Third-party risk in US financial services: five rulebooks, one expectation.
A US financial institution answers to several supervisors on third-party risk at once — the banking agencies’ 2023 interagency guidance, the FFIEC handbooks, the SEC’s disclosure rules, the FTC’s Safeguards Rule, and NYDFS Part 500 if you are licensed in New York. They use different language and land on the same place: you remain accountable for what your providers do, and “ongoing” monitoring means ongoing. This page sets out what each requires and what a program has to be able to evidence.
Last reviewed
The 2023 interagency guidance
One document replacing three, organised around the life cycle of a third-party relationship.
On 6 June 2023 the Federal Reserve, FDIC and OCC issued joint final guidance on third-party relationships, replacing each agency’s separate material — including OCC Bulletin 2013-29 and its 2020 FAQs — with a single set of expectations. It is guidance rather than a rule, and it is what examiners work from.
Its structure is the relationship life cycle, and each stage carries expectations:
- Planning — assess the risk of the arrangement before you enter it, including whether it involves a critical activity.
- Due diligence and third-party selection — proportionate to risk, covering the provider’s financial condition, business experience, information security, subcontractor use, resilience and legal or regulatory standing.
- Contract negotiation — performance measures, incident notification, audit and reporting rights, subcontractor conditions, and termination terms that let you exit.
- Ongoing monitoring — through the life of the relationship, with intensity matched to risk.
- Termination — planned, including data return and transition, so exit is possible in practice rather than only in the contract.
Three themes run across all of them: governance and accountability with named oversight, independent reviews of the program itself, and documentation and reporting good enough for someone else to follow. The guidance is also explicit that the depth of all this should scale with the size and complexity of the institution and the risk of the relationship — which is the sentence a small institution should hold on to, because it is not an instruction to do everything for everyone.
The FFIEC handbooks
Where the operational detail lives, and what examiners open on the day.
The FFIEC IT Examination Handbook series is the working detail underneath the interagency guidance — outsourcing, architecture and operations, business continuity, information security. Where the guidance sets expectations, the handbooks describe what adequate looks like in an examination, including for the concentration and resilience questions that come up when a whole sector depends on the same handful of core processors and cloud platforms.
The practical use of them is pre-examination: they tell you what will be asked for. Institutions that get uncomfortable examinations on third-party risk usually fail on evidence rather than on intent — an inventory that does not reconcile, monitoring that turns out to be an annual questionnaire, or critical vendors whose contracts lack the notification and audit rights the guidance expects.
The SEC disclosure rules
Which turn a vendor incident into a filing question, on a four-day clock.
For public companies, the SEC’s cybersecurity rules do two things. Under Item 1.05 of Form 8-K, a material cybersecurity incident must be disclosed within four business days of determining that it is material — the clock runs from the materiality determination, not from discovery, and the determination itself must be made without unreasonable delay. Under Regulation S-K Item 106, the annual report must describe your processes for assessing, identifying and managing material cybersecurity risks — explicitly including risks associated with your use of third-party service providers — plus board oversight and management’s role.
The third-party implication is the part that catches people. An incident at a service provider can be material to you, and the obligation to determine that sits with you — while the facts sit with them. If a critical vendor’s contract does not require prompt notification with enough detail to run a materiality assessment, you have a disclosure obligation you cannot meet on time. That is a contracting problem, and it is cheapest to fix before signature.
It also raises the standard on the Item 106 description. Ninety percent of large filers already describe evaluating or monitoring vendors’ security practices, which means a thin description now stands out — and the description has to be true.
NYDFS Part 500
The most prescriptive of the five, and the one with the hardest deadlines.
New York’s cybersecurity regulation applies to entities licensed by the Department of Financial Services, and it is a rule rather than guidance. Section 500.11 requires a written third-party service provider security policy covering identification and risk assessment of providers, minimum security practices required of them, due diligence to evaluate those practices, and periodic reassessment.
The amended regulation phased in through to 1 November 2025, when the final tranche took effect — including multi-factor authentication for all individuals accessing any information system, which reaches third-party vendor access as well as your own staff. DFS guidance has been explicit on two points worth quoting to a board: covered entities remain accountable for the cybersecurity risk their providers create and cannot delegate that accountability, and the expectation is that vendors be contractually required to meet MFA standards comparable to your own. Compliance with the final provisions was first certified in the annual submissions due 15 April 2026.
If you are NYDFS-regulated, Part 500 is usually the binding constraint — build to it and the other four rulebooks are largely satisfied on the third-party dimension.
The GLBA Safeguards Rule
For the non-bank financial institutions the banking agencies do not supervise.
The FTC’s Safeguards Rule under Gramm-Leach-Bliley applies to non-banking financial institutions — mortgage brokers, auto dealers, payday lenders, and others. It requires a written information security program with a qualified individual accountable for it, and it addresses service providers directly: select providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess them.
Since 13 May 2024 it also carries a notification duty. A security breach involving the unencrypted information of 500 or more consumers must be reported to the FTC as soon as possible and no later than 30 days after discovery, through a form on the FTC’s site. “Unencrypted” includes encrypted data where the key was also accessed. As with the SEC rule, the clock can start at an event inside a service provider, and you cannot report what they have not told you.
What all five require require
Different rulebooks, converging demands. Build to the right-hand column and you satisfy the third-party dimension of all of them.
| Expectation | What has to exist | What examiners ask for |
|---|---|---|
| Know your third parties | A complete inventory, risk-ranked, reconciled against payables and contracts | The list, and how you know it is complete |
| Diligence before commitment | Assessment proportionate to risk, completed before signature | The assessment for a named critical vendor, and its date relative to the contract |
| Contract terms that work | Notification deadlines, audit and evidence rights, subcontractor conditions, exit terms | The clauses in a live contract, not the template |
| Ongoing monitoring | Continuous, risk-scaled, with a named owner and an escalation path | What changed at a critical vendor last quarter, and who was told |
| Governance and reporting | Named accountability, board-level reporting, independent review of the program | Board pack extracts and the last independent review |
The word that does the work is "ongoing"
US financial services questions.
What is the 2023 interagency guidance on third-party relationships?
Do the SEC rules require disclosing a vendor breach?
What does NYDFS Part 500 require for third-party providers?
Does a SOC 2 report satisfy these requirements?
Is there a small-institution exemption?
Related reading.
“What changed since the last review?” Have an answer.
Book a 30-minute call and we will show you continuous monitoring on one of your critical providers — the evidence that answers the question an examiner actually asks.