The federal banking agencies today pledged to step up oversight of third-party core providers whose business practices “unreasonably limit” community banks from conducting due diligence or from negotiating contract terms that address the banks’ business needs.
The FDIC, Federal Reserve and Office of the Comptroller of the Currency issued a joint statement “to provide clarity on their risk-based supervision of certain services provided to community banking organizations,” or CBOs. In addition, they proposed joint guidance with the National Credit Union Administration to assist financial institutions in better tailoring third-party risk management practices to the risk levels specific to each third-party relationship.
Core provider oversight
In the statement, the agencies said they are aware that a significant percentage of the core provider market is represented by just a few large providers, which limits community banks’ negotiating power.
“Given these constraints, CBOs report they often experience challenges obtaining reasonable due diligence information, negotiating contract terms, or conducting effective ongoing monitoring,” the agencies said. “These challenges may make it difficult for CBOs to hold core providers accountable for delivering quality services.”
As a result, the agencies will consider three factors in their supervision of certain services provided by core providers to community banks:
- The level of core provider transparency, such as whether it has contractual provisions that limit a community bank’s ability to compare the provider’s offerings with those of other providers.
- Contract features that make it difficult for community banks to manage their core provider relationships in ways that address their business needs.
- Whether core providers are investing to keep their technology up-to-date and are taking steps to strengthen cybersecurity and prevent service outages or disruptions.
“The agencies monitor services that core providers deliver to CBOs to identify issues related to safety and soundness or violations of law,” the agencies said. “When such issues are identified, the agencies may bring the appropriate actions against core providers and/or the CBO pursuant to their statutory authorities.”
The joint statement includes recommendations from the American Bankers Association’s Core Platforms Committee.
Third-party risk management
The proposed guidance would discuss the potential benefits for financial institutions in aligning third-party risk management practices to the “reasonably assessed” risk levels of each third-party relationship, according to the document. It also seeks to provide strategies to tailor third-party risk management practices to the institution’s size, complexity and risk profile, as well as the nature of the third-party relationship.
The proposed guidance will replace existing guidance on the subject, with comments due 60 days from publication in the Federal Register.









