As third-party partnerships increase, so does the need for effective risk management.
As third-party partnerships increase, so does the need for effective risk management.
Regulators are focusing on governance, documentation and risk-based oversight.
Ongoing monitoring is essential as institutions navigate a rapidly changing environment.
This article has been updated from the original, published Aug. 14, 2023, to reflect new events, conditions or research.
Financial institutions are increasingly partnering with third parties to implement advanced banking technologies that can generate efficiencies and cost savings, or to add new banking products to drive revenue.
As these partnerships increase, so does the need for effective risk management and oversight. Since the June 2023 interagency guidance issued by the Federal Deposit Insurance Corp., the Board of Governors of the Federal Reserve, and the Office of the Comptroller of the Currency, regulators have reinforced expectations through supervisory activity and related risk alerts, emphasizing consistent application of third-party risk management practices across institutions of all sizes.
While the 2023 guidance remains foundational, recent regulatory focus has been on execution—particularly governance, documentation and risk-based oversight. Institutions are expected to demonstrate that their programs are operationalized, monitored and auditable.
This may be most significant for small and midsize banks, which often have less mature third-party risk management frameworks than large banks. Many will need to evolve from fragmented vendor management to a fully integrated, lifecycle‑based third-party risk management program with clear ownership, risk segmentation and board visibility.
Additionally, the rapid rise of fintech has fundamentally complicated the risk landscape. Fintech companies are no longer just vendors to banks; they are embedded operators within the banking value chain. As a result, traditional due diligence models are being strained by opaque ownership structures, reliance on fourth parties—such as a fintech company's vendors and service providers—and rapid scaling.
The 2023 guidance outlines five stages in the third-party relationship lifecycle and the risk management practices institutions should apply at each stage:
Before conducting business with a third party, an institution needs an effective plan to determine the risks involved and the related complexities. Once the risks are identified, the institution can design and establish mitigation techniques.
Regulators emphasize up-front risk tiering and clear alignment between third-party relationships and the institution’s strategic objectives and have heightened their scrutiny of fintech partnerships and embedded finance models.
The guidance specifies that, to understand the risks associated with a third party, an institution should consider the following in the planning process:
After evaluating these factors, an institution can build a risk matrix to visualize whether the exposure involved in the relationship would be within its risk tolerance.
The guidance calls for due diligence proportionate to the risk associated with the potential third-party relationship. More complex or higher-risk arrangements warrant closer scrutiny.
Supervisory feedback since 2023 has underscored the need for more robust documentation of due diligence decisions, including clear evidence of how institutions assess a third party’s financial condition, operational resilience, cybersecurity posture and subcontractor dependencies.
No matter the arrangement, institutions need to evaluate their ability to identify, assess, monitor and mitigate risks that arise.
A third-party contract should allow the bank to perform continuous, effective risk management practices. If negotiating these terms is difficult, the institution needs to analyze the related risk and weigh whether to enter into a relationship.
As part of its oversight responsibilities, the board of directors should stay informed on negotiations, whether through direct involvement or updates from an approved negotiating delegate.
Ongoing monitoring is essential as institutions navigate a rapidly changing banking environment. The 2023 guidance states that organizations’ ongoing monitoring, like other third-party risk management processes, “should be appropriate for the risks associated with each third-party relationship, commensurate with the banking organization’s size, complexity, and risk profile and with the nature of its third-party relationships.”
Technology is evolving quickly, and advanced tools such as artificial intelligence bring new considerations and capabilities to the industry, as well as unique risks. Establishing mechanisms to track the risk landscape and identify emerging risks is just as important as conducting regular reviews of current risks.
When an institution decides a third-party relationship has run its course, efficient termination of the contract is important—as is determining whether to transition the activity to another third party or bring it in-house.
Regulators have also highlighted three critical governance practices for third-party relationships:
Risk management is an evolving process of identifying, assessing and mitigating risk. As financial institutions continue to partner with third parties to offer new capabilities, effective oversight of those relationships is essential to managing risk, meeting regulatory expectations and supporting safe and sound operations.
As supervisory focus shifts from policy adoption to execution, institutions that can demonstrate a mature, well-documented third-party risk management program will be better positioned to withstand continuing scrutiny of third-party relationships.