Third-Party Vendor Risk Management for Banks: Rules and Contracts

Third-party vendor risk management for banks is governed primarily by the Interagency Guidance on Third-Party Relationships: Risk Management, finalized on June 6, 2023, by the OCC, Federal Reserve, and FDIC. The core principle is short: using a third party does not reduce or remove your institution’s obligation to conduct all activities in a safe and sound manner and in compliance with applicable laws, including consumer protection and customer information security.1FDIC. Interagency Guidance on Third-Party Relationships: Risk Management Everything else in the framework flows from that.

What Rules Actually Apply

The 2023 interagency guidance replaced the separate frameworks each federal banking agency had used previously. It does not carry the force of law and does not impose new legal requirements, but it describes the practices examiners use to evaluate a bank’s risk management, so falling short invites scrutiny under safety and soundness standards.2Federal Register. Interagency Guidance on Third-Party Relationships: Risk Management

Several enforceable rules sit alongside the guidance. The Bank Service Company Act gives federal banking agencies direct authority to examine and regulate companies that provide services to banks, treating those service companies much like insured depository institutions for enforcement purposes.3Office of the Law Revision Counsel. 12 USC 1867 – Regulation and Examination of Bank Service Companies The Gramm-Leach-Bliley Act’s Safeguards Rule requires financial institutions to take reasonable steps to select vendors capable of maintaining appropriate safeguards, to require those safeguards by contract, and to periodically assess whether vendors are holding up their end.4eCFR. 16 CFR 314.4 – Elements The interagency guidelines at 12 CFR Part 364 Appendix B require every insured institution to exercise appropriate due diligence in selecting service providers, contractually require them to implement appropriate security measures, and monitor them through audits or equivalent evaluations based on the institution’s risk assessment.5Legal Information Institute. 12 CFR Appendix B to Part 364 – Interagency Guidelines Establishing Information Security Standards Where a vendor handles payment card data, PCI DSS compliance also applies.

Board and Management Responsibilities

The board of directors holds ultimate responsibility for overseeing third-party risk management and holding management accountable. Under the interagency guidance, the board should provide clear direction on acceptable risk appetite, approve policies governing vendor relationships, and confirm that appropriate procedures are in place. For higher-risk or critical vendor relationships, the board or a designated committee should be aware of and may need to approve specific contracts.2Federal Register. Interagency Guidance on Third-Party Relationships: Risk Management

The board also needs periodic reports on how management handles planning, due diligence, contract negotiation, and ongoing monitoring, and examiners want to see the board confirmed management took action on problems the reports surfaced. How the day-to-day program is structured is flexible. Some banks centralize vendor risk under a single compliance or procurement function; others distribute accountability across business lines. Regulators do not prescribe a model, but they expect the approach to be deliberate and documented, with clear ownership at every stage of the lifecycle.2Federal Register. Interagency Guidance on Third-Party Relationships: Risk Management

Building an Inventory and Tiering Vendors by Risk

Every program starts with a comprehensive inventory of all third-party relationships, ranked by risk so oversight resources go where exposure is greatest. A relationship typically qualifies as critical or high-risk if the vendor performs a core banking function, handles sensitive customer data, or could cause significant customer impact or financial loss if it failed.

Risk tiering considers the inherent risk of the outsourced activity: how complex it is, the scope of data the vendor can access, and the potential consequences for the institution’s legal standing or regulatory compliance. The interagency guidance states that risk management practices should be commensurate with the risk and complexity of each relationship.1FDIC. Interagency Guidance on Third-Party Relationships: Risk Management The tier assigned drives everything downstream: due diligence depth, monitoring frequency, contractual complexity, and reporting to the board.

Concentration risk deserves separate attention. If several critical vendors run on the same cloud platform, a single outage there can disable multiple services at once. The guidance calls out “dependency on a single provider for multiple activities” as a key consideration for operational resilience.6Board of Governors of the Federal Reserve System. Interagency Guidance on Third-Party Relationships

Pre-Contract Due Diligence

Before signing, the institution must evaluate whether the vendor can actually deliver what it promises, securely and reliably. Due diligence is extensive for critical vendors and lighter for lower-risk relationships.2Federal Register. Interagency Guidance on Third-Party Relationships: Risk Management For high-risk relationships, the assessment covers, at a minimum:

  • Financial condition, using audited financial statements and other indicators of the vendor’s ability to support the service long-term.
  • Information security controls, evaluated for consistency with the bank’s own program, including encryption and vulnerability testing; SOC reports from independent auditors are the standard tool.
  • Operational resilience, confirmed through tested disaster recovery and business continuity plans.
  • Legal and regulatory compliance, including ownership structure, any history of enforcement actions, and processes to comply with applicable laws.
  • Subcontractor reliance, meaning how heavily the vendor depends on downstream providers and whether it can manage those relationships effectively.
  • Background and qualifications of key personnel running the vendor.

The point is not to collect documents and file them. If a SOC report flags control deficiencies, the team needs to judge whether those gaps matter for the specific use case, not simply confirm the report exists.

Subcontractors and Fourth-Party Risk

A vendor may outsource parts of its operation to companies the bank has never vetted. The guidance expects the institution to evaluate how heavily a vendor relies on subcontractors, whether the vendor can effectively oversee them, and whether their geographic location introduces additional risk.6Board of Governors of the Federal Reserve System. Interagency Guidance on Third-Party Relationships The contract needs to require notification before subcontracting, prohibit subcontracting without consent where appropriate, and hold the vendor liable for its subcontractors’ performance.

Foreign-Based Vendors

Under OCC guidance on foreign-based service providers, banks must ensure that offshore arrangements do not limit the regulator’s ability to access data or information needed to supervise the bank’s operations in a timely manner. Due diligence must include choice-of-law and forum provisions, country-specific risks like political instability and data sovereignty laws, and compliance with U.S. sanctions requirements. The bank also needs sufficient internal expertise to oversee the relationship across borders, including ongoing monitoring of country and compliance risk.7Office of the Comptroller of the Currency. Bank Use of Foreign-Based Third-Party Service Providers: Risk Management Guidance

Contract Provisions Regulators Expect

The contract is the primary control once the relationship begins. The interagency guidance identifies specific provisions to negotiate, tailored to the risk and complexity of the relationship.8Office of the Comptroller of the Currency. Interagency Guidance on Third-Party Relationships: Risk Management For critical vendor agreements, examiners expect to see:

Indemnification and liability provisions get attention from examiners too. Accepting vendor-friendly caps that leave the institution exposed to losses far above the contract value is a common weakness.

Ongoing Monitoring

Due diligence does not end when the contract is signed. The interagency guidance treats ongoing monitoring as a distinct, continuous phase of the lifecycle.2Federal Register. Interagency Guidance on Third-Party Relationships: Risk Management For critical relationships, that means tracking performance against SLAs, reviewing updated SOC reports and other control documentation, and reassessing the vendor’s risk profile at least annually.

Monitoring should also catch changes that shift the risk equation: ownership changes, shifts in strategic direction, deterioration in financial health, or turnover of key personnel. A vendor acquisition can change the technology platform and the people managing the account. The program needs to surface these changes early, and the institution needs a defined process for escalating concerns to senior management and the board.

Depth should match the tier. A critical core processing vendor warrants regular meetings, performance dashboards, and annual on-site reviews or independent assessments. A low-risk commodity vendor may need only periodic confirmation that the service is performing as expected.

Incident Notification Timelines

When a security incident affects a vendor, federal rules impose short reporting timelines on both the institution and the service provider.

The 36-Hour Rule for Banks

Under the Computer-Security Incident Notification Rule, banking organizations supervised by the OCC, Federal Reserve, or FDIC must notify their primary federal regulator as soon as possible, and no later than 36 hours after determining that a “notification incident” has occurred.9eCFR. 12 CFR Part 53 – Computer-Security Incident Notification A notification incident is a computer-security event that has materially disrupted or degraded (or is reasonably likely to do so) the institution’s ability to carry out banking operations, deliver products and services to a material portion of its customers, or operate a business line whose failure would result in material revenue or franchise value loss.10eCFR. 12 CFR Part 304 Subpart C – Computer-Security Incident Notification The clock starts on determination, not on the incident itself, but waiting for complete information before making the determination is not a valid excuse for delay.

Service Provider Notification Duty

Vendors have their own duty under the same rule. A bank service provider must notify each affected banking organization as soon as possible after determining it has experienced a computer-security incident that has materially disrupted or is reasonably likely to disrupt covered services for four or more hours. Notice goes to a designated contact at the institution, or to the CEO and CIO if no contact has been established.11FDIC. Computer-Security Incident Notification Final Rule The contract should specify who receives these notices and through what channel, so a vendor notification does not land in an unmonitored inbox.

Federally insured credit unions operate under a different timeline. The NCUA requires notification no later than 72 hours after reasonably believing a reportable cyber incident has occurred, which includes incidents caused by a compromise at a third-party service provider or cloud host.12National Credit Union Administration. Cyber Incident Notification Requirements

Termination and Exit Planning

Termination provisions belong in the original contract, not in a scramble during a crisis. The interagency guidance calls for contracts to include provisions for orderly transition and return of data upon termination.2Federal Register. Interagency Guidance on Third-Party Relationships: Risk Management An effective exit plan defines the triggers for exit, how the vendor will return or destroy data, the notice period and transition support, whether a backup provider or in-house alternative can absorb the work, and how affected customers will be informed.

Common triggers include vendor financial distress, repeated service failures or missed SLAs, regulatory violations, and strategic changes that make the relationship obsolete. The contract should allow termination without penalty when a regulator directs it. When a vendor knows the bank cannot easily leave, the bank’s ability to enforce standards erodes.

For critical relationships, the institution should maintain a documented transition plan, reviewed and updated periodically, that identifies operational steps, responsible parties, and timelines for moving services to a new provider or bringing them in-house.