Join a community of professionals and get:
on all CeFPro events.
unlock speaker decks and audience polls.
Full library access the moment you sign up.
Digital Content

- Unlimited access to peer-contribution articles and insights
- Global research and market intelligence reports
- Discover Connect Magazine, a monthly publication
- Panel discussion and presentation recordings
- US regulators are
stepping up scrutiny of third-party core technology providers serving
community banks
- Market concentration
is raising concerns that smaller banks lack sufficient negotiating power
with major vendors
- Regulators will
examine provider transparency, contract restrictions, technology
investment, cybersecurity and operational resilience
- Agencies could take
action against providers or banks when safety, soundness or legal issues
emerge
- Proposed guidance
encourages institutions to tailor vendor oversight to the risk presented
by individual relationships
- The Federal Reserve
has proposed additional guidance specifically for community banks
US banking regulators are stepping up
scrutiny of third-party core technology providers amid concerns that dominant
vendors are restricting community banks’ ability to conduct due diligence,
negotiate contracts and effectively manage operational risks.
The Federal Deposit Insurance
Corporation, Federal Reserve and Office of the Comptroller of the Currency
issued a joint statement outlining how they will supervise services provided to
community banking organizations, with particular attention on business
practices that may “unreasonably limit” banks’ ability to manage relationships
with core providers.
The agencies acknowledged that a
significant proportion of the core provider market is controlled by a
relatively small number of large companies – potentially weakening the
negotiating position of smaller financial institutions.
“Given these constraints, CBOs report
they often experience challenges obtaining reasonable due diligence
information, negotiating contract terms, or conducting effective ongoing
monitoring,” the regulators said.
“These challenges may make it
difficult for CBOs to hold core providers accountable for delivering quality
services.”
Regulators will focus on three broad
areas when assessing services delivered by core providers, including the level
of transparency offered to community banks.
That could involve examining
contractual provisions that restrict a bank’s ability to compare a provider’s
products and services with competing offerings, as well as contract terms that
make it more difficult for institutions to manage vendor relationships in
accordance with their individual business requirements.
Technology resilience will also face
scrutiny. Regulators said they will consider whether providers are investing
sufficiently to maintain and modernize their technology, while strengthening
cybersecurity and reducing the risk of outages and service disruptions.
The agencies warned that they have
powers to intervene when problems create safety and soundness concerns or
result in violations of the law.
“When such issues are identified, the
agencies may bring the appropriate actions against core providers and/or the
CBO pursuant to their statutory authorities,” they said.
The regulatory intervention comes
alongside proposed joint guidance from the FDIC, Fed and OCC, together with the
National Credit Union Administration, designed to help financial institutions
tailor third-party risk management practices more closely to the risks
presented by individual vendor relationships.
Rather than applying identical
oversight requirements across every third party, institutions would be
encouraged to align their controls with the “reasonably assessed” risk of each
relationship.
The proposals would also provide
strategies for adjusting third-party risk management according to an
institution’s size, complexity and overall risk profile, together with the
nature and significance of the service being provided.
Separately, the Federal Reserve has
requested feedback on a proposed third-party risk management guide specifically
for community banks under its supervision. The document is intended to
complement the broader interagency guidance.
The proposals highlight growing
regulatory attention on the risks created by financial institutions’ dependence
on external technology companies – particularly where market concentration
leaves smaller banks with limited bargaining power.
For community banks, the measures
could strengthen their position when dealing with critical technology
providers.
For vendors, however, they signal
that contractual practices, transparency, cybersecurity investment and
operational resilience are increasingly becoming matters of direct regulatory
interest.
The proposed third-party risk
management guidance will replace existing guidance, with comments due within 60
days of its publication in the Federal Register.