Article

Regulatory guidance on third-party risk management for banks

Managing risk throughout the third-party relationship lifecycle

August 28, 2026

Key takeaways

Bank building icon with a dollar symbol and columns, representing financial services or banking.

As third-party partnerships increase, so does the need for effective risk management.

 Line Illustration of a magnifying glass

Regulators are focusing on governance, documentation and risk-based oversight.

monitoring

Ongoing monitoring is essential as institutions navigate a rapidly changing environment.

#
Risk consulting Financial services Financial institutions

This article has been updated from the original, published Aug. 14, 2023, to reflect new events, conditions or research.

Financial institutions are increasingly partnering with third parties to implement advanced banking technologies that can generate efficiencies and cost savings, or to add new banking products to drive revenue.

As these partnerships increase, so does the need for effective risk management and oversight. Since the June 2023 interagency guidance issued by the Federal Deposit Insurance Corp., the Board of Governors of the Federal Reserve, and the Office of the Comptroller of the Currency, regulators have reinforced expectations through supervisory activity and related risk alerts, emphasizing consistent application of third-party risk management practices across institutions of all sizes.

While the 2023 guidance remains foundational, recent regulatory focus has been on execution—particularly governance, documentation and risk-based oversight. Institutions are expected to demonstrate that their programs are operationalized, monitored and auditable.

This may be most significant for small and midsize banks, which often have less mature third-party risk management frameworks than large banks. Many will need to evolve from fragmented vendor management to a fully integrated, lifecycle‑based third-party risk management program with clear ownership, risk segmentation and board visibility.

Additionally, the rapid rise of fintech has fundamentally complicated the risk landscape. Fintech companies are no longer just vendors to banks; they are embedded operators within the banking value chain. As a result, traditional due diligence models are being strained by opaque ownership structures, reliance on fourth parties—such as a fintech company's vendors and service providers—and rapid scaling.

The third-party relationship lifecycle

The 2023 guidance outlines five stages in the third-party relationship lifecycle and the risk management practices institutions should apply at each stage:

1. Planning

Before conducting business with a third party, an institution needs an effective plan to determine the risks involved and the related complexities. Once the risks are identified, the institution can design and establish mitigation techniques.

Regulators emphasize up-front risk tiering and clear alignment between third-party relationships and the institution’s strategic objectives and have heightened their scrutiny of fintech partnerships and embedded finance models.

The guidance specifies that, to understand the risks associated with a third party, an institution should consider the following in the planning process:

  • The strategic purpose of the arrangement
  • The benefits and risks of the relationship
  • The volume of transactions involved
  • Related direct and indirect costs
  • The impact of the relationship on employees and customers
  • The physical and information security implications
  • Monitoring of the third party’s compliance with laws and regulations
  • Ongoing oversight of the relationship
  • Potential contingency plans

After evaluating these factors, an institution can build a risk matrix to visualize whether the exposure involved in the relationship would be within its risk tolerance.

2. Due diligence

The guidance calls for due diligence proportionate to the risk associated with the potential third-party relationship. More complex or higher-risk arrangements warrant closer scrutiny.

Supervisory feedback since 2023 has underscored the need for more robust documentation of due diligence decisions, including clear evidence of how institutions assess a third party’s financial condition, operational resilience, cybersecurity posture and subcontractor dependencies.

No matter the arrangement, institutions need to evaluate their ability to identify, assess, monitor and mitigate risks that arise.

3. Contract negotiation

A third-party contract should allow the bank to perform continuous, effective risk management practices. If negotiating these terms is difficult, the institution needs to analyze the related risk and weigh whether to enter into a relationship.

As part of its oversight responsibilities, the board of directors should stay informed on negotiations, whether through direct involvement or updates from an approved negotiating delegate.

4. Ongoing monitoring

Ongoing monitoring is essential as institutions navigate a rapidly changing banking environment. The 2023 guidance states that organizations’ ongoing monitoring, like other third-party risk management processes, “should be appropriate for the risks associated with each third-party relationship, commensurate with the banking organization’s size, complexity, and risk profile and with the nature of its third-party relationships.”

Technology is evolving quickly, and advanced tools such as artificial intelligence bring new considerations and capabilities to the industry, as well as unique risks. Establishing mechanisms to track the risk landscape and identify emerging risks is just as important as conducting regular reviews of current risks.

5. Termination

When an institution decides a third-party relationship has run its course, efficient termination of the contract is important—as is determining whether to transition the activity to another third party or bring it in-house.

Governance practices

Regulators have also highlighted three critical governance practices for third-party relationships:

  • Oversight and accountability: The board of directors is ultimately responsible for the oversight of third-party risk management, which includes guiding management on the acceptable level of risk in third-party relationships, as well as approving risk management policies and procedures.
  • Independent reviews: Independent, periodic reviews are critical for assessing whether the institution’s third-party risk management processes, procedures and controls are adequate and effective.
  • Documentation and reporting: To support compliance with the guidance, institutions must thoroughly document their third-party risk management processes, procedures and controls, as well as the outcomes of related independent reviews.

Looking ahead

Risk management is an evolving process of identifying, assessing and mitigating risk. As financial institutions continue to partner with third parties to offer new capabilities, effective oversight of those relationships is essential to managing risk, meeting regulatory expectations and supporting safe and sound operations.

As supervisory focus shifts from policy adoption to execution, institutions that can demonstrate a mature, well-documented third-party risk management program will be better positioned to withstand continuing scrutiny of third-party relationships.

RSM contributors

Related insights

Contact our risk professionals

Complete this form and an RSM representative will be in touch shortly.

Subscribe to Financial Services Insights

Sign up now for a monthly update on the marketplace trends important to financial institutions, capital markets, asset management and other financial services.