U.S. banking regulators moved Thursday to tighten and standardize oversight of the sprawling web of outside vendors that support modern finance, unveiling proposed guidance on third-party risk management and a separate statement aimed at community banks' relationships with core service providers.
The Federal Deposit Insurance Corporation, the Federal Reserve Board, the National Credit Union Administration and the Office of the Comptroller of the Currency said they are seeking public comment on proposed guidance intended to help financial institutions better manage the risks that arise when critical functions are outsourced to third parties. The agencies said the proposal reflects their supervisory experience and lessons learned from examinations of banks' and credit unions' third-party risk management practices.
The guidance is meant to push institutions toward a more tailored, principles-based approach, rather than a one-size-fits-all compliance checklist. Regulators said the objective is to help banks and credit unions align their risk management practices with the specific risks posed by individual third-party relationships, a recognition that not every vendor arrangement carries the same operational, financial or compliance exposure.
The agencies emphasized that the proposal is non-binding, consistent with the nature of supervisory guidance. Still, the move is significant for an industry that has become increasingly dependent on outside providers for payments processing, cloud services, cybersecurity, data management, loan servicing and other essential functions. As financial institutions have outsourced more of their infrastructure, regulators have grown more concerned that weaknesses at a vendor can quickly become weaknesses at the bank itself.
When finalized, the federal bank regulatory agencies plan to rescind existing third-party risk management guidance and replace it with the new framework. Regulators said the change is intended to promote consistency across the supervisory landscape while also supporting prudent innovation in the banking industry. The agencies did not provide a timeline for final adoption, but comments will be due 60 days after publication in the Federal Register.
In a separate but related step, the agencies also issued a statement on community banks' engagement with core service providers. That statement is aimed at the smaller institutions that often rely heavily on a limited number of external providers for essential banking infrastructure. The agencies said the statement discusses certain factors they will consider in making supervisory and enforcement decisions related to those core providers, underscoring that the quality and resilience of those relationships can have direct implications for safety and soundness.
The Federal Reserve Board also separately requested comment on a proposed third-party risk management guide specifically for Federal Reserve-supervised community banks. That document is intended to serve as a companion to the broader interagency guidance, suggesting regulators want a framework that is broad enough to apply across the industry while still accounting for the scale and resource constraints of smaller banks.
The coordinated action comes at a time when regulators globally are paying closer attention to operational resilience, outsourcing risk and the concentration of critical services among a relatively small number of vendors. For community banks in particular, the issue is acute: they may lack the internal scale to replicate services in-house, yet they remain responsible for ensuring that outsourced functions do not create hidden vulnerabilities.
By seeking comment before finalizing the guidance, the agencies are inviting banks, credit unions, vendors and other stakeholders to weigh in on how the framework should be applied in practice. The result could shape how institutions document due diligence, monitor vendor performance, manage contracts, assess concentration risk and respond to disruptions in the years ahead.
For now, the message from Washington is clear: third-party relationships are no longer peripheral to bank supervision. They are central to it, and regulators want a more disciplined, consistent and risk-sensitive approach before the next operational shock tests the system.
