39.3 Third-Party Planning, Diligence and Contract Design
Key Takeaways
Third-party risk management covers planning, diligence, contracts, monitoring and termination.
A bank retains responsibility for applicable obligations performed through a service provider.
Contract controls should address the actual service, information access, oversight and exit risks.
1. Supervisory Framework & Retaining Responsibility for Regulated Activities
Modern banks rely heavily on external vendors and technology partners to deliver consumer financial services. However, federal banking laws establish an unyielding supervisory principle: a banking organization's use of third parties does not diminish its responsibility to ensure that all activities comply with applicable consumer protection laws and safety and soundness standards.
Responsibility under the governing law
A bank cannot contract away its compliance obligations. From a regulatory and legal standpoint:
- Determine responsibility under the applicable statute, agency relationship and transaction facts. Outsourcing a regulated duty does not eliminate that duty, but it does not create automatic liability for every unrelated action of a vendor.
- Apply the governing duty: A creditor or servicer remains responsible for its applicable duties when using vendors. Mortgage payment crediting is addressed by Regulation Z Section 1026.36(c)(1); other servicing protections are in Regulation X. Determine any bank liability for a collection agency’s acts under the relevant law and facts rather than an automatic strict-liability doctrine.
- Regulatory agencies assess supervisory enforcement actions, civil money penalties, and applicable consumer restitution orders against the charter itself, regardless of any private indemnification clauses in the vendor contract.
Statutory Authority: The Bank Service Company Act (BSCA)
Under Section 7(c) of the Bank Service Company Act (12 U.S.C. § 1867(c)), the performance of any service for an insured depository institution by a third party is subject to regulation and examination by the bank's primary federal banking agency to the same extent as if such services were being performed by the bank itself on its own premises. Regulators exercise direct authority to examine vendor facilities, interview vendor staff, inspect system source code, and review vendor workpapers.
2. The Five Stages of the Third-Party Risk Management Lifecycle
The Interagency Guidance articulates a continuous, five-stage lifecycle framework that institutions should implement for all third-party relationships, scaled to the risk profile and criticality of the activity:
Stage 1: Planning & Scoping
Prior to entering into any relationship, the bank should evaluate the strategic business case, evaluate operational complexities, and assess inherent compliance risks:
- Critical Third-Party Designation: The guidance establishes a heightened supervisory tier for critical third-party relationships. A third-party relationship is designated as critical if it involves activities that:
- Cause the bank to face significant risk if the third party fails to meet expectations;
- Have a significant customer impact (e.g., direct-facing deposit or lending channels); or
- Involve significant investment or handle sensitive customer information (Nonpublic Personal Information [NPI] under GLBA).
- Compliance Risk Assessment: Compliance leadership should identify all consumer protection statutes implicated by the proposed relationship (e.g., TILA, ECOA, Reg E, GLBA, FCRA).
Stage 2: Due Diligence and Selection
Due diligence should be conducted prior to contract execution and commensurate with the criticality of the service:
- Compliance Management System (CMS) Evaluation: Reviewing the vendor's compliance policies, training programs, internal monitoring procedures, consumer complaint logs, and previous regulatory or legal history.
- Financial Condition & Stability: Reviewing audited financial statements, credit ratings, liquidity ratios, and funding runway to ensure the vendor will remain viable throughout the contract term.
- Information Security & Data Governance: Reviewing independent third-party audit reports (such as SOC 1 Type II and SOC 2 Type II reports), network architecture diagrams, data encryption protocols (at rest and in transit), and vulnerability penetration tests under GLBA Safeguards (12 CFR Part 30 Appendix B).
- Business Continuity & Incident Response: Reviewing Business Continuity Plans (BCP), Disaster Recovery (DR) test results, recovery time objectives (RTO), and incident response plans.
- Subcontractor (Fourth-Party) Risk: Evaluating the vendor's policies for selecting, managing, and monitoring downstream subcontractors who will have access to bank systems or customer data.
Stage 3: Contract Negotiation and Risk-Based Protections
Contracts govern the legal rights, duties, and risk allocations between the parties. In critical relationships, the compliance officer should verify the inclusion of essential protective clauses:
- Clear Scope of Services & Performance Standards (SLAs): Specific operational deliverables, processing timelines, and quantifiable service level agreements (SLAs) with financial penalties for non-compliance.
- Regulatory Compliance Covenant: Express contractual commitment that the third party will comply with all federal and state consumer financial protection laws and promptly update systems upon regulatory changes.
- Unrestricted Audit and Examination Rights: Absolute right of the bank, internal audit, external reviewers, and federal regulatory agencies to access vendor facilities, personnel, records, and systems for examination purposes.
- Data Security, GLBA Safeguards, and Confidentiality: Strict obligations to protect NPI and customer records in compliance with GLBA Section 501(b).
- Incident notification: Negotiate prompt notice and useful incident information. The bank’s thirty-six-hour regulatory clock starts after its determination of a notification incident. Covered service providers separately notify affected bank contacts as soon as possible for qualifying disruptions lasting, or reasonably likely to last, four or more hours. Twenty-four-to-thirty-six-hour contract language is not a universal requirement.
- Subcontracting Restrictions: Express prohibition against delegating or subcontracting services without the bank's prior written consent.
- Indemnification & Insurance: Robust indemnification clauses protecting the bank against regulatory fines, civil money penalties, consumer restitution, and defense costs resulting from vendor non-compliance or data breaches, accompanied by appropriate cyber liability insurance coverage.
- Default, Termination, and Transition Rights: Right of the bank to terminate the agreement promptly without financial penalty upon material regulatory breach, supervisory directive, or failure to remediate audit findings.
A bank's compliance officer is reviewing a proposed master services agreement with a critical cloud computing vendor that will store all customer deposit and credit card account records. Which of the following contractual provisions is essential to ensure compliance with federal supervisory expectations and the Interagency Guidance on Third-Party Relationships?
Appropriate audit and access provisions, security safeguards and prompt incident information, with limitations assessed and escalated under the risk-based contract process.
A provision establishing that the vendor's liability for data security breaches and regulatory fines is capped at the total monthly fee of $500.
A clause prohibiting federal banking examiners from inspecting vendor server facilities unless the bank gives 90 days of prior written notice.
A requirement that all consumer disputes involving the vendor's software be resolved through binding arbitration without notifying the bank.
Sections you finish are checked off in the contents.