Proposed Third-Party Risk Management Guide for Traditional Community Banking Organizations
Primary source
Metadata and text below are from the Federal Register, a public-domain U.S. government work. Always verify the official published version before relying on it for any legal matter.
Issuing agencies
Abstract
The Board invites comment on a proposed guide for traditional community banking organizations on managing risks associated with third-party relationships. The proposed guide would reflect the Board's supervisory experience and lessons learned through examining community banking organizations' third-party risk management practices. In particular, the proposed guide would discuss the key risks faced by traditional community banking organizations in their third-party relationships in general and in relation to particular categories of third-party relationships most common to traditional community banking organizations.
Full Text
<html>
<head>
<title>Federal Register, Volume 91 Issue 177 (Tuesday, September 15, 2026)</title>
</head>
<body><pre>
[Federal Register Volume 91, Number 177 (Tuesday, September 15, 2026)]
[Notices]
[Pages 58438-58446]
From the Federal Register Online via the Government Publishing Office [<a href="http://www.gpo.gov">www.gpo.gov</a>]
[FR Doc No: 2026-18852]
=======================================================================
-----------------------------------------------------------------------
FEDERAL RESERVE SYSTEM
[Docket No. OP-1880]
Proposed Third-Party Risk Management Guide for Traditional
Community Banking Organizations
AGENCY: The Board of Governors of the Federal Reserve System (Board).
ACTION: Proposed guidance and request for comment.
-----------------------------------------------------------------------
SUMMARY: The Board invites comment on a proposed guide for traditional
community banking organizations on managing risks associated with
third-party relationships. The proposed guide would reflect the Board's
supervisory experience and lessons learned through examining community
banking organizations' third-party risk management practices. In
particular, the proposed guide would discuss the key risks faced by
traditional community banking organizations in their third-party
relationships in general and in relation to particular categories of
third-party relationships most common to traditional community banking
organizations.
DATES: Comments must be received on or before November 16, 2026.
ADDRESSES: You may submit comments, identified by Docket No. OP-1880 by
any of the following methods:
<bullet> Agency Website: <a href="https://www.federalreserve.gov/apps/proposals/">https://www.federalreserve.gov/apps/proposals/</a>. Follow the instructions for submitting comments, including
attachments. Preferred Method.
<bullet> Mail: Benjamin W. McDonough, Secretary, Board of Governors
of the Federal Reserve System, 20th Street and Constitution Avenue NW,
Washington, DC 20551.
<bullet> Hand Delivery/Courier: Same as mailing address.
<bullet> Other Means: <a href="/cdn-cgi/l/email-protection#29595c4b45404a4a4644444c475d5a694f5b4b074e465f"><span class="__cf_email__" data-cfemail="3b4b4e59575258585456565e554f487b5d4959155c544d">[email protected]</span></a>. You must include
docket number in the subject line of the message.
Comments received are subject to public disclosure. In general,
comments received will be made available on the Board's website at
<a href="https://www.federalreserve.gov/apps/proposals/">https://www.federalreserve.gov/apps/proposals/</a> without change and will
not be modified to remove personal or business information including
confidential, contact, or other identifying information. Comments
should not include any information such as confidential information
that would be not appropriate for public disclosure. Public comments
may also be viewed electronically or in person in Room M-4365A, 2001 C
St. NW, Washington, DC 20551, between 9 a.m. and 5 p.m. during Federal
business weekdays.
FOR FURTHER INFORMATION CONTACT: Juan Climent, Deputy Associate
Director, (202) 460-2180, Jeff Ernst, Manager, (202) 369-9439, Allison
Boller, Sr., Financial Institution Policy Analyst II, (202) 253-4686,
Joseph Vall-Llobera, Director of Examinations, (470) 733-1198, Division
of Supervision and Regulation; or Claudia Von Pervieux, Special
Counsel, (202) 469-1020, Benjamin Nuyens, Senior Counsel, (202) 909-
7574, Legal Division; Board of Governors of the Federal Reserve System,
20th Street and Constitution Avenue NW, Washington, DC 20551.
SUPPLEMENTARY INFORMATION:
I. Overview
As described elsewhere in today's Federal Register, the Board, the
Federal Deposit Insurance Corporation, the Office of the Comptroller of
the Currency, and the National Credit
[[Page 58439]]
Union Administration (collectively, the ``agencies'') published for
comment proposed guidance on third-party risk management that would
apply to all banking organizations supervised by the agencies, Proposed
Third-Party Risk Management Guidance (Proposed All-Bank TPRM Guidance).
The Proposed All-Bank TPRM Guidance would provide principles for
banking organizations to consider when managing third-party risks.
Some community banks have expressed the need for additional
resources to support their third-party risk management efforts. To
address that need, the Board is issuing for comment a proposed guide on
third-party risk management for ``traditional community banking
organizations'' \1\ (Community Bank Guide) that is intended to serve as
a companion document to the Proposed All-Bank TPRM Guidance. The
proposed Community Bank Guide would have the explicit goal of assisting
TCBOs in understanding and conducting third-party risk management. It
would articulate how the principles in the Proposed All-Bank TPRM
Guidance can be applied in practice by TCBOs. Limiting the scope to
TCBOs and the third parties they tend to engage with makes it possible
to provide clear examples of how smaller banking organizations can
operationalize the high-level principles in the Proposed All-Bank TPRM
Guidance.
---------------------------------------------------------------------------
\1\ ``Traditional community banking organizations'' (``TCBOs'')
are banking organizations with less than $30 billion in assets that
focus on serving their local communities. The proposed guide is not
intended for community banking organizations with more complex
business models or third-party relationship profiles, such as
complex bank-fintech partnerships (e.g., where a bank makes products
or services available through an arrangement with one or more
fintech companies and the fintech company, rather than the bank,
markets, distributes, or otherwise provides access to the products
or services).
---------------------------------------------------------------------------
The proposed Community Bank Guide would not be relevant to other
institutions, as it would be specifically tailored to the unique
characteristics and risk profiles of TCBOs. It would not be a rule, and
banking organizations would not be required to take the actions
described in the guide.
The Board seeks comment on whether the proposed Community Bank
Guide would be useful to TCBOs and how it could be improved. In
particular, the Board is interested in feedback on whether the proposed
guide provides the appropriate level of detail, such that it will serve
as a useful resource for TCBOs without establishing de facto
supervisory standards.
In drafting the proposed Community Bank Guide, the Board has
endeavored to distill the key risks and risk management considerations
associated with third-party relationships most engaged in by TCBOs. In
doing so, the Board consulted various resources, including relevant
sections of examination materials (e.g., the Federal Financial
Institutions Examination Council's IT Examination Handbook and Bank
Secrecy Act/Anti-Money Laundering Examination Manual), industry
materials, and responses to the agencies' relevant requests for
information.\2\ The Board also used information learned from the
supervisory process, including sound risk management practices the
Board has seen at TCBOs (including associated materials such as risk
assessment methodologies, sample contracts, and due diligence files).
---------------------------------------------------------------------------
\2\ ``Request for Information on Bank-Fintech Arrangements
Involving Banking Products and Services Distributed to Consumers and
Businesses,'' 89 FR 61577 (July 31, 2024); ``Request for Information
Regarding Community Bank Digitalization,'' 90 FR 20212 (May 12,
2025); and ``Request for Information Regarding Community Banks'
Engagement With Core Service Providers and Other Essential Third-
Party Service Providers,'' 90 FR 54882 (November 28, 2025).
---------------------------------------------------------------------------
II. Request for Comment
The Board invites comment on all aspects of the proposed Community
Bank Guide. The Board also seeks feedback on ways to improve upon the
proposed guide so that it can be as useful as possible for TCBOs in
managing their third-party risks. In addition, the Board invites
comment on these specific topics:
<bullet> What are the advantages and disadvantages of tailoring the
expectations established in the proposed Community Bank Guide to
banking organizations with assets below $30 billion?
<bullet> How, if at all, could the Board further clarify the
characteristics of a TCBO? What additional examples of community
banking organization profiles, if any, would be helpful to clarify
whether a community banking organization would be within the scope of
the proposed Community Bank Guide?
<bullet> The proposed guide is meant to serve as a resource for
TCBOs to support their efforts to manage risks from third-party
relationships. To what extent would the information included in the
proposed guide be useful for TCBOs? How can the proposed guide be
clarified or modified to advance that objective?
<bullet> In drafting the proposed guide, the Board sought to
provide a level of detail that would make the document a useful
practical resource. At the same time, the Board sought to avoid
creating de facto standards that TCBOs believe they would be evaluated
against. To what extent has the Board appropriately calibrated the
level of detail in the proposed guide?
<bullet> What changes or additional clarifications, if any, would
be helpful regarding the overarching third-party risk management
considerations used by TCBOs, provided in Section IV.B?
<bullet> What adjustments should the Board consider to the proposed
categories of vendor types most used by TCBOs? What additional
categories, if any, should Section IV.C provide?
<bullet> How can the proposed guide be improved to better support
contract negotiations with third parties?
<bullet> Should ``deposit placement networks'' be included as an
additional vendor category in Section IV.C? Would TCBOs benefit from
having specific third-party risk management considerations for this
type of relationship? If so, how do the overarching risk management
considerations apply and what additional risk considerations are most
relevant?
III. Paperwork Reduction Act
The Paperwork Reduction Act of 1995 (44 U.S.C. 3501-3521) (PRA)
states that no agency may conduct or sponsor, nor is the respondent
required to respond to, an information collection unless it displays a
currently valid Office of Management and Budget (OMB) control number.
The guide does not revise any existing, or create any new,
information collections pursuant to the PRA. Rather, any reporting,
recordkeeping, or disclosure activities mentioned in the guide are
usual and customary and should occur in the normal course of business
as defined in the PRA.\3\ Consequently, no submissions will be made to
the OMB for review.
---------------------------------------------------------------------------
\3\ 5 CFR 1320.3(b)(2).
---------------------------------------------------------------------------
IV. Text of Proposed Third-Party Risk Management Guide for Traditional
Community Banking Organizations
A. Introduction
B. Overarching Third-Party Risk Management Considerations
1. Operational Resilience
2. System and Information Security
3. Compliance With Rules and Regulations
4. Financial Resilience
C. TPRM Considerations on a Vendor-by-Vendor Basis
1. Core Providers
2. Information Technology (IT) Infrastructure Providers
3. Cybersecurity Providers
[[Page 58440]]
4. Payment Processing and Digital Banking Providers
5. Loan Management System Providers
6. Card Issuing and Processing Providers
7. BSA/AML and Financial Crime Platform Providers
8. Fraud Prevention and Detection Providers
A. Introduction
Community banking organizations regularly rely on third parties \4\
to support their banking operations. Third-party relationships can
offer community banking organizations access to new technologies, risk-
management tools, human capital, delivery channels, products, services,
and markets. The Board of Governors of the Federal Reserve System
(``Board'') is issuing this guide to provide a resource for traditional
community banking organizations in managing risks that arise from their
third-party relationships. For purposes of this guide, ``traditional
community banking organizations'' (``TCBOs'') are banking organizations
with less than $30 billion in assets that focus on serving their local
communities.\5\ For the purposes of this guide, consumer compliance is
not in scope.
---------------------------------------------------------------------------
\4\ For the purposes of this document, the term ``third party''
is interchangeable with ``service provider'' and ``vendor.''
\5\ This guide is not intended for community banking
organizations with more complex business models or third-party
relationship profiles, such as complex bank-fintech partnerships
(e.g., where a bank makes products or services available through an
arrangement with one or more fintech companies and the fintech
company, rather than the bank, markets, distributes, or otherwise
provides access to the products or services).
---------------------------------------------------------------------------
This guide complements the proposed guidance described elsewhere in
today's Federal Register, Proposed Third-Party Risk Management
Guidance, which applies to all banking organizations supervised by the
agencies (All-Bank TPRM Guidance). This guide is an additional resource
for TCBOs supervised by the Board and helps explain how such
institutions could operationalize the principles articulated in the
All-Bank TPRM Guidance.
This guide is divided into two main sections. The first section
discusses four overarching third-party risk management topics, which
are common to the types of third-party relationships \6\ that TCBOs
typically engage with:
---------------------------------------------------------------------------
\6\ A third-party relationship is defined in the All-Bank TPRM
Guidance as a business arrangement between a banking organization
and an entity or individual for the provision of one or more
products, services, and other activities that support the banking
organization.
---------------------------------------------------------------------------
<bullet<ls-thn-eq> Operational Resilience: How a third party's
operational disruptions could affect a TCBO.
<bullet<ls-thn-eq> System and Information Security: A third party's
impact on the security of a TCBO's sensitive networks, systems or data.
<bullet<ls-thn-eq> Compliance with Rules and Regulations: How a
third party impacts a banking organization's compliance with applicable
rules and regulations.
<bullet<ls-thn-eq> Financial Resilience: The impact of a third
party's financial standing on a TCBO.
The second section identifies eight categories of third parties
that smaller banking organizations often engage with, namely, core
service providers, information technology infrastructure providers,
cybersecurity providers, payment processing and digital banking
providers, loan management system providers, card issuing and
processing providers, Bank Secrecy Act/Anti-Money Laundering (BSA/AML)
and financial crime platform providers, and fraud prevention and
detection providers. For each third-party type, this guide discusses
(1) how the overarching considerations discussed in the first section
apply; and (2) additional risk management considerations specific to
the third-party category. In the case of certain categories, this guide
also includes a discussion of risk management strategies a TCBO may
consider when transitioning to a new provider.
There are many ways to manage third-party risks effectively, and
the suggestions in this guide are not the only available practices for
TCBOs to effectively manage their risks. There is no one-size-fits-all
approach to effective risk management. The examples and details in this
guide are intended to support TCBOs in establishing appropriate third-
party risk management practices. This guide does not set forth
enforceable standards or prescriptive requirements; accordingly, non-
compliance with this guide will not by itself result in supervisory
criticism against a banking organization.\7\ Additionally, each banking
organization is responsible for operating in a safe and sound manner
and adopting risk management practices that are best suited to managing
the specific risks that it faces. All examples and risk considerations
in this guide are illustrative, are not comprehensive, and will not be
applicable to all situations.
---------------------------------------------------------------------------
\7\ See 12 CFR part 262, Appendix A. However, supervisory action
may result for any violations of law or unsafe or unsound practices
stemming from insufficient management of third-party risk.
---------------------------------------------------------------------------
B. Overarching Third-Party Risk Management Considerations
This section discusses four third-party risk management topics that
will generally be the highest priority for TCBOs. For each topic, it
provides overarching risk management considerations.
1. Operational Resilience
A TCBO typically has several third-party relationships that are
essential to its operations, such that if the vendor experiences a
serious disruption, the TCBO would struggle to operate. With this
degree of reliance, the TCBO's operational resilience depends to a
large degree on the operational resiliency of the third party. As a
result, assessing the operational resilience of such third parties may
be a high priority for the TCBO.
A third party's operational resilience can become compromised in
any number of ways, such as cyberattacks and information technology
failures. A TCBO is generally not expected to have the technical
expertise to assess such risks itself. It may, therefore, rely on a
review of reasonably conducted independent assessments for the matters
covered therein, such as:
<bullet> SSAE 18 SOC Reports (Statement on Standards for
Attestation Engagement Service Organization Control Reports);
<bullet> Technology service provider reports from the Federal
banking agencies (if applicable);
<bullet> Audit reports;
<bullet> Penetration testing reports;
<bullet> Industry standard assessments (e.g., Payment Card Industry
Data Security Standard (PCI DSS), National Institute of Standards and
Technology (NIST), and International Organization for Standardization
(ISO)).
Additionally, as part of due diligence, contract negotiation, and
monitoring, a TCBO may consider the third party's historical system
uptime performance, service availability metrics, and whether
performance capabilities align with the TCBO's needs. This may involve
reviewing the results of business continuity/disaster recovery tests in
light of the TCBO's recovery time and recovery point objectives. To
facilitate this review, it is useful for contracts to address a TCBO's
right to access these reports, or the right to audit directly if
reports are unavailable.
A TCBO may also seek to negotiate service level agreements (SLAs)
for operational resiliency in contracts with third parties (e.g.,
system availability commitments and cyber incident notification
requirements) and monitor for compliance against the SLAs. The Board
recognizes that a TCBO may lack leverage in contract negotiations with
[[Page 58441]]
certain third parties, and may not be able to obtain optimal terms.\8\
---------------------------------------------------------------------------
\8\ This qualifier applies in all cases where the guide
describes effective risk management principles for contract
negotiation. As stated in the All-Bank TPRM Guidance, ``[t]he
banking organization may still reasonably proceed with the
relationship if, for example, the banking organization has a
reasonable understanding of the risks relevant to the third-party
relationship and any residual risks are in line with the banking
organization's risk appetite and tolerances, especially if there are
limited alternative options.''
---------------------------------------------------------------------------
2. System and Information Security
Third-party relationships can also complicate a TCBO's efforts to
protect sensitive systems, data, and information. Third parties often
need access to sensitive banking organization systems to provide their
services. While granting this access can allow a TCBO to benefit from
the third party's services, it can also create new vulnerabilities to
cyberattacks. A third party's interaction with a banking organization's
systems and information creates a new ``attack vector'' that can be
exploited. Security incidents at vendors could lead to the theft of
banking organization customer data or compromise banking organization
systems and may require regulatory reporting.\9\
---------------------------------------------------------------------------
\9\ See 12 CFR part 208, App. D-2, 12 CFR part 225, subpart N.
---------------------------------------------------------------------------
Effective due diligence and ongoing monitoring of third parties
with access to sensitive banking organization systems may include
reviewing audit reports and other independent assessments that identify
the design and operating effectiveness of controls that protect banking
organization information. Independent assessments often include
information on the type of sensitive data protected and the access
controls, encryption, incident response, backup and disaster recovery
processes and associated operational effectiveness. Independent
assessments may also evaluate the third party's ability to identify
unauthorized activity and suspicious patterns indicative of a party
seeking to access sensitive information and the effectiveness of
remediation activities if information is comprised.
Contracts may address access to audits and other relevant reports,
and a third party's responsibility for notifying the TCBO of
cybersecurity incidents and remediation, including acceptable reporting
timelines. A TCBO may also consider negotiating for liability
provisions for security breaches, data loss, and regulatory violations
resulting from vendor security failures and requirements that vendors
maintain insurance to cover costs associated with information security
breaches, investigations, recoveries, and business interruption. A TCBO
may benefit from monitoring cyber events that impact the vendor, and
ongoing enhancements to the vendor's information systems control
environment.
When terminating a relationship with a vendor that has access to
sensitive systems or data, a TCBO may benefit from verifying that the
data has been successfully migrated or destroyed, that access has been
removed, and that any continuing obligations (e.g., transition
assistance and log retention) are in place.
3. Compliance With Rules and Regulations
A TCBO's third-party relationships may have implications for its
compliance with applicable rules and regulations, either because the
third party performs a service on the TCBO's behalf that is subject to
a compliance regime; or because the third party offers services that
support the TCBO's compliance efforts. For example, use of a third-
party BSA/AML system directly impacts a TCBO's ability to comply with
BSA/AML laws. Meanwhile, a core service provider's ability to
accurately store and transmit data can impact regulatory reporting
requirements. Additionally, many TCBOs participate in payment networks,
such as the National Automated Clearing House Association (NACHA) or
card networks. These networks often maintain operating rules, and TCBOs
may rely on third parties to help them comply with those rules. In such
cases, third-party errors could leave a TCBO out of compliance with
network rules, and lead to fines or in severe cases, loss of network
access.
Due diligence and ongoing monitoring of third parties that provide
services that support a TCBO's compliance efforts may include a review
of negative news screens, compliance attestations, certifications of
good standing from relevant entities, and independent audit reports to
understand the third party's historical record of regulatory and rules
compliance; quality and consistency of alerts, errors and exception
reporting; and the third party's ability to incorporate regulatory
changes into services. A TCBO may consider contractually identifying
the third party's roles and responsibilities for supporting the TCBO's
compliance with rules and regulations, including implementing timely
regulatory changes, notification requirements, and responding to
regulatory or TCBO customer inquiries, where applicable. Contracts may
consider liability or indemnification provisions for network rules or
regulatory violations caused by the third party, as well as access to
audits or attestations that validate the third party's ability to
comply with such rules and regulations. Where relevant, contracts can
establish clear data retention obligations aligned with regulatory
requirements.
Finally, a TCBO is ultimately responsible for compliance with rules
and regulations and may benefit from tracking regulator or network rule
changes that may have implications for the provider's services; and
confirming the vendor makes any changes necessary to ensure compliance.
4. Financial Resilience
A third party's financial resilience can also be an important risk
management consideration to the extent a TCBO relies on the third party
for essential operations and the availability of substitutes. During
due diligence and ongoing monitoring, a TCBO may approach evaluating
the financial resilience of a third party in a manner consistent with
the third party's risk profile. For example, a TCBO may limit a review
of the third party's financial standing to publicly available
information such as credit ratings, SEC filings, and market
intelligence when the third party is a publicly-registered entity with
established operating history. Conversely, when the third party is a
private company or newer market entrant, a TCBO may benefit from a more
concentrated assessment of the third party's financial standing. This
may include reliance on funding sources, cash outlay, and pro forma
financial statements, among other factors.
A TCBO may experience challenges in acquiring reliable or
independently validated financial information from privately-owned
third parties, including third parties in the startup phase. In such
cases, the TCBO may choose to accept higher inherent risk or even be
willing to contribute financially to the third party, depending on the
distinct advantages it may offer. The TCBO may consider establishing
contractual commitments for the third party to provide financial
information at a future point in time, hold adequate levels of
insurance, or limit growth of its services to the TCBO until financial
performance can be adequately assessed.
C. TPRM Considerations on a Vendor-by-Vendor Basis
This section contains third-party risk management considerations
for the third-party relationships most common to TCBOs. For each
category, the guide explains how the overarching risk management
considerations from
[[Page 58442]]
Section IV.B apply, and then discusses additional risk management
considerations that may be relevant. In some categories, the guide also
discusses considerations for transitioning to a new third party.
1. Core Providers
Many TCBOs rely on core processing service providers (core
providers) to develop and maintain the central system of record and
operational backbone for TCBOs. These systems manage customer accounts,
process daily transactions across deposits and loans, maintain the
general ledger, generate regulatory reports, and serve as the
integration hub connecting specialized applications. Generally, core
providers are the most material and complex third-party relationship
for TCBOs.
Overarching Risk Management Considerations
A core provider's availability, integrity, and security are
essential to nearly all banking operations. Moreover, core providers
often deliver multiple services beyond the core processing platform,
such as payment processing, card programs, loan origination, or digital
banking. Relying on a single provider for multiple services may offer
operational efficiencies and simplified third-party risk management,
but can also create heightened risk if the third party experiences
financial distress, operational failures, or security compromises. For
all these reasons, financial and operational resilience and system and
information security are primary risk factors for a TCBO to consider
when overseeing core provider relationships. In managing these risks, a
TCBO may benefit from consulting the risk management strategies
discussed in Section IV.B.
Specific Risk Management Considerations
Core systems can play an essential role in integrating various
applications and platforms TCBOs rely on. For example, in order to
operate effectively, BSA/AML and fraud detection systems must be able
to communicate with payments, card, or loan processing systems. Such
integration between a TCBO's systems can be essential to its
operations. Integration failures can lead to significant operational
breakdowns. To mitigate the risk of such failures, a TCBO may consider:
<bullet> testing integrations in a separate test environment, prior
to going live;
<bullet> establishing contractual service agreements to maintain
the security and availability of integrations; and
<bullet> monitoring performance of established connections and
integrations, especially following material business or regulatory
changes and through periodic continuity testing.
Given the core system's integration into a wide array of daily
banking operations, monitoring can primarily occur through routine
business practices that include system-generated alerts for failed
transactions or processing errors. Daily reconciliation processes
between connected systems provide inherent monitoring of core platform
accuracy through ledger balancing, exception investigation, and
researching if errors were appropriately captured and detected within
the system. TCBOs may benefit from closely controlling for and
resolving any ledger reconciliation issues prior to going live
following a core conversion. Furthermore, when integrating new cores,
other systems may require substantial migrations such as card or loan
systems. Phasing these complex and resource intensive migrations over
time can aid the TCBO in managing risk.
Core Conversion
The process of switching to a new core provider or platform is
often referred to as a ``core conversion.'' A TCBO may consider a core
conversion for a variety of reasons, including to:
<bullet> benefit from a more modern system that is more reliable
and offers straightforward integration with other third parties;
<bullet> migrate from a platform being sunset or discontinued by
the vendor;
<bullet> negotiate more equitable pricing and contract terms;
<bullet> gain greater control over the TCBO's own data; and
<bullet> obtain more responsive customer support (from the core to
the TCBO).
These benefits, however, can come at a cost. Core conversions can
be expensive and involve significant operational complexity. The Board
supports TCBOs' pursuing modernization to meet customer needs and
recognizes that TCBOs may reasonably accept higher risk when adopting
technology-forward core systems that enable greater agility and
innovation. The decision whether to undertake a core conversion is
TCBO-specific. An individual TCBO must ultimately determine whether the
benefits justify the risks and expense, based on its business model and
risk tolerance. Many TCBOs benefit from specialized core conversion
consultants or special counsel when undertaking a conversion.
As an alternative to full conversion, a TCBO may consider relying
on an integration platform, often referred to as a middleware provider.
Integration platform providers assist banking organizations when legacy
core providers cannot facilitate integrations with desired products. An
integration platform enables the flow of data between the TCBO's core
and ancillary systems, and the systems of another third party. As an
example, a TCBO may contract with a third party to offer a specific
product that records transactions in a separate ledger. To pass
transactional information back to the TCBO's core system, it chooses to
contract with another third-party integration platform to establish
Application Programming Interface (API) connections. Adding such a
platform extends the value chain and presents different inherent risks
than a conversion.
In addition to the factors discussed in Section IV.B, a TCBO
deciding whether to undertake a core conversion and which provider to
use may consider:
<bullet> direct and indirect costs of conversion, which may include
licensing or subscription fees, implementation and conversion services,
potential early termination fees for the existing provider, third-party
consulting services, and internal staff time diverted from normal
responsibilities;
<bullet> whether the prospective core provider will be able to meet
the TCBO's evolving strategic needs, based on the provider's current
and planned offerings;
<bullet> ease and cost of integration with other systems the TCBO
relies on;
<bullet> historical operating reports (e.g., error and exception
reports) to determine whether the provider's performance aligns with
the TCBO's risk appetite; and
<bullet> testimonials from other financial institutions on
conversion experience.
Negotiating favorable contract terms is an important aspect of the
conversion process, though the Board recognizes that TCBOs may have
limited leverage in such negotiations. Contractual considerations may
include:
<bullet> whether the contract provides a reasonable and transparent
pricing structure. The TCBO may seek to negotiate provisions about the
costs of upgrades to enable compliance with evolving regulatory
requirements; variable costs impacted by the number of accounts the
TCBO maintains on the core system, the TCBO's asset size, or its
transaction volume; whether billing statements are required to clearly
explain each service that is being charged; and how long the ``back
billing'' window is for the core provider
[[Page 58443]]
to issue retroactive charges for items missing from prior invoices.
<bullet> whether the terms of the contract are reasonable and
transparent, including initial term length and automatic renewal
conditions.
<bullet> whether the third party is subject to SLAs with measurable
performance standards that reflect the TCBO's individual needs and risk
profile, along with provisions that enable the TCBO to monitor and
enforce the SLAs.
<bullet> liability provisions that reflect the criticality of core
banking services, with appropriate indemnification for security
breaches, intellectual property claims against the TCBO, and data
protection violations.
<bullet> flexibility to terminate the relationship, taking into
account the conditions under which termination is allowed and any fees
the TCBO will incur.
2. Information Technology (IT) Infrastructure Providers
Many TCBOs use IT infrastructure providers to deliver foundational
services for their technology environment, including cloud hosting,
software applications, and physical infrastructure.
Overarching Risk Management Considerations
Disruption to an IT infrastructure provider's networks and systems
could significantly impact the TCBO's internal operations and the
delivery of products and services to customers. It could also expose
sensitive customer data. Consequently, operational and financial
resilience and information security are all important risk factors to
consider when engaging with IT infrastructure providers; and a TCBO may
benefit from considering the risk management strategies for these areas
discussed in Section IV.B.
Transitioning to a Cloud-Based Infrastructure Provider
Depending on its business model, a TCBO may realize significant
benefits from migrating to a cloud-based IT infrastructure, including
reduced capital expenditure, improved scalability, and access to
advanced computing resources and security capabilities. However, cloud
migration may also involve significant operational complexity,
depending on the implementation model a TCBO chooses.
TCBO cloud migrations can vary significantly. For example, a
minimalist migration could be limited to applications that have already
been optimized for the cloud, such as office productivity suite
applications. A TCBO may also choose to migrate individual
applications, such as loan processing systems and customer relationship
systems. A maximalist migration would include a TCBO's entire IT
infrastructure, including all its information systems. Each decision
carries different tradeoffs with respect to complexity, cost, and
expertise. There can also be variation in how specific applications are
migrated. For example, a TCBO may choose to simply replicate its
existing loan management system in the cloud; alternatively, a TCBO
could choose to modify the application to optimize it for the cloud.
Such choices can impact the operational complexity of a TCBO's
migration and have implications related to the degree of IT expertise
that it will need to oversee its cloud-based systems. As a general
matter, many cloud service providers (CSPs) have resources to help
TCBOs understand the provider's offerings and assess what
implementation model best fits the TCBO's individual needs. A TCBO may
benefit from discussing with the CSP:
<bullet> the level of in-house expertise the TCBO will need for a
successful migration;
<bullet> the categories of data to be migrated and any compromises
to data accuracy and integrity that might arise; and
<bullet> how operational disruptions during the transition can be
minimized, and how the TCBO will be notified of material incidents,
consistent with applicable rules and regulations, when information
systems are successfully migrated.
As part of its planning for a cloud migration, a TCBO may consider
various operational aspects of the transition, including how the TCBO
will dispose of physical equipment and transfer or cancel software
licenses.
A TCBO may benefit from becoming more familiar with the types of
audits and periodic assessments its infrastructure provider conducts,
and how this information captures security and performance metrics. In
general, infrastructure providers will capture their reporting through
customizable dashboard interfaces, which the TCBO can rely on for
ongoing monitoring activities. For example, many infrastructure
providers allow customers to view how the contracted services are
complying with standards and customer-driven compliance rules.
3. Cybersecurity Providers
TCBOs often rely on cybersecurity vendors to help protect their
information systems, networks, and data. Among other things, these
third parties offer products and services that can bolster defenses
against attacks, detect malicious activity, and help TCBOs respond to
and recover from cybersecurity incidents. In many cases, an IT
infrastructure provider may provide cybersecurity services in
connection with its products and services.
Overarching Risk Management Considerations
Cybersecurity has increasingly become an operational imperative for
banking organizations. To the extent a TCBO depends on a third party
for its cybersecurity, that third party's operational resilience
becomes a key risk management consideration.\10\ A vendor's information
and systems security are also important considerations, given that
cybersecurity providers often have access to a TCBO's sensitive
information, including customer data. The discussion on how to manage
these issues in Section IV.B is generally relevant to cybersecurity
vendors.
---------------------------------------------------------------------------
\10\ For example, a past significant failure by an
infrastructure and cybersecurity provider in delivering global
internet traffic to its customers caused widespread customer website
outages.
---------------------------------------------------------------------------
Specific Risk Management Considerations
An ineffective cybersecurity vendor can make a TCBO vulnerable to
cyber incidents, which can lead to financial losses. For example, cyber
incidents can cause operational disruptions to banking portals, ATMs,
or other services, which, in turn, can drive customers to competitor
banking organizations or cause loss of confidential customer
information, leading to regulatory fines and customer lawsuits.
To assess the effectiveness of a cybersecurity vendor's product or
service, either as part of due diligence or ongoing monitoring, a TCBO
may consider:
<bullet> reviewing independent assessment reports (e.g., SOC 2
reports and ISO reports);
<bullet> consulting with peer banking organizations;
<bullet> reading publicly available reviews of the third party's
product and service capabilities; and
<bullet> reviewing system performance reports and analyzing error
rates (e.g., false positives or negatives), mean time to detect
threats, and testing the accuracy of threat detection through simulated
exercises.
[[Page 58444]]
If a TCBO has specific standards or requirements \11\ that it needs
a cybersecurity provider to meet (e.g., computer-security incident
notification requirements, periodic reviews or audits, state privacy
laws, data processing and retention timelines, encryption requirements,
system availability standards, and multi-factor authentication
requirements), it may benefit from incorporating those standards into
the governing contract as SLAs. A TCBO may also benefit from obtaining
contractual rights to adjust threat detection sensitivity to reflect
the TCBO's risk tolerance and review output reports on a periodic basis
to ensure that the vendor is complying with agreements.
---------------------------------------------------------------------------
\11\ See e.g. Computer-Security Incident Notification, 12 CFR
225.303 (bank service provider notification).
---------------------------------------------------------------------------
4. Payment Processing and Digital Banking Providers
Payment processing and digital banking providers deliver
transaction and account management services including wire transfers,
ACH origination, peer-to-peer payments, bill pay, mobile/online banking
portals, treasury management platforms, commercial or retail digital
banking services (customer facing mobile and digital applications), and
customer service/call center operations. This may also include third-
party payment processors engaged by TCBOs, rather than by a TCBO's
customer.
Overarching Risk Management Considerations
A payment processing and digital banking provider's operational
resilience is a significant risk consideration, since disruptions can
prevent customers from accessing accounts and making payments. The
strategies for managing these risks discussed in Section IV.B are
generally applicable to payment processing and digital banking
providers. In addition, a TCBO may consider developing tested backup
processing methods, such as switching payments to another processing
rail or manually processing time-sensitive transactions.
Payment processing and digital banking providers often support a
TCBO's adherence to payment network rules. To help manage these risks,
a TCBO may benefit from consulting the compliance discussion in Section
IV.B. In addition, a TCBO may consider assessing whether a payment
processor is in good standing with the relevant payment network.
Payment networks typically require payment processors to conduct audits
or file attestations to remain in good standing. Examples include
annual NACHA audits and FedLine Solutions Security self-assessments.
These reports can help the TCBO assess the third party's ongoing
ability to process transactions and secure data consistent with network
rules, and maintain the bank's access to critical payments
infrastructure.
Finally, the provider's information security can be another
important focus area, since payment processing and digital banking
providers typically maintain customer credentials and transaction data,
and security breaches affecting the vendor could expose sensitive
customer data. The discussion of information and systems security in
section IV.B is generally relevant to managing these risks.
Specific Risk Management Considerations
Different payment channels require different data processing
capabilities. For example, instant payment channels may require higher
frequency data exchanges than channels that rely on batch processing.
As part of due diligence, a TCBO may benefit from verifying that its
payment processor has the data processing capabilities for the payment
channels it wants to offer customers, as well as the ability to
effectively feed information into compliance and fraud detection
systems. To do this, a TCBO can consider requesting product
demonstrations that reflect its individual specifications and business
needs.
As part of routine monitoring of payment processing and digital
banking providers, a TCBO may consider:
<bullet> the quality and accuracy of system-generated alerts to
identify any posting or reconciliation issues between payment
processing systems and core systems;
<bullet> analyzing relevant customer complaints to identify
recurring or emerging issues; and
<bullet> reviewing failed transactions or discrepancies to verify
whether the systems accurately flagged issues.
5. Loan Management System Providers
Loan management system providers support some or all elements of
the lending lifecycle from origination through payoff. They generally
provide loan origination platforms, loan servicing systems, document
management solutions, and lending compliance tools.
Overarching Risk Management Considerations
Loan management system failures can halt new loan originations,
prevent loan servicing activities, and disrupt loan payment processing.
Given that loans typically constitute the largest asset class for
TCBOs, such problems can quickly become a material threat to a TCBO's
business. Thus, a loan management system provider's operational
resilience is an important focus area, and TCBOs may benefit from
consulting the operational resilience considerations discussed in
Section IV.B. In addition, a TCBO may consider whether it can
temporarily substitute manual processes for the third party's services
in the event of sustained disruption.
Loan management systems also contain extensive personal and
financial information. Security breaches affecting loan systems can
expose sensitive borrower information with significant potential for
identity theft and fraud. The discussion of systems and information
security in Section IV.B may be useful in managing these risks.
Specific Risk Management Considerations
Loan management systems are designed to originate, process, and/or
service loans based on the TCBO's established credit risk management
practices and underwriting standards. Some loan management systems may
use automated credit decisioning or risk scoring approaches. During due
diligence, a TCBO may consider the third party's ability to
consistently apply the TCBO's credit policies as part of this
automation. For example, a TCBO may have specific requirements for
certain loan types (e.g., oil and gas loans require specific
structures, covenants, or collateral that must be configured into the
system). A TCBO can verify these requirements are being met through
implementation testing. In addition, a TCBO can consider whether the
third party can support the TCBO's efforts to maintain compliance with
applicable lending laws, and scale with portfolio growth.
Unlike payment processing where errors are often identified
quickly, loan origination or processing errors may remain undetected
for extended periods, allowing errors to accumulate, create loan
origination backlogs, delay loan closings, and prevent customers from
accessing credit during the disruption period. Examples include
automated credit scorecards miscalculating debt ratios due to
incomplete data, incorrect past-due date calculations that generate
[[Page 58445]]
erroneous late fees, or incorrect interest compounding frequencies. To
assess the risk that a provider's systems are prone to such errors, a
TCBO may consider reviewing independent assessments (such as
independent audits or SOC reports) for controls effectiveness, past
regulatory violations, or publicly available complaints databases such
as Consumer Financial Protection Bureau (CFPB) Consumer Complaint
Database.
A TCBO may benefit from sampling loan files to verify that they are
booked accurately, contain the required disclosures, are delivered
timely, and are properly documented. A TCBO remains responsible for
accurate loan processing and disclosures, and may consider contractual
provisions requiring the third party to indemnify the bank for losses
caused by third-party errors, maintain appropriate insurance coverage,
and provide the TCBO access to system documentation or the right to
audit third-party processes.
6. Card Issuing and Processing Providers
Card issuing and processing third parties provide a range of
services for debit card, credit card, and ATM card programs, including
card production, network integration, transaction authorization,
settlement processing, dispute resolution, fraud monitoring, and bank-
identification-number (BIN) sponsorship arrangements. BIN sponsorship
is necessary when the TCBO does not have direct membership in a card
network (e.g., Visa or Mastercard). The BIN sponsoring bank acts as
issuer of the cards, while the TCBO maintains the customer
relationship.
Overarching Risk Management Considerations
Operational resilience is a significant consideration, since system
failures, network disruptions, or processing errors can prevent
customers from accessing their funds, completing purchases, or
withdrawing cash. Financial resilience can become particularly
important when a TCBO relies on a BIN sponsor; if the BIN sponsor
becomes insolvent, the TCBO could lose network access, forcing rushed
program termination and card reissuance. For co-branded card programs
with merchant partners, partner insolvency may leave the institution
liable for unpaid rewards obligations. System and information security
is also a material overarching risk management consideration. Card
programs involve continuous transmission of sensitive cardholder data
across multiple parties and networks, resulting in multiple points of
entry for security breaches. Finally, the provider's adherence to
network rules is a relevant consideration.
In addition to the strategies for addressing these risks discussed
in Section IV.B, a TCBO may review a processor's network compliance
certification and monitor network bulletins for security events.
Further, card networks generally require processors to maintain PCI DSS
attestations and reports of compliance, where applicable. These
attestations and accompanying reports can assist TCBOs with evaluating
the third party's security risk management practices in alignment with
risk appetite.
Specific Risk Management Considerations
In cases where a TCBO is transitioning card service providers, the
TCBO may consider the following to minimize service disruptions:
<bullet> keeping the old processor active while bringing the new
one online to avoid customer card outages;
<bullet> developing communication strategies to inform customers of
card replacement timing, activation procedures, and payment
arrangements that may require updating;
<bullet> validating the accuracy of card holder data (e.g., active/
inactive cards, fraud blocks, or temporary holds) to ensure accurate
reissuing, if necessary; and
<bullet> coordinating with outgoing and incoming BIN sponsors to
migrate card holder data, test network access, and re-issue cards (if
applicable).
As part of ongoing monitoring, a TCBO may benefit from reviewing
customer complaints and system-generated alerts related to card
authorization failures, fraud incidents, or dispute resolution to
assist the TCBO in identifying recurring issues or service quality
concerns. Furthermore, a TCBO may monitor card processing reports to
ensure third parties and processors are not issuing outside of
agreement.
7. BSA/AML and Financial Crime Platform Providers
BSA/AML and financial crime platform providers deliver transaction
monitoring, sanctions screening, currency transaction reporting (CTR),
suspicious activity reporting (SAR), Customer Due Diligence (CDD), and
Customer Identification Program (CIP) services.
Overarching Risk Management Considerations
The principal risk to a TCBO from BSA/AML third parties is the
impact on the TCBO's ability to comply with banking regulations. System
failures, configuration errors, or inadequate transaction coverage can
result in the TCBO facilitating money laundering or terrorist financing
and regulatory violations. While operational resilience of BSA/AML
vendors can be important, TCBOs may be able to rely on manual
workarounds in the event of interruptions. System and information
security is also a key risk consideration, as security breaches
affecting BSA/AML platforms could expose sensitive customer information
and investigation details. A TCBO may benefit from reviewing the risk
management strategies on these issues discussed in Section IV.B.
Specific Risk Management Considerations
In deciding on appropriate BSA/AML tools that meets its compliance
needs, a TCBO may consider reviewing vendor system documentation to
understand detection rules, logic, thresholds, and scenario coverage
for alignment with its risk profile and applicable regulatory guidance
(e.g., FinCEN advisories and sanctions lists). A TCBO may benefit from
considering the extent to which its BSA/AML provider aligns with the
TCBO's risks and business profile. For most TCBOs, basic BSA/AML tools
will be sufficient. Where, however, a TCBO's clients present higher
risk (e.g., marijuana-related businesses), tools with more advanced
capabilities may be appropriate.
As part of ongoing monitoring, a TCBO may consider analyzing
scenarios that generate excessive false positives or do not generate
any useful alerts. Increasing false positive rates may indicate system
tuning is needed, while decreasing alert volumes may indicate system
issues or that tuning is too lenient. Additionally, a TCBO may consider
verifying that the third party delivers timely sanctions list updates
and regulatory changes.
Contract negotiation is also important in managing compliance risks
associated with BSA/AML and financial crime platform providers. When
negotiating contracts, a TCBO may consider:
<bullet> clarifying the third party's responsibilities for
maintaining system compliance with BSA/AML regulations, FinCEN
requirements, and applicable examination guidance. This could include
sanctions list updates and rule changes within defined timeframes;
<bullet> the TCBO's rights to tune alert thresholds, modify
transaction monitoring scenarios, and adjust risk scoring parameters,
including any associated costs and timeframes; and
[[Page 58446]]
<bullet> the TCBO's ownership of customer data, alert histories,
investigation documentation, and SAR filings, with rights to access and
extract data throughout and beyond the contract term.
8. Fraud Prevention and Detection Providers
Fraud prevention and detection providers offer real-time fraud
monitoring, device fingerprinting, behavioral analytics, identity
verification tools, and authentication services across banking
channels. A TCBO may receive these services embedded in another
provider's solution (e.g., the TCBO uses fraud prevention and detection
tools provided through its payment and card processor), or establish
separate relationships to address shortcomings in fraud prevention or
detection for specific delivery channels, products, or transaction
stages.
Overarching Risk Management Considerations
Fraud prevention tools typically operate in real time to prevent
fraudulent transactions before they occur. Operational resilience is
important because system failures can immediately affect the customer
experience--either by blocking legitimate transactions or allowing
fraudulent transactions to proceed, potentially leading to operational
losses at the TCBO. System and information security is important, as
these tools may include access to sensitive customer information such
as biometrics and authentication credentials. Failures to implement
appropriate fraud risk management systems could result in the TCBO
being in violation of network rules. The discussion of these issues in
Section IV.B may be helpful as a TCBO considers how to manage these
risks.
Specific Risk Management Considerations
A fraud detection tool's effectiveness can depend on how thoroughly
and promptly it can take advantage of fraud intelligence data. During
due diligence, a TCBO may consider the third party's ability to
integrate with multiple data sources, including other third-party
systems and threat intelligence feeds (such as dark web monitoring and
shared fraud databases), and apply them to identity verification and
transaction authorization controls.
Many of the risk management strategies that apply to BSA/AML
providers are equally relevant to fraud prevention and detection
providers. As with BSA/AML providers, ongoing monitoring of fraud
prevention and detection providers can include analyzing trends in
fraud alerts, customer complaints, and scenarios that generate
excessive false positives, as increasing false positive rates may
indicate system tuning is needed, while decreasing alert volumes may
indicate system issues or tuning that is too lenient. A TCBO may also
consider the extent to which the provider can calibrate its model based
on the TCBO's direction in keeping with the TCBO's risk appetite.
In addition, when the service provider plays a role in customer
communication and investigating disputes, a TCBO may consider tracking
investigation and resolution timelines to ensure compliance with
contractual commitments and regulatory requirements.
By order of the Board of Governors of the Federal Reserve
System.
Benjamin W. McDonough,
Secretary of the Board.
[FR Doc. 2026-18852 Filed 9-14-26; 8:45 am]
BILLING CODE 6201-01-P
</pre><script data-cfasync="false" src="/cdn-cgi/scripts/5c5dd728/cloudflare-static/email-decode.min.js"></script></body>
</html>This is legal information, not legal advice. Laws vary by jurisdiction and change frequently. Always verify current law with official sources and consult a licensed attorney in your jurisdiction for advice on your specific situation.