Third-Party Risk Management Guidance
Interagency guidance · issued June 2023Who it applies to
- Entities and teams responsible for risk management across the third-party relationship lifecycle
- Entities and teams responsible for contingency planning for critical third-party providers
- Entities and teams responsible for ability to transition or terminate without undue disruption
- Entities and teams responsible for ongoing monitoring of provider performance and resilience
The Interagency Guidance on Third-Party Relationships is current supervisory guidance rather than a rule with one implementation date. Banking organisations are expected to apply it through their ongoing third-party risk-management lifecycle.