Financial institutions run on other companies' software, data, and staff. Core processing, card issuing, deposit account origination, underwriting models, fraud screening, collections, statement printing, and customer support are all commonly performed by third parties. Federal banking regulators have a consistent answer to what that means legally: an institution may outsource an activity, but it cannot outsource its responsibility for performing that activity in a safe, sound, and compliant manner.
In 2023 the Federal Reserve, FDIC, and OCC issued joint interagency guidance on third-party relationships, replacing the separate frameworks each agency had used. It is guidance rather than a rule, and it is explicitly risk-based: the expectation is that oversight is proportionate to the risk a relationship presents, not that every vendor receives identical treatment.
The lifecycle, stage by stage
- Planning. Before selecting anyone, define what the activity is, why it is being outsourced, what could go wrong, and what the institution's own capability would need to be if the relationship ended. Planning is where criticality is decided, and that decision drives everything downstream.
- Due diligence and selection. Assess the candidate's financial condition, business experience, legal and regulatory history, operational and information security capability, insurance coverage, reliance on its own subcontractors, and resilience. The depth should match criticality.
- Contract negotiation. Convert the diligence findings into enforceable obligations: performance standards, security requirements, audit and examination access, subcontractor controls, incident reporting, data return, and termination rights.
- Ongoing monitoring. Diligence is not a one-time event. Performance, financial condition, control reports, security posture, complaint volumes, and regulatory developments all need periodic review at an interval matched to risk.
- Termination. Plan the exit before the entry. Data return and destruction, transition assistance, customer notification, and the institution's ability to operate during transition all need to be settled in the contract.
Cutting across all five stages are three governance elements the guidance treats as continuous: oversight and accountability with clear ownership, independent reviews of the program itself, and documentation and reporting sufficient for the board and examiners to see what is happening.
Due diligence that produces evidence
The most common weakness in third-party programs is a diligence file made entirely of the vendor's own assertions. A questionnaire the vendor filled out is a starting point, not a finding. Evidence-based diligence collects artifacts a reviewer can evaluate:
- Audited financial statements and, for private companies, sufficient information to assess going-concern risk — not just a credit-bureau summary.
- Independent control reports such as SOC 2 Type II, read for the exceptions and the complementary user entity controls rather than filed on receipt of the cover page.
- Penetration test summaries, vulnerability management practices, and evidence of remediation timelines actually met.
- Business continuity and disaster recovery plans plus results of the most recent test, including recovery time and recovery point objectives that match your needs.
- The vendor's own third-party inventory for the services you are buying, so fourth-party concentration is visible.
- Regulatory and litigation history, including enforcement actions against the vendor or its principals.
- For vendors performing consumer-facing or decisioning functions, their compliance management system, complaint handling, and model documentation.
Watch out: a control report covering the wrong system, the wrong period, or the wrong trust services criteria is worse than none, because it creates false comfort in the file. Check the scope section against the specific service you are buying, and check whether the report period covers the time you actually relied on the service.
The contract terms that matter later
| Provision | What to get | Why it matters |
|---|---|---|
| Scope and performance | Specific service description with measurable standards and remedies | Vague scope makes every later dispute a negotiation rather than a claim |
| Audit and examination access | Right for the institution and its regulators to access records and personnel | Supervisors may examine services performed for insured institutions; the contract should not obstruct that |
| Information security | Defined controls, encryption standards, access management, and testing obligations | Ties the vendor to a standard rather than to "commercially reasonable" effort |
| Incident notification | Notice within a defined short period, with cooperation and forensic access | State and federal notification clocks run from discovery, not from the vendor's convenience |
| Subcontractors | Approval or notice rights, flow-down of material obligations, and a current list | Fourth-party risk is otherwise invisible until it fails |
| Compliance obligations | Express undertaking to comply with applicable laws and the institution's policies | Consumer-facing conduct by a vendor becomes the institution's exposure |
| Data rights and return | Ownership, portability format, return and certified destruction on exit | Data hostage situations are the most common exit failure |
| Termination | Termination for cause, for convenience where feasible, and for regulatory direction, plus transition assistance | Without transition help, the right to terminate is theoretical |
| Limitation of liability | Carve-outs for confidentiality breach, security incidents, and indemnified claims | A cap set at a few months of fees will not cover a notification event |
Incident notification deserves particular attention because the drafting is usually too loose. "Prompt" notice is unenforceable; a defined hour count from discovery, with an obligation to cooperate and preserve evidence, is what an incident response team can actually use. Our guide to vendor breach notification clauses that work covers the drafting in detail.
Monitoring: what to watch and how often
Monitoring fails in one of two directions. Either everything is reviewed annually regardless of risk, which wastes capacity and misses fast-moving problems, or monitoring is entirely reactive and the first signal is an outage. A workable program tiers both the frequency and the signals.
For critical relationships, watch operational metrics against the contract's standards, complaint volumes and themes, security findings and remediation aging, financial condition indicators, changes in ownership or key personnel, and changes in the vendor's own subcontractors. For lower-risk relationships, an annual refresh of core diligence and a check that the service is still needed may be enough.
Practical step: track consumer complaints by vendor, not only by product. Complaint data is the earliest reliable indicator that an outsourced customer-facing function has drifted from what the contract requires, and it is exactly what an examiner will ask you to produce. Complaints submitted to the CFPB about your products are visible to your regulator whether or not you are tracking them.
Bank-fintech partnerships, from both sides
The most scrutinized third-party relationships in recent years have been bank partnerships with technology companies that originate deposits or credit under the bank's charter. Supervisors have focused on whether the bank actually oversees the program: whether it sees the underwriting criteria, controls the marketing, can access the ledger, monitors compliance testing, and can direct changes.
From the bank's side, the discipline is to treat the partner as performing a bank activity — with the same policy expectations, testing, and reporting the bank applies internally. From the fintech's side, the discipline is to build for oversight from the start: auditable records, exportable data, documented decisioning, and a compliance function that can answer an examiner's question without a two-week fire drill.
Two functions recur as failure points. Sanctions screening sits in the control path and carries strict-liability exposure for each U.S. person in the chain, as explained in our guide to OFAC sanctions obligations. And credit decisioning performed by a vendor or a purchased model still has to satisfy fair lending requirements, which means the contract must deliver model documentation and testing access — the point developed in our guide to fair lending in automated underwriting. The wider allocation of these duties between partners is the subject of our guide to embedded finance compliance risk.
Concentration, resilience, and getting out
Two structural risks receive less attention than they deserve. Concentration risk arises when many institutions depend on the same provider, or when one institution depends on a single provider across multiple critical functions. The failure mode is correlated: the provider's outage is everyone's outage, and the institution's diversification is illusory.
Exit risk arises when a relationship must end and cannot. Data in a proprietary format, no transition assistance obligation, customer relationships held by the vendor, and no internal capability to resume the function all combine to make termination rights unusable. Testing the exit — at least on paper, with a documented plan and an estimated timeline — turns a contractual right into an operational option.
Quick answers
Is the interagency guidance a rule we can be fined for violating?
The 2023 interagency guidance is supervisory guidance rather than a regulation, and agencies have said guidance does not itself create enforceable legal obligations. That distinction matters less in practice than it sounds: deficient third-party management is routinely cited through safety-and-soundness authority, and the underlying legal obligations the vendor helps you meet remain fully enforceable against you.
Do we need the same diligence for every vendor?
No, and attempting it usually degrades the program. The framework is explicitly risk-based. The work is in defining criticality honestly and consistently, then scaling diligence, contract rigor, monitoring frequency, and reporting to that tier. A landscaping contract and a core processor should not receive the same file.
Can regulators examine our vendors directly?
For insured depository institutions, federal banking agencies have authority to examine services performed for the institution by third parties, which is why examination access clauses belong in the contract. Vendors sometimes resist this language; it is not optional for services supporting a supervised institution, and resistance to it is itself a diligence finding.
Who owns the risk when a subcontractor causes the failure?
As between the institution and its regulator, the institution does. As between the institution and its vendor, the answer is whatever the contract says — which is why flow-down obligations, subcontractor approval or notice rights, and indemnities that reach subcontractor conduct are worth negotiating up front rather than after an incident.
How does this interact with privacy and data protection obligations?
Directly. Where personal data is processed by a vendor, contractual data protection terms are typically required by state privacy statutes as well as by financial regulation, and the required content differs by state. Our guide to data processing agreements covers the controller, processor, and subprocessor structure that those statutes expect.
Your next moves
Build the inventory first — every third party, the activity it supports, the data it touches, and a criticality rating you can defend. Most institutions find that the inventory alone surfaces relationships nobody owns and services nobody has reviewed since onboarding.
Then work the critical tier properly: refresh diligence with real artifacts, close the contract gaps in audit access, incident notification, subcontractors, and exit, and set monitoring signals that would actually detect deterioration. Document the whole thing well enough that a reader who was not in the room can follow the reasoning. Related guides on partnership structures, data terms, and compliance allocation sit in the banking, payments, and fintech pathway.