Skip to content

Invest2 publishers3 min readPublished

Bank regulators put core-provider contracts on the exam agenda of the banks that signed them

The FDIC, Federal Reserve, OCC and NCUA want examiners looking harder at transparency, contract structure and technology inside core servicing deals. The guidance carrying that expectation is non-binding, with 60 days for comment.

The Investor · Invest desk

Illustration accompanying Bank regulators put core-provider contracts on the exam agenda of the banks that signed them

What happened

  • The FDIC, Federal Reserve Board, NCUA and OCC proposed new third-party risk supervision guidelines on Friday morning, aimed in particular at community banks' relationships with their core service providers.
  • Examiners would apply extra scrutiny to core arrangements that give community banks limited transparency or that unreasonably limit their ability to do due diligence, monitor, or negotiate contract terms.
  • A separate statement from the agencies sets out factors they will consider when making supervisory and enforcement decisions related to core service providers.
  • A companion proposal for so-called traditional community banks calls for less supervisory oversight of institutions that avoid novel activities such as fintech partnerships and digital asset services.
  • Comments on the proposed guidance are due 60 days after it is published in the Federal Register.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • constraint An examiner can now criticise contract terms a small bank had almost no power to set, because the agencies themselves say the core sector is concentrated and the choice of providers is thin.
  • decision A community bank weighing a fintech partner is also choosing which supervisory track it sits on, and the cheaper track is the one without the partner.
  • exposure Core providers, which are not the examined institutions, are named in a document about enforcement decisions, so their disclosure and contracting practices become reachable through their clients.
  • contradiction A sitting Fed governor says the package puts its detail in the wrong place, leaving the banks with the most complex vendor arrangements with the vaguer of the two documents.

The instrument here is a bank examination. The agencies say the core services sector is highly concentrated and that community banks have few providers to choose from [10]. The remedy they propose for that concentration is risk-based examinations of the arrangements [11]. An examiner reads a contract the bank signed and had little power to rewrite. The guidance itself is addressed to the banks. It "is intended to assist banks and credit unions to better align and tailor their third-party risk management practices to the risks of individual third-party relationships," the agencies said in a joint statement [18].

The providers get a document of their own, of a kind. Neither account says what authority those supervisory and enforcement decisions would rest on, or what a core provider would actually face. A dollar figure appears nowhere in either one [21].

The proposed guidance takes a principles-based approach and, as with all supervisory guidance, is non-binding, according to the OCC's release [5]. Pressure therefore arrives at the next exam, in an examiner's judgement about transparency, contract structure and technology components [3]. The proposal also asks for closer oversight of servicers' technology investments and capabilities [12]. When the text is final the agencies plan to rescind the existing third-party risk management guidance and replace it [7].

The lighter track is the part that changes procurement. A community bank comparing its incumbent core provider's own digital product against a third-party fintech partnership now has a supervisory reason to prefer the incumbent. That sits awkwardly beside Federal Reserve Gov. Lisa Cook's statement that a principles-based and risk-focused approach "may be helpful towards promoting these goals," "especially for enabling innovation and competition for vendor services" [17].

Fed Gov. Michael Barr objected that the traditional-bank guidelines were drafted more specifically than the broader third-party guidance [15]. "Experience suggests that many banks with complex business models are especially in need of guidance that better addresses their particular third-party risk management issues, which is not addressed in these proposals," he said [16].

The two accounts also differ on who issued the community-bank companion. American Banker describes a joint proposal from the agencies covering traditional community banks and their third-party service providers [13]. The OCC release says the Federal Reserve Board separately requested comment on a guide for Fed-supervised community banks [14]. Three documents landed that day, or four, depending on which account is right [20].

The counter-thesis is straightforward, and it is cheap. Examiner attention is free leverage for a small bank at renewal: a compliance officer who can cite supervisory expectations on transparency and on the ability to negotiate terms [4] has an argument he did not have last week. Making it costs nothing. That reading holds only while the leverage stays with the buyer. If the agencies open a supervisory action against a core provider itself under the factors in that separate statement [8], the pressure has found the party with the market power, and the argument above is wrong.

What to watch

  • Whether the lighter oversight track for traditional community banks survives into the final text after the comment period closes.
  • Whether the community bank companion document is finalised as a Federal Reserve-only guide or as a joint product of all four agencies.
  • Whether the largest core providers file comment letters objecting to the language on contract negotiation and due diligence access.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories