US financial services

Third-party risk in US financial services: five rulebooks, one expectation.

A US financial institution answers to several supervisors on third-party risk at once — the banking agencies’ 2023 interagency guidance, the FFIEC handbooks, the SEC’s disclosure rules, the FTC’s Safeguards Rule, and NYDFS Part 500 if you are licensed in New York. They use different language and land on the same place: you remain accountable for what your providers do, and “ongoing” monitoring means ongoing. This page sets out what each requires and what a program has to be able to evidence.

Last reviewed

The 2023 interagency guidance

One document replacing three, organised around the life cycle of a third-party relationship.

On 6 June 2023 the Federal Reserve, FDIC and OCC issued joint final guidance on third-party relationships, replacing each agency’s separate material — including OCC Bulletin 2013-29 and its 2020 FAQs — with a single set of expectations. It is guidance rather than a rule, and it is what examiners work from.

Its structure is the relationship life cycle, and each stage carries expectations:

  • Planning — assess the risk of the arrangement before you enter it, including whether it involves a critical activity.
  • Due diligence and third-party selection — proportionate to risk, covering the provider’s financial condition, business experience, information security, subcontractor use, resilience and legal or regulatory standing.
  • Contract negotiation — performance measures, incident notification, audit and reporting rights, subcontractor conditions, and termination terms that let you exit.
  • Ongoing monitoring — through the life of the relationship, with intensity matched to risk.
  • Termination — planned, including data return and transition, so exit is possible in practice rather than only in the contract.

Three themes run across all of them: governance and accountability with named oversight, independent reviews of the program itself, and documentation and reporting good enough for someone else to follow. The guidance is also explicit that the depth of all this should scale with the size and complexity of the institution and the risk of the relationship — which is the sentence a small institution should hold on to, because it is not an instruction to do everything for everyone.

The FFIEC handbooks

Where the operational detail lives, and what examiners open on the day.

The FFIEC IT Examination Handbook series is the working detail underneath the interagency guidance — outsourcing, architecture and operations, business continuity, information security. Where the guidance sets expectations, the handbooks describe what adequate looks like in an examination, including for the concentration and resilience questions that come up when a whole sector depends on the same handful of core processors and cloud platforms.

The practical use of them is pre-examination: they tell you what will be asked for. Institutions that get uncomfortable examinations on third-party risk usually fail on evidence rather than on intent — an inventory that does not reconcile, monitoring that turns out to be an annual questionnaire, or critical vendors whose contracts lack the notification and audit rights the guidance expects.

The SEC disclosure rules

Which turn a vendor incident into a filing question, on a four-day clock.

For public companies, the SEC’s cybersecurity rules do two things. Under Item 1.05 of Form 8-K, a material cybersecurity incident must be disclosed within four business days of determining that it is material — the clock runs from the materiality determination, not from discovery, and the determination itself must be made without unreasonable delay. Under Regulation S-K Item 106, the annual report must describe your processes for assessing, identifying and managing material cybersecurity risks — explicitly including risks associated with your use of third-party service providers — plus board oversight and management’s role.

The third-party implication is the part that catches people. An incident at a service provider can be material to you, and the obligation to determine that sits with you — while the facts sit with them. If a critical vendor’s contract does not require prompt notification with enough detail to run a materiality assessment, you have a disclosure obligation you cannot meet on time. That is a contracting problem, and it is cheapest to fix before signature.

It also raises the standard on the Item 106 description. Ninety percent of large filers already describe evaluating or monitoring vendors’ security practices, which means a thin description now stands out — and the description has to be true.

NYDFS Part 500

The most prescriptive of the five, and the one with the hardest deadlines.

New York’s cybersecurity regulation applies to entities licensed by the Department of Financial Services, and it is a rule rather than guidance. Section 500.11 requires a written third-party service provider security policy covering identification and risk assessment of providers, minimum security practices required of them, due diligence to evaluate those practices, and periodic reassessment.

The amended regulation phased in through to 1 November 2025, when the final tranche took effect — including multi-factor authentication for all individuals accessing any information system, which reaches third-party vendor access as well as your own staff. DFS guidance has been explicit on two points worth quoting to a board: covered entities remain accountable for the cybersecurity risk their providers create and cannot delegate that accountability, and the expectation is that vendors be contractually required to meet MFA standards comparable to your own. Compliance with the final provisions was first certified in the annual submissions due 15 April 2026.

If you are NYDFS-regulated, Part 500 is usually the binding constraint — build to it and the other four rulebooks are largely satisfied on the third-party dimension.

The GLBA Safeguards Rule

For the non-bank financial institutions the banking agencies do not supervise.

The FTC’s Safeguards Rule under Gramm-Leach-Bliley applies to non-banking financial institutions — mortgage brokers, auto dealers, payday lenders, and others. It requires a written information security program with a qualified individual accountable for it, and it addresses service providers directly: select providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess them.

Since 13 May 2024 it also carries a notification duty. A security breach involving the unencrypted information of 500 or more consumers must be reported to the FTC as soon as possible and no later than 30 days after discovery, through a form on the FTC’s site. “Unencrypted” includes encrypted data where the key was also accessed. As with the SEC rule, the clock can start at an event inside a service provider, and you cannot report what they have not told you.

What all five require require

Different rulebooks, converging demands. Build to the right-hand column and you satisfy the third-party dimension of all of them.

ExpectationWhat has to existWhat examiners ask for
Know your third partiesA complete inventory, risk-ranked, reconciled against payables and contractsThe list, and how you know it is complete
Diligence before commitmentAssessment proportionate to risk, completed before signatureThe assessment for a named critical vendor, and its date relative to the contract
Contract terms that workNotification deadlines, audit and evidence rights, subcontractor conditions, exit termsThe clauses in a live contract, not the template
Ongoing monitoringContinuous, risk-scaled, with a named owner and an escalation pathWhat changed at a critical vendor last quarter, and who was told
Governance and reportingNamed accountability, board-level reporting, independent review of the programBoard pack extracts and the last independent review

The word that does the work is "ongoing"

Every one of these regimes expects monitoring through the life of the relationship, and it is the expectation programs most reliably fail. An annual questionnaire is not ongoing monitoring; it is a periodic re-collection of the vendor’s own claims. The question an examiner can ask — and a plaintiff’s lawyer certainly will — is what you knew about a critical vendor’s security posture between the last assessment and the incident. Continuous external monitoring is the only practical answer that does not depend on the vendor volunteering bad news.

US financial services questions.

What is the 2023 interagency guidance on third-party relationships?
Joint final guidance issued on 6 June 2023 by the Federal Reserve, FDIC and OCC, replacing each agency’s previous third-party risk material — including OCC Bulletin 2013-29 — with one set of expectations organised around the relationship life cycle: planning, due diligence and selection, contracting, ongoing monitoring and termination.
Do the SEC rules require disclosing a vendor breach?
They require disclosing a material cybersecurity incident within four business days of determining materiality, and an incident at a service provider can be material to you. The practical consequence is contractual: without prompt, detailed notification from the vendor you cannot make that determination in time.
What does NYDFS Part 500 require for third-party providers?
Section 500.11 requires a written third-party service provider security policy covering identification and risk assessment, minimum security practices required of providers, due diligence, and periodic reassessment. The amended regulation’s final provisions took effect on 1 November 2025, including MFA for all access to information systems, which reaches vendor access.
Does a SOC 2 report satisfy these requirements?
It contributes and does not complete. A SOC 2 is periodic evidence over a scope the vendor chose; supervisory expectations are for ongoing monitoring across the relationship. See SOC 2 vendor management for what a report does and does not cover.
Is there a small-institution exemption?
No, but proportionality is explicit: the interagency guidance says practices should reflect the size and complexity of the institution and the risk of the relationship. Fewer relationships assessed less elaborately can be entirely adequate — what is not adequate is having no inventory, no diligence before signature, or no monitoring.

“What changed since the last review?” Have an answer.

Book a 30-minute call and we will show you continuous monitoring on one of your critical providers — the evidence that answers the question an examiner actually asks.