Proposed guidance focuses on risk management with third parties; statement on community banks ‘core service providers’ issued

Managing risks associated with third-party relationships is the subject of proposed guidance issued Friday by federal banking and credit union regulators.

The banking agencies also issued a statement on community banks’ engagement with core service providers.

According to the agencies (the Federal Deposit Insurance Corp. (FDIC), the Federal Reserve Board, the Office of the Comptroller of the Currency (OCC) and the National Credit Union Administration (NCUA), the proposed guidance is based on their supervisory experience and lessons learned from examining financial institutions’ third-party risk management practices.

The guidance, the agencies said, “is intended to assist banks and credit unions to better align and tailor their third-party risk management practices to the risks of individual third-party relationships.” The added that the proposal focuses on a principles-based approach and is non-binding.

They said that when the guidance becomes final, it would replace existing third-party risk management guidance (which would be rescinded) to” promote consistency and prudent innovation in the banking industry.”

Comments are due on the proposed guidance within 60 days of its publication in the Federal Register.

Also Friday, the Federal Reserve separately requested comment on a proposed third-party risk management guide specifically for Federal Reserve-supervised community banks, which is intended to serve as a companion document to the proposed guid

In the separate action on community banks and engagement with core service providers, the banking regulators said their joint statement discusses certain factors the agencies will consider in making supervisory and enforcement decisions related to these core providers.

“The agencies believe there is a need for additional clarification regarding a subset of community banking organizations’ (CBOs’) third-party relationships, based on the agencies’ supervision of CBOs and their service providers, and reinforced by the agencies’ outreach to CBOs and other relevant stakeholders,” the agencies wrote. The said the subset is third parties that provide the “critical systems applications” and infrastructure that support the operation and essential functions of one or more of a CBO’s lines of business.

Examples, the agencies said, include through the provision of transaction processing, account management, payments processing, customer relationship management, compliance and reporting, online banking, and other material functions. “For purposes of this statement, the agencies refer to these entities broadly as core providers. These relationships are essential to the safe and sound operations of CBOs, yet certain core provider business practices and market dynamics may pose obstacles to a CBO’s ability to efficiently and effectively identify, assess, and address the attendant risks.”

Agencies Seek Comment on Proposed Third-Party Risk Management Guidance and Issue Statement on Community Bank Engagement with Core Service Providers

Be the first to comment

Leave a Reply

Your email address will not be published.