Embracing Escrow: OCC, FDIC, and FED Board releases revised third-party risk management guidelines for US Banks
In June this year, the
These guidelines replace the FED's 2013 guidance, the
The guidance offers the views of the OCC,
The new guidance demonstrates a continued drive towards operational resilience amongst financial services providers, and it will apply to all banking institutions within
The "Third-Party Relationships: Interagency Guidance on Third-Party Relationships: Risk Management" stipulates that banks must review their internal policies, standards and procedures. With the industry's increased reliance on third-party technology and software, the guidance now requires banks to revise their relationships with software suppliers to include third party risk management principles. This must include independent reviews, documentation and reporting, and oversight and accountability.
The regulators identify 5 key stages where third-party risk management must be considered:
- Planning
- Due diligence and 3rd party selection
- Contract negotiation
- Ongoing monitoring
- Termination
Notably, the agencies recognized the crucial role played by contractual and escrow arrangements between banks and third-party providers. Software escrow agreements emerge as highly efficient, proportionate, and cost-effective measures to mitigate risks associated with technology providers. These agreements offer a minimum level of resilience through legal and technical means, ensuring uninterrupted business operations during service restoration or the implementation of alternative options.
Escrow agreements are directly mentioned in the stipulations for contract negotiation with third parties, however, it applies across all stages of risk management.
The inclusion of Escrow agreements is a progressive step forward in regulating third party risk management. Escrow is a solution that is proportional to each application whilst remaining cost effective, allowing smaller financial institutions to implement it immediately.
"We are pleased to see the agencies adopt our recommendation to include guidance on practical resilience solutions like Escrow. Its inclusion in third party risk management will be particularly impactful. Escrow agreements are no longer an afterthought for these institutions; they're front and centre throughout the risk management process.
"The guidelines represent a significant step towards accountability and resilience in the financial services sector, especially with general trends showing the increase in the number and type of banking organizations' third-party relationships. By embracing the principles outlined and incorporating Escrow provisions, banks can enhance their risk management practices and ensure the smooth continuity of their operations."
Attachments
Disclaimer
Fine Art Insurance Market Is Booming Worldwide with Zurich, Chubb, Aspen Insurance
Travelers Announces the Start of the 2023 Travelers Championship
Advisor News
Annuity News
Health/Employee Benefits News
Life Insurance News