You can't outsource the risk
A bank can outsource an activity. It cannot outsource the responsibility for that activity. That single principle sits at the center of how regulators now expect financial institutions to manage third parties, and it is the one most vendor-management programs still get wrong.
The rule the regulators actually stated
In June 2023, the Federal Reserve, FDIC, and OCC issued joint Interagency Guidance on Third-Party Relationships: Risk Management, replacing each agency's separate, older guidance with a single consistent standard. Its core principle is blunt: whether an activity is performed in-house or by a third party, the institution remains responsible for operating in a safe and sound manner and complying with the law, to the same extent as if it did the work itself. Using a vendor does not diminish the obligation. It simply adds a party you now have to govern.
A lifecycle, not a questionnaire
The guidance frames third-party risk as a lifecycle, and each stage is a place where risk is either managed or quietly accepted:
- Planning: deciding, before you engage, whether and how to use a third party for the activity, and what risk it introduces.
- Due diligence and selection: assessing the vendor's ability to perform, its controls, its financial condition, and its own reliance on others, tailored to the criticality of what it will do.
- Contract negotiation: putting audit rights, security and breach-notification obligations, performance standards, and exit rights in writing, before you sign.
- Ongoing monitoring, the stage most programs underinvest in: watching performance and risk across the life of the relationship, not just at onboarding.
- Termination: being able to exit cleanly, with data returned or destroyed and the activity transitioned, brought in-house, or wound down without disrupting customers.
Around all of it sits governance: clear accountability, documentation and reporting, and independent review, with the board engaged where the activity is critical.
You can outsource the activity. You cannot outsource the responsibility.
Where programs actually fail
Most third-party programs do the front end (a due-diligence questionnaire at onboarding) and then go quiet. But risk isn't static. Vendors change ownership, degrade, get breached, or quietly subcontract your critical work to a fourth party you never assessed. The failures that reach the board almost always trace to the same gaps: no ongoing monitoring, no inventory of which vendors support critical activities, and no real exit plan for the ones that do.
Concentration is the risk behind the list
The most dangerous third-party exposures rarely show up in a vendor spreadsheet, because they are not about any single vendor: they are about concentration. When many institutions, or many of your own critical services, depend on the same cloud platform, core provider, or processor, one failure cascades. A defensible program doesn't just assess vendors one at a time; it maps where the single points of failure sit across the whole estate, and asks what happens when one of them goes down.
What good looks like
A mature program is risk-tiered (not every vendor earns the same scrutiny), continuous rather than a one-time check, and board-visible for the relationships that support critical operations. Above all, it is owned: someone inside the institution is accountable for each critical third party, because the regulator holds the institution accountable regardless.
NorthBridge helps regulated institutions build third-party risk programs that satisfy the interagency guidance and actually reduce risk: risk-tiered, continuously monitored, and board-ready, with concentration and exit risk made visible. If your program stops at onboarding, let's close the gap.
Start a conversationRelated: What boards should ask the CISO, and our illustrative board cyber dashboard.