The four U.S. financial regulators have put forth new guidelines regarding third-party risk management for banks and credit unions. These guidelines aim to allow financial institutions to tailor their oversight of external relationships based on the specific risks posed by each relationship. The proposed guidelines would replace the existing guidance and give banks and credit unions more flexibility in determining the level of oversight needed for each third-party relationship.
Under the proposed guidelines, financial institutions would need to assess both the potential harm from an external provider and the likelihood of that harm occurring. Institutions could then adjust their controls, contracts, and monitoring efforts accordingly based on the level of risk involved. The framework also acknowledges that some residual risk may be acceptable based on the institution’s risk appetite and ability to operate safely.
One key aspect of the proposal is the emphasis on matching the level of oversight to the level of risk involved in each third-party relationship. This approach aims to address concerns that the current guidance has been applied too broadly and has not taken into account the differences among vendors. Additionally, the proposal aims to encourage banks to work with newer service providers in a way that is both safe and efficient.
In addition to the main proposal, the Federal Reserve has also requested feedback on a separate guide for traditional community banking organizations. This guide is tailored specifically for locally focused banks with assets of less than $30 billion. It covers areas such as operational resilience, information security, legal compliance, and financial resilience, providing practical information that smaller institutions have requested.
However, not all regulators are in agreement with the proposed guidelines. Federal Reserve Governor Michael Barr has expressed concerns that the wording of the proposals could weaken oversight rather than strengthen it. Barr particularly objected to the proposed “material financial risk” standard for supervisory action, which he believes could make banks less proactive in addressing potential issues.
Overall, the proposed guidelines aim to provide banks and credit unions with more flexibility in managing third-party risks while ensuring that appropriate oversight is in place. The regulators are seeking feedback on the proposals before finalizing them and withdrawing the current third-party risk framework. This new approach could have implications for a wide range of third-party relationships, including those involving fintech companies and crypto service providers.
