Community Banks’ Biggest Third-Party Risk Is the Vendor They Can’t Replace
A pair of regulatory actions issued Friday (Sept. 11) could change how banks think about third-party risk. The Federal Reserve Board, the Federal Deposit Insurance Corp., the Office of the Comptroller of the Currency and the National Credit Union Administration proposed replacing existing third-party risk-management guidance with a principles-based framework designed to let financial institutions…
Regulatory actions issued on September 11 could reshape how community banks view third-party risk. The Federal Reserve Board, Federal Deposit Insurance Corp., Office of the Comptroller of the Currency, and National Credit Union Administration proposed a principles-based framework for third-party risk management. This new approach emphasizes the magnitude and likelihood of potential harm, rather than a uniform process-driven approach.
However, the agencies highlighted a crucial issue: when a community bank identifies a significant third-party risk but has limited practical ability to change it. Core providers, such as transaction processing, payments, digital banking, and cloud computing, are essential to a bank's operations. Many banks rely on a few large providers, limiting negotiating power.
The agencies warned that community banks may face obstacles in identifying, assessing, and addressing risks posed by these core providers. The proposed framework shifts the focus from vendor management to dependency management, highlighting that the relevant measure of risk is not merely the number of vendors but the degree of dependency on non-replaceable vendors.
The agencies emphasized that the availability, integrity, and security of core processing platforms are crucial to nearly all banking operations.
Written by urgent.news from PYMNTS's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.