The interagency guidance on third-party relationships is set to be replaced. It was issued in June 2023 and has anchored every vendor-management program in the industry since. On September 11 the Federal Reserve, FDIC, OCC, and NCUA requested comment on proposed guidance that would help institutions “better align and tailor” third-party risk management “to the risks of individual third-party relationships.” When it is finalized, the banking agencies plan to rescind the existing guidance and replace it. Comments are due November 16.
The agencies are unusually direct about why. Their proposal says the 2023 guidance “frequently has been interpreted in an overly broad manner and with an insufficient focus on tailoring,” and that it “unintentionally incentivized overly-process-driven approaches that fail to prioritize higher-risk relationships.” The replacement makes risk identification and assessment the foundation. Oversight would scale to the magnitude and likelihood of harm that a specific relationship poses, instead of to the category of activity it touches.
Core providers, named as the hardest case
Alongside the proposal, the Fed, FDIC, and OCC issued a joint statement on community banks’ engagement with core service providers. It calls core providers community banks’ “most material, complex, and highest-risk third-party relationships,” and acknowledges that “a significant percentage of the core provider market is represented by just a few large providers, which limits CBOs’ negotiating power.”
The statement then turns that into supervisory leverage. When the agencies decide how much examination attention to give a core provider, they will weigh its transparency. That covers its willingness to hand over timely due-diligence information, its use of measurable service levels, its disclosure of operational and security incidents, and its billing practices. They will also weigh contract terms that obstruct a bank’s exit or its use of supplemental providers. The Fed also proposed a separate third-party guide for the community banks it supervises.
For the first time, a core provider’s refusal to hand you a SOC report is framed as the provider’s supervisory problem as well as yours.
The anchor for AI vendors moves too
In August we pointed to the 2023 guidance as one of the two anchors that still govern generative-AI vendors after the model-risk rewrite carved GenAI out of scope. That anchor is now in motion. Tailoring cuts both ways. A lighter touch for low-risk vendors is only defensible if your risk assessment says why. An AI feature embedded in a core or compliance platform is exactly the kind of relationship whose risk rating needs to be written down instead of assumed.
- Keep operating under the 2023 guidance until a final version replaces it. The proposal is non-binding and changes nothing today.
- Start the re-tiering now: rank every third party by assessed magnitude and likelihood of harm, and record the rationale. That record is what tailoring will be judged on.
- Comment by November 16, and use the core-provider statement in your next renewal. Ask for SOC reports, measurable SLAs, and incident-notice terms in writing.
Zovos keeps a risk rating and a written rationale on every vendor in your inventory, including the AI features inside them. A risk-tailored program then has its evidence attached from day one.
This is for information only and is not legal advice. The guidance is proposed and non-binding, so confirm your obligations with counsel before acting.