The Office of the Comptroller of the Currency, Federal Reserve, and Federal Deposit Insurance Corporation released interagency guidance in March 2024 establishing clear expectations for how regulated financial institutions manage relationships with technology service providers and other critical third parties. The guidance consolidates previous supervisory statements and updates risk management standards to reflect current operational dependencies.
The practical challenge for leadership is not interpreting the guidance—it is establishing clear ownership for an outcome that touches procurement, compliance, technology, legal, and operations without naturally residing in any single function. The result is accountability without structure: everyone agrees third-party risk matters, but no one coordinates the assessments, monitors the controls, or decides when to escalate.
Why Third-Party Risk Management Is Now a Board and Executive Concern
Most financial institutions depend on external technology providers for core banking platforms, payment processing, cybersecurity monitoring, data analytics, and cloud infrastructure. When one of these providers experiences a security incident, operational failure, or compliance lapse, your institution inherits the consequence—regulatory action, customer notification obligations, business interruption, and reputational exposure—without having direct control over the underlying controls.
The March 2024 guidance treats this operational reality as a governance issue. Examiners will look for evidence that the board and senior management understand the risk, have assigned clear accountability, fund the program appropriately, and receive reporting sufficient to make risk decisions. The absence of that structure, regardless of what individual departments are doing, constitutes a supervisory finding.
What the Guidance Requires at Each Stage of the Third-Party Lifecycle
The interagency guidance organizes third-party risk management into five stages: planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination. Each stage carries specific expectations.
Planning and Risk Assessment
Before engaging a third party, the institution must document the business need, identify the data and systems involved, assess the criticality of the service, and determine the inherent risk. This assessment determines the depth of due diligence required and the intensity of ongoing oversight. The expectation is that someone with sufficient authority approves the decision to proceed and that the approval is based on a documented risk analysis, not just cost or convenience.
Due Diligence and Selection
Due diligence must be proportionate to the risk. For critical service providers—those whose failure would impair operations, customer service, or regulatory compliance—the institution must evaluate financial condition, operational resilience, information security controls, business continuity plans, regulatory history, and subcontractor dependencies. The guidance expects documented evidence: audit reports, security assessments, certifications, and evidence of testing. A questionnaire alone is not sufficient for high-risk relationships.
Contract Negotiation
Contracts must include specific provisions: performance standards, the right to audit, notification requirements for security incidents and material changes, ownership and return of data, compliance with applicable law, and termination rights with sufficient notice to allow orderly transition. For critical third parties, the guidance expects the institution to negotiate these terms rather than accept standard agreements without modification. Examiners will review whether the contract gives the institution the access and control needed to manage the risk.
Ongoing Monitoring
Monitoring is not annual compliance paperwork. The institution must track performance against service-level agreements, review security and audit reports when issued, validate that contractual controls remain effective, and reassess risk when the third party's ownership, financial condition, or service model changes. For critical providers, this includes periodic independent testing or on-site assessments. The expectation is continuous awareness, not point-in-time review.
Termination and Transition
The institution must have a documented exit strategy for every critical third party. This includes identifying alternative providers, establishing transition timelines, securing data return or destruction, and ensuring continuity of service during the change. The absence of a credible exit plan is a finding, because it means the institution has no practical recourse if the relationship must end due to performance, risk, or regulatory concern.
Who Owns Third-Party Risk Management and What That Ownership Entails
The guidance expects the board to approve the third-party risk management framework, receive regular reporting on critical relationships, and ensure that senior management has assigned accountability. That accountability typically does not rest with a single department. Procurement initiates relationships, technology evaluates capability, legal negotiates contracts, compliance validates regulatory alignment, and information security assesses controls. The problem is coordination.
Effective ownership requires someone with enterprise authority to maintain the inventory of critical third parties, establish risk rating criteria, determine when due diligence is adequate, decide when contract terms are acceptable, escalate findings that affect strategic or regulatory risk, and report the overall posture to the board. This role is not administrative. It requires risk judgment, regulatory literacy, and sufficient authority to pause or terminate a relationship when the evidence warrants it.
Many institutions assign this responsibility to a chief risk officer, chief compliance officer, or chief information security officer. The more common problem is that the title exists but the authority, time, or expertise does not. If the person nominally accountable has no power to reject a vendor selection made by the business line, no time to review the audit reports, and no regulatory background to interpret the findings, the structure exists only on paper.
How This Relates to Vendor, MSP, and Third-Party Oversight
Third-party risk management is the governance discipline. Vendor oversight, managed service provider relationships, and technology vendor assessments are the operational activities that discipline governs. The distinction matters because technology teams often perform vendor assessments without a clear connection to enterprise risk decisions or board reporting. Compliance teams may track vendor contracts without visibility into operational performance or security incidents. Information security may evaluate controls without understanding the business dependency or regulatory classification.
The guidance closes that gap by requiring a single coordinated framework. Every critical relationship must be classified, assessed, monitored, and reported under one structure with consistent criteria. Leadership must know which vendors pose material risk, what controls are in place, where gaps exist, and what would happen if the relationship ended tomorrow. If that information is scattered across departments with no consolidated view, the program does not meet supervisory expectations regardless of how much work individual teams are doing.
What Leadership Should Do Next
Start with a forthright internal assessment. Can your board describe the institution's three most critical third-party relationships and the residual risk in each? Can senior management produce a current inventory of all technology service providers with criticality ratings and the last assessment date? Can someone with authority make a risk-based decision to terminate a vendor relationship if the evidence supports it? If the answer to any of these is uncertain, the problem is not process—it is governance.
Establish clear ownership at the executive level with sufficient authority, time, and expertise. This may mean elevating a current role, creating a cross-functional committee with real decision rights, or bringing in fractional executive leadership with regulatory and cybersecurity experience. The person accountable must be able to read a SOC 2 report, interpret a penetration test, negotiate contract language, and explain the findings to the board in business terms.
Document the framework before adding more procedure. Define what makes a third party critical, what level of due diligence each risk tier requires, what contract provisions are mandatory, how often reassessment occurs, what triggers escalation, and who decides. If the framework is sound, operational teams can execute it. If the framework is unclear, additional checklists will not improve the outcome.
Review your most critical relationships first. Identify the providers that, if compromised or unavailable, would halt operations or create regulatory exposure. Confirm that contracts include audit rights, incident notification, and termination provisions. Validate that current security assessments exist and that someone with technical competence has reviewed them. If gaps exist, document them, assign remediation deadlines, and report status to the board.
Build board reporting that presents risk, not activity. The board does not need a list of every vendor or a summary of questionnaires completed. It needs to know which relationships carry material risk, what the institution is doing to manage that risk, where controls are insufficient, and what decisions require board input. If current reporting cannot answer those questions concisely, the underlying program is not producing the right information.
When Fractional Leadership Solves the Ownership Problem
Many community banks and credit unions have capable technology and compliance teams but lack the executive-level role that ties third-party risk management to enterprise strategy, regulatory expectations, and board oversight. Creating a full-time C-suite position may not be justified by the institution's size or complexity, but the accountability gap remains.
[Virtual CISO leadership](/vciso/) provides that missing executive function on a fractional basis. A vCISO establishes the governance structure, defines risk criteria, leads the assessment of critical relationships, ensures that findings are escalated appropriately, and reports to the board in terms that connect cybersecurity and vendor risk to business resilience and regulatory standing. The result is clear ownership without the cost or organizational disruption of a permanent hire.
This approach is particularly effective when the institution already has competent operational teams but lacks the strategic and regulatory oversight those teams need to coordinate effectively. The vCISO does not replace internal staff—they provide the executive authority, regulatory literacy, and cross-functional coordination that turns distributed activity into a coherent program.
Moving from Compliance Activity to Strategic Oversight
The March 2024 interagency guidance does not introduce an entirely new set of technical requirements. It makes explicit what examiners have been finding for years: that third-party risk management is an executive governance responsibility, not a departmental compliance task. The institutions that struggle are not those lacking procedures—they are those lacking ownership, clarity, and the ability to connect operational findings to strategic and regulatory decisions.
If your institution cannot quickly answer who owns third-party risk, what the critical relationships are, and how the board knows the program is working, the gap is governance. Address that first. The rest follows more readily than most leadership expects.
If establishing that governance structure is the current obstacle, a confidential consultation can clarify what sufficient ownership looks like for your institution, what frameworks meet supervisory expectations, and whether fractional executive leadership would close the gap more effectively than internal reorganization. That conversation is available once, when the decision is live.
Sources
- Cybersecurity Framework | NIST , www.nist.gov
- Privacy and Security | Federal Trade Commission , www.ftc.gov
- Privacy Framework | NIST , www.nist.gov
Related service: Vendor, MSP and Third-Party Oversight
Clear accountability for the security work your providers perform: defined expectations, stated evidence requirements, and a review process that holds over the life of the contract.