISK MANAGEMENT
Not all relationships present the same level of risk, and therefore not all
relationships require the same level or type of oversight or risk management. As part of
sound risk management, a banking organization analyzes the risks associated with each
third-party relationship and tailors risk management practices, commensurate with the
banking organization’s size, complexity, and risk profile and with the nature of the third-
banking organization’s determination of whether risks have changed over time and to
31
• Cause a banking organization to face significant risk if the third party fails to
meet expectations;
operations.
party relationships that support these critical activities. Notably, an activity that is critical
for one banking organization may not be critical for another. Some banking
whereas others identify critical activities and those third parties that support such
for third-party relationships. The stages of the risk management life cycle of third-party
relationships are shown in Figure 1 and detailed below. The degree to which the
organization is based on specific facts and circumstances and these examples may not
It is important to involve staff with the requisite knowledge and skills in each
stage of the risk management life cycle. A banking organization may involve experts
across disciplines, such as compliance, risk, or technology, as well as legal counsel, and
32
may engage external support when helpful to supplement the qualifications and technical
1. Planning
organization to evaluate and consider how to manage risks before entering into a third-
party relationship. Certain third parties, such as those that support a banking
greater degree of planning and consideration. For example, when critical activities are
7
When a banking organization uses a third-party assessment service or utility, it has a business
arrangement with that entity. Therefore, the arrangement should be incorporated into the banking
organization’s third-party risk management processes.
33
involved, plans may be presented to and approved by a banking organization’s board of
planning:
• Understanding the strategic purpose of the business arrangement and how the
arrangement aligns with a banking organization’s overall strategic goals, objectives, risk
• Identifying and assessing the benefits and the risks associated with the business
• Evaluating the estimated costs, including estimated direct contractual costs and
employees, including dual employees, 9 and what transition steps are needed for the
8
The term “foreign-based third-party” refers to third parties whose servicing operations are located in a
foreign country and subject to the law and jurisdiction of that country. Accordingly, this term does not
include a U.S.-based subsidiary of a foreign firm because its servicing operations are subject to U.S. laws.
This term does include U.S. third parties to the extent that their actual servicing operations are located in or
subcontracted to entities domiciled in a foreign country and subject to the law and jurisdiction of that
country.
9
Dual employees are employed by both the banking organization and the third party.
34
banking organization to manage the impacts when activities currently conducted
use of those customers’ information, third-party interaction with customers, potential for
• Determining how the banking organization will select, assess, and oversee the
third party, including monitoring the third party’s compliance with applicable laws,
whether staffing levels and expertise, risk management and compliance management
need to be adapted over time for the banking organization to effectively address the
• Outlining the banking organization’s contingency plans in the event the banking
organization needs to transition the activity to another third party or bring it in-house.
35
2. Due Diligence and Third-Party Selection
Conducting due diligence on third parties before selecting and entering into third-
management with the information needed about potential third parties to determine if a
relationship would help achieve a banking organization’s strategic and financial goals.
The due diligence process also provides the banking organization with the information
needed to evaluate whether it can appropriately identify, monitor, and control risks
associated with the particular third-party relationship. Due diligence includes assessing
the third party’s ability to: perform the activity as expected, adhere to a banking
organization’s policies related to the activity, comply with all applicable laws and
regulations, and conduct the activity in a safe and sound manner. Relying solely on
experience with or prior knowledge of a third party is not an adequate proxy for
performing appropriate due diligence, as due diligence should be tailored to the specific
The scope and degree of due diligence should be commensurate with the level of
risk and complexity of the third-party relationship. More comprehensive due diligence is
particularly important when a third party supports higher-risk activities, including critical
scrutiny, the banking organization should consider broadening the scope or assessment
In some instances, a banking organization may not be able to obtain the desired
due diligence information from a third party. For example, the third party may not have a
long operational history, may not allow on-site visits, or may not share (or be permitted
to share) information that a banking organization requests. While the methods and scope
36
of due diligence may differ, it is important for the banking organization to identify and
document any limitations of its due diligence, understand the risks from such limitations,
and consider alternatives as to how to mitigate the risks. In such situations, a banking
organization may, for example, obtain alternative information to assess the third party,
consult with other organizations, 10 or engage in joint efforts to supplement its due
diligence. As the activity to be performed by the third party may present a different level
of risk to each banking organization, it is important to evaluate the conclusions from such
supplemental efforts based on the banking organization’s own specific circumstances and
performance criteria for the activity. Effective risk management processes include
evaluating the capabilities of any external party conducting the supplemental efforts,
understanding how such supplemental efforts relate to the banking organization’s planned
use of the third party, and assessing the risks of relying on the supplemental efforts. Use
of such external parties to conduct supplemental due diligence does not abrogate the
and sound manner and consistent with applicable laws and regulations.
10
Any collaborative activities among banks must comply with antitrust laws. Refer to the Federal Trade
Commission and U.S. Department of Justice’s “Antitrust Guidelines for Collaborations Among
Competitors” (April 2000), available at
[Link]
collaboration-among-competitors/[Link].
37
Depending on the degree of risk and complexity of the third-party relationship, a
banking organization typically considers the following factors, among others, as part of
due diligence:
A review of the third party’s overall business strategy and goals helps the banking
organization to understand: (1) how the third party’s current and proposed strategic
business arrangements (such as mergers, acquisitions, and partnerships) may affect the
activity; and (2) the third party’s service philosophies, quality initiatives, and
employment policies and practices (including its diversity policies and practices). Such
information may assist a banking organization to determine whether the third party can
perform the activity in a manner that is consistent with the banking organization’s
appropriately mitigate risks associated with the third-party relationship. This may
include (1) evaluating the third party’s ownership structure (including identifying any
whether the third party has the necessary legal authority to perform the activity, such as
any necessary licenses or corporate powers; (2) determining whether the third party itself
or any owners are subject to sanctions by the Office of Foreign Assets Control; (3)
determining whether the third party has the expertise, processes, and controls to enable
38
international laws and regulations; (4) considering the third party’s responsiveness to any
considering whether the third party has identified, and articulated a process to mitigate,
c. Financial Condition
financial information, including audited financial statements, annual reports, and filings
with the U.S. Securities and Exchange Commission (SEC), among others, helps a
banking organization evaluate whether the third party has the financial capability and
stability to perform the activity. Where relevant and available, a banking organization
may consider other types of information such as access to funds, expected growth,
earnings, pending litigation, unfunded liabilities, reports from debt rating agencies, and
other factors that may affect the third party’s overall financial condition.
d. Business Experience
previous experience in performing the activity; and (3) history of addressing customer
organization’s assessment of the third party’s ability to perform the activity effectively.
Another consideration may include whether there have been significant changes in the
activities offered or in its business model. Likewise, a review of the third party’s
39
services may help determine if statements and assertions accurately represent the
Resources Considerations
other key personnel related to the activity to be performed provides insight into the
consideration is whether the third party and the banking organization, as appropriate,
periodically conduct background checks on the third party’s key personnel and
for identifying and removing the third party’s employees who do not meet minimum
suitability requirements or are otherwise barred from working in the financial services
sector. Another consideration is whether the third party has training to ensure that its
employees understand their duties and responsibilities and are knowledgeable about
applicable laws and regulations as well as other factors that could affect performance or
pose risk to the banking organization. Finally, an evaluation of the third party’s
succession and redundancy planning for key personnel, and of the third party’s processes
for holding employees accountable for compliance with policies and procedures, provides
f. Risk Management
party’s overall risk management, including policies, processes, and internal controls, and
40
alignment with applicable policies and expectations of the banking organization
surrounding the activity. This would include an assessment of the third party’s
the third party’s controls and operations are subject to effective audit assessments,
including independent testing and objective reporting of results and findings. Banking
remediating, and holding management accountable for concerns identified during audits,
internal compliance reviews, or other independent tests, if available. When relevant and
third parties related to relevant domestic or international standards. 11 In such cases, the
banking organization may also consider whether the scope and the results of the SOC
suggest that additional scrutiny of the third party or any of its contractors may be
appropriate.
g. Information Security
banking organization’s systems and information, can help a banking organization decide
whether or not to engage with a third party. Due diligence in this area typically involves
assessing the third party’s information security program, including its consistency with
11
For example, those of the National Institute of Standards and Technology, Accredited Standards
Committee X9, and the International Standards Organization.
41
the banking organization’s information security program, such as its approach to
data. It may also involve determining whether there are any gaps that present risk to the
banking organization or its customers and considering the extent to which the third party
applies controls to limit access to the banking organization’s data and transactions, such
management. It also aids a banking organization when determining whether the third
party keeps informed of, and has sufficient experience in identifying, assessing, and
mitigating, known and emerging threats and vulnerabilities. As applicable, assessing the
third party’s data, infrastructure, and application security programs, including the
software development life cycle and results of vulnerability and penetration tests, can
Finally, due diligence can help a banking organization evaluate the third party’s
It is important to review and understand the third party’s business processes and
information systems that will be used to support the activity. When technology is a major
banking organization’s and the third party’s information systems to identify gaps in
It is also important to review the third party’s processes for maintaining timely and
accurate inventories of its technology and its contractor(s). A banking organization also
42
benefits from understanding the third party’s measures for assessing the performance of
i. Operational Resilience
and recover from any disruption or incidents, both internal and external. 12 Such an
assessment is particularly important where the impact of such disruption could have an
adverse effect on the banking organization or its customers, including when the third
party interacts with customers. It is important to assess options to employ if the third
party’s ability to perform the activity is impaired and to determine whether the third party
disaster recovery and business continuity plans that specify the time frame to resume
activities and recover data. To gain additional insight into a third party’s resilience
capabilities, a banking organization may review (1) the results of operational resilience
and business continuity testing and performance during actual disruptions; (2) the third
party’s telecommunications redundancy and resilience plans; and (3) preparations for
known and emerging threats and vulnerabilities, such as wide-scale natural disasters,
a single provider for multiple activities; and (2) interoperability or potential end of life
12
Disruptive events could include technology-based failures, human error, cyber incidents, pandemic
outbreaks, and natural disasters.
43
issues with the software programming language, computer platform, or data storage
incidents. Such review assists in confirming that the third party’s escalation and
requirements. 13
k. Physical Security
It is important to evaluate whether the third party has sufficient physical and
environmental controls to protect the safety and security of people (such as employees
and customers), its facilities, technology systems, and data, as applicable. This would
typically include a review of the third party’s employee on- and off-boarding procedures
l. Reliance on Subcontractors 14
An evaluation of the volume and types of subcontracted activities and the degree
to which the third party relies on subcontractors helps inform whether such
organization. This typically includes an assessment of the third party’s ability to identify,
13
For example, regulatory requirements regarding incident notification include the FBAs’ “Computer
Security Incident Notification Rule.” See 12 CFR 53 (OCC); 12 CFR 225, subpart N (Board); 12 CFR
304, subpart C (FDIC).
14
Third parties may enlist the help of suppliers, service providers, or other organizations, which this
guidance collectively refers to as subcontractors.
44
manage, and mitigate risks associated with subcontracting, including how the third party
selects and oversees its subcontractors and ensures that its subcontractors implement
m. Insurance Coverage
An evaluation of whether the third party has existing insurance coverage helps a
banking organization determine the extent to which potential losses are mitigated,
including losses posed by the third party to the banking organization or that might
prevent the third party from fulfilling its obligations to the banking organization. Such
losses may be attributable to dishonest or negligent acts; fire, floods, or other natural
disasters; loss of data; and other matters. Examples of insurance coverage may include
fidelity bond; liability; property hazard and casualty; and areas that may not be covered
important to obtain and evaluate information regarding the third party’s legally binding
arrangements may create or transfer risks to the banking organization or its customers.
3. Contract Negotiation
When evaluating whether to enter into a relationship with a third party, a banking
45
proposed contract can meet the banking organization’s business goals and risk
negotiates contract provisions that will facilitate effective risk management and oversight
and that specify the expectations and obligations of both the banking organization and the
third party. A banking organization may tailor the level of detail and comprehensiveness
of such contract provisions based on the risk and complexity posed by the particular
third-party relationship.
While third parties may initially offer a standard contract, a banking organization
organization has limited negotiating power, it is important for the banking organization to
understand any resulting limitations and consequent risks. Possible actions that a banking
organization might take in such circumstances include determining whether the contract
can still meet the banking organization’s needs, whether the contract would result in
increased risk to the banking organization, and whether residual risks are acceptable. If
the contract is unacceptable for the banking organization, it may consider other
approaches, such as employing other third parties or conducting the activity in-house. In
associated with engaging third parties and particularly before executing contracts
46
approve or delegate approval of contracts involving higher-risk activities. Legal counsel
that existing provisions continue to address pertinent risk controls and legal protections.
If new risks are identified, a banking organization may consider renegotiating a contract.
banking organization typically considers the following factors, among others, during
contract negotiations:
the rights and responsibilities of each party. This typically includes specifying the nature
and scope of the business arrangement. Additional considerations may also include, as
support, maintenance, and customer service; (2) the activities the third party will perform;
and (3) the terms governing the use of the banking organization’s information, facilities,
personnel, systems, intellectual property, and equipment, as well as access to and use of
may also be helpful to specify their responsibilities and reporting lines. It is also
important for a banking organization to understand how changes in business and other
circumstances may give rise to the third party’s rights to terminate or renegotiate the
contract.
47
b. Performance Measures or Benchmarks
service-level agreement between the banking organization and the third party can help
specify the measures surrounding the expectations and responsibilities for both parties,
including conformance with policies and procedures and compliance with applicable laws
and regulations. Such measures can be used to monitor performance, penalize poor
obligation for retention and provision of timely, accurate, and comprehensive information
to allow the banking organization to monitor risks and performance and to comply with
timely manner;
• The banking organization’s access to, or use of, the third-party’s data and any
• The banking organization’s access to, or use of, its own or the third-party’s data
and how such data and supporting documentation may be shared with regulators in a
48
• Whether the third party is permitted to resell, assign, or permit access to
customer data, or the banking organization’s data, metadata, and systems, to other
entities;
enforcement actions, regulatory proceedings, or other events pose a significant risk to the
changes, or other business initiatives that could affect the activities involved; and
• Specification of the type and frequency of reports to be received from the third
party, as appropriate. This may include performance reports, financial reports, security
To help ensure that a banking organization has the ability to monitor the
performance of a third party, a contract often establishes the banking organization’s right
to audit and provides for remediation when issues are identified. Generally, a contract
includes provisions for periodic, independent audits of the third party and its relevant
subcontractors, consistent with the risk and complexity of the third-party relationship.
types and frequency of audit reports the banking organization is entitled to receive from
the third party (for example, SOC reports, Payment Card Industry (PCI) compliance
reports, or other financial and operational reviews). Such contract provisions may also
49
reserve the banking organization’s right to conduct its own audits of the third party’s
with applicable laws and regulations, including those activities involving third parties.
The use of third parties does not abrogate these responsibilities. Therefore, it is important
for a contract to specify the obligations of the third party and the banking organization to
comply with applicable laws and regulations. It is also important for the contract to
provide the banking organization with the right to monitor and be informed about the
third party’s compliance with applicable laws and regulations, and to require timely
Contracts that clearly describe all costs and compensation arrangements help
reduce misunderstandings and disputes over billing and help ensure that all compensation
arrangements are consistent with sound banking practices and applicable laws and
schedules, calculations for base services, and any fees based on volume of activity and
for special requests. Contracts also may specify the conditions under which the cost
structure may be changed, including limits on any cost increases. During negotiations, a
banking organization should confirm that a contract does not include incentives that
promote inappropriate risk taking by the banking organization or the third party. A
banking organization should also consider whether the contract includes burdensome
50
upfront or termination fees, or provisions that may require the banking organization to
reimburse the third party. Appropriate provisions indicate which party is responsible for
payment of legal, audit, and examination fees associated with the activities involved.
Another consideration is outlining cost and responsibility for purchasing and maintaining
In order to prevent disputes between the parties regarding the ownership and
extent to which the third party has the right to use the banking organization’s
name, logo, trademark, and copyrighted material. Provisions that indicate whether any
data generated by the third party become the banking organization’s property help avert
the third party related to its acquisition of licenses or subscriptions for use of any
intellectual property developed by other third parties. When the banking organization
to provide for the banking organization’s access to source code and programs under
With respect to contracts with third parties, there may be increased risks related to
typically prohibit the use and disclosure of banking organization and customer
information by a third party and its subcontractors, except as necessary to provide the
51
contracted activities or comply with legal requirements. If the third party receives
personally identifiable information, contract provisions are important to ensure that the
third party implements and maintains appropriate security measures to comply with
Another important provision is one that specifies when and how the third party
intrusions. Considerations may include the types of data stored by the third party, legal
obligations for the banking organization to disclose the breach to its regulators or
customers, the potential for consumer harm, or other factors. Such provisions typically
stipulate that the data intrusion notification to the banking organization include estimates
of the effects on the banking organization and its customers and specify corrective action
to be taken by the third party. They also address the powers of each party to change
security and risk management procedures and requirements and resolve any
confidentiality and integrity issues arising out of shared use of facilities owned by the
third party. Typically, such provisions stipulate whether and how often the banking
organization and the third party will jointly practice incident management exercises
Both internal and external factors or incidents (for example, natural disasters or
cyber incidents) may affect a banking organization or a third party and thereby disrupt the
for continuation of the activity in the event of problems affecting the third party’s
52
for the contract to address the third party’s responsibility for appropriate controls to
support operational resilience of the services, such as protecting and storing programs,
backing up datasets, addressing cybersecurity issues, and maintaining current and sound
To help ensure maintenance of operations, contracts often require the third party
to provide the banking organization with operating procedures to be carried out in the
event business continuity plans are implemented, including specific recovery time and
recovery point objectives. Contracts may also stipulate whether and how often the
banking organization and the third party will jointly test business continuity plans.
Another consideration is whether the contract provides for the transfer of the banking
organization’s accounts, data, or activities to another third party without penalty in the
for a banking organization to be held liable for claims and be reimbursed for damages
arising from a third party’s misconduct, including negligence and violations of laws and
the extent to which the banking organization will be held liable for claims or be
reimbursed for damages based on the failure of the third party or its subcontractor to
perform, including failure of the third party to obtain any necessary intellectual property
liability are in proportion to the amount of loss the banking organization might
53
experience as a result of third-party failures, or whether indemnification clauses require
the banking organization to hold the third party harmless from liability.
k. Insurance
One way in which a banking organization can protect itself against losses caused
by or related to a third party and the products and services provided through third-party
typically require the third party to (1) maintain specified types and amounts of insurance
insured); (2) notify the banking organization of material changes to coverage; and (3)
coverage should be commensurate with the risk of possible losses, including those caused
by the third party to the banking organization or that might prevent the third party from
fulfilling its obligations to the banking organization, and the activities performed.
l. Dispute Resolution
Disputes regarding a contract can delay or otherwise have an adverse impact upon
the activities performed by a third party, which may negatively affect the banking
contract should establish a dispute resolution process to resolve problems between the
banking organization and the third party in an expeditious manner, and whether the third
party should continue to provide activities to the banking organization during the dispute
provisions that may impact the banking organization’s ability to resolve disputes in a
54
m. Customer Complaints
a banking organization may find it useful to include a contract provision to ensure that
customer complaints and inquiries are handled properly. Effective contracts typically
specify whether the banking organization or the third party is responsible for responding
to include provisions for the third party to receive and respond to customer complaints
and inquiries in a timely manner and to provide the banking organization with sufficient,
timely, and usable information to analyze customer complaint and inquiry activity and
include provisions for the banking organization to receive prompt notification from the
n. Subcontracting
result in risk due to the absence of a direct relationship between the banking organization
and the subcontractor, further lessening the banking organization’s direct control of
activities. The impact on a banking organization’s ability to assess and control risks may
be especially important if the banking organization uses third parties for higher-risk
activities, including critical activities. For this reason, a banking organization may want
to address when and how the third party should notify the banking organization of its use
or intent to use a subcontractor and whether specific subcontractors are prohibited by the
55
entity without the banking organization’s consent. Where subcontracting is integral to
the activity being performed for the banking organization, it is important to consider
conformance with performance measures, periodic audit results, and compliance with
laws and regulations. Where appropriate, a banking organization may consider including
a provision that states the third party’s liability for activities or actions by its
subcontractors and which party is responsible for the costs and resources required for any
to reserve the right to terminate the contract without penalty if the third party’s
law and jurisdictional provisions that provide dispute adjudication under the laws of a
single jurisdiction, whether in the United States or elsewhere. When engaging with
includes a jurisdiction other than the United States, it is important to understand that such
contracts and covenants may be subject to the interpretation of foreign courts relying on
laws in those jurisdictions. It may be warranted to seek legal advice on the enforceability
of the proposed contract with a foreign-based third party and other legal ramifications,
Contracts can protect the ability of the banking organization to change third
56
contract stipulates what constitutes default, identifies remedies, allows opportunities to
cure defaults, and establishes the circumstances and responsibilities for termination.
to allow for the orderly transition of the activity, when desired or necessary, without
prohibitive expense;
• Provide for the timely return or destruction of the banking organization’s data,
• Assign all costs and obligations associated with transition and termination; and
notice and without penalty, if formally directed by the banking organization’s primary
q. Regulatory Supervision
the performance of activities by third parties for the banking organization is subject to
regulatory examination and oversight, including appropriate retention of, and access to,
all relevant documentation and other materials. 15 This can help ensure that a third party
is aware of its role and potential liability in its relationship with a banking organization.
4. Ongoing Monitoring
Ongoing monitoring enables a banking organization to: (1) confirm the quality
and sustainability of a third party’s controls and ability to meet contractual obligations;
(2) escalate significant issues or concerns, such as material or repeat audit findings,
15
See 12 U.S.C. 1464(d)(7)(D) and 1867(c)(1).
57
deterioration in financial condition, security breaches, data loss, service interruptions,
compliance lapses, or other indicators of increased risk; and (3) respond to such
the duration of a third-party relationship, commensurate with the level of risk and
complexity of the relationship and the activity performed by the third party. Ongoing
activities, including critical activities. Because both the level and types of risks may
change over the lifetime of third-party relationships, banking organizations may adapt
Typical monitoring activities include: (1) review of reports regarding the third
party’s performance and the effectiveness of its controls; (2) periodic visits and meetings
with third-party representatives to discuss performance and operational issues; and (3)
regular testing of the banking organization’s controls that manage risks from its third-
perform direct testing of the third party’s own controls. To gain efficiencies or leverage
58
monitoring. 16 To support effective monitoring, a banking organization dedicates
sufficient staffing with the necessary expertise, authority, and accountability to perform a
banking organization typically considers the following factors, among others, as part of
ongoing monitoring:
consistency with the banking organization’s strategic goals, business objectives, risk
• Changes to the third party’s business strategy and its agreements with other
entities that may pose new or increased risks or impact the third party’s ability to meet
contractual obligations;
obligations to others;
• Relevant audits, testing results, and other reports that address whether the
third party remains capable of managing risks and meeting contractual obligations and
regulatory requirements;
• The third party’s ongoing compliance with applicable laws and regulations
16
Refer to important considerations discussed in “Due Diligence and Third-Party Selection” of this
guidance when a banking organization chooses to engage external resources to supplement its third-party
risk management.
59
• The third party’s reliance on, exposure to, and use of subcontractors, the
location of subcontractors (and any related data), and the third party’s own risk
• Training provided to employees of the banking organization and the third party;
incidents impacting the activity, including any resulting adjustments to the third party’s
operations or controls;
plans, and testing results to evaluate the third party’s ability to respond to and recover
• Factors and conditions external to the third party that could affect its
performance and financial and operational standing, such as changing laws, regulations,
• The volume, nature, and trends of customer inquiries and complaints, the
adequacy of the third party’s responses (if responsible for handling customer inquiries or
5. Termination
expiration or breach of the contract, the third party’s failure to comply with applicable
laws or regulations, or a desire to seek an alternate third party, bring the activity in-house,
60
or discontinue the activity. When this occurs, it is important for management to
another third party, brought in-house, or discontinued. Depending on the degree of risk
• Relevant capabilities, resources, and the time frame required to transition the
activity to another third party or bring in-house while still managing legal, regulatory,
system connections and access control, or other control concerns that require additional
risk management and monitoring after the end of the third-party relationship;
customers, if the termination happens as a result of the third party’s inability to meet
expectations.
GOVERNANCE
There are a variety of ways for banking organizations to structure their third-party
61
their third-party risk management processes among their business lines. 17 Other banking
organizations may centralize the processes under their compliance, information security,
structures its process, the following practices are typically considered throughout the
third-party risk management life cycle, 18 commensurate with risk and complexity.
directors has ultimate responsibility for providing oversight for third-party risk
management and holding management accountable. The board also provides clear
guidance regarding acceptable risk appetite, approves appropriate policies, and ensures
risk management policies, procedures, and practices, commensurate with the banking
organization’s risk appetite and the level of risk and complexity of its third-party
relationships.
In carrying out its responsibilities, the board of directors (or a designated board
17
Each applicable business line can provide valuable input into the third-party risk management process,
for example, by completing risk assessments, reviewing due diligence information, and evaluating the
controls over the third-party relationship.
18
Refer to Figure 1: Stages of the Risk Management Life Cycle.
62
• Whether third-party relationships are managed in a manner consistent with the
banking organization’s strategic goals and risk appetite and in compliance with
63
• Assessing whether the banking organization’s compliance management
system is appropriate to the nature, size, complexity, and scope of its third-party
relationships;
• Terminating business arrangements with third parties when they do not meet
2. Independent Reviews
to assess the adequacy of its third-party risk management processes. Such reviews
and controlled;
• Whether the banking organization’s processes and controls are designed and
operating adequately;
management activities throughout the third-party risk management life cycle, including
64
• Whether conflicts of interest or appearances of conflicts of interest are
whether and how to adjust its third-party risk management process, including its policies,
promptly and thoroughly to issues or concerns identified and escalate them to the board,
as appropriate.
their life cycle. Documentation and reporting, key elements that assist those within or
outside the banking organization who conduct control activities, will vary among banking
Examples of processes that support effective documentation and internal reporting that
the agencies have observed include, but are not limited to:
risk presented, related subcontractors) that clearly identifies those relationships associated
• Executed contracts;
• Remediation plans and related reports addressing the quality and sustainability
65
• Risk and performance reports required and received from the third party as
events that pose, or may pose, a material risk to the banking organization;
The concepts discussed in this guidance are relevant for all third-party
relationships and are provided to banking organizations to assist in the tailoring and
organization’s size, complexity, risk profile, and the nature of its third-party
relationships. Each agency will review its supervised banking organizations’ risk
Supervisory reviews will evaluate risks and the effectiveness of risk management to
determine whether activities are conducted in a safe and sound manner and in compliance
relationships, that not all third-party risk relationships present the same risks, and that
banking organizations accordingly tailor their practices to the risks presented. Thus, the
66
scope of the supervisory review depends on the degree of risk and the complexity
associated with the banking organization’s activities and third-party relationships. When
risk profile and key aspects of financial and operational performance, including
activities performed by the third party and assess compliance with applicable laws and
regulations;
• Highlight and discuss any material risks and deficiencies in the banking
organization’s risk management process with senior management and the board of
directors as appropriate;
remediation of any deficiencies, particularly those associated with the oversight of third
applicable rating system and highlight any material risks and deficiencies in the Report of
Examination.
When circumstances warrant, an agency may use its legal authority to examine
67
Such examinations may evaluate the third party’s ability to fulfill its obligations in a safe
and sound manner and comply with applicable laws and regulations, including those
designed to protect customers and to provide fair access to financial services. The
agencies may pursue corrective measures, including enforcement actions, when necessary
Michael J. Hsu,
Acting Comptroller of the Currency.
Ann E. Misback,
Secretary of the Board.
68