Four major financial services trade groups released a joint report last week calling on federal banking regulators to overhaul how they supervise banks’ relationships with technology vendors and third-party vendors. The report, produced by the Consumer Bankers Association, American Fintech Council, Coalition for Financial Ecosystem Standards, and Independent Community Bankers of America, argues that the supervisory framework governing third-party risk management (TPRM) is increasingly misaligned with how banks actually operate today.
The core argument
The groups aren’t calling for a wholesale rewrite of the 2023 Interagency Guidance on Third Party Relationships. What they want changed is how that guidance gets applied in practice, and how regulators handle the realities of a banking technology ecosystem now dominated by a handful of hyperscale cloud providers and a small number of AI infrastructure developers.
The report warns that banks today manage hundreds or thousands of vendor relationships, many involving AI systems that update continuously and resist the kind of point-in-time validation the current framework was built around. The result, the groups argue, is a growing gap between what examiners expect and what is operationally achievable.
“The central question in third-party risk management can no longer be whether a bank can eliminate all risks at the outset of a vendor relationship,” the report states. Instead, it frames the core challenge as whether banks can identify, monitor, and contain risks in real time.
What the report recommends
The groups make six near-term recommendations, several of which are directly relevant to companies that sell to or partner with banks:
- Regulators should stop penalizing banks for failing to obtain information from dominant vendors that simply won’t provide it. This matters because the same dynamic plays out when banks push collection agencies and other service providers for compliance documentation.
- The guidance’s current specificity around due diligence, contracting, and governance should be preserved. Banks told the report’s authors they use that specificity as leverage in vendor negotiations. Weakening it would reduce their ability to demand transparency from all service providers, including those in the collections space.
- Banks should be responsible only for assessing their direct vendors’ own subcontractor management programs, not for directly supervising “nth party” relationships further down the chain. This is a potential benefit for collection agencies that rely on technology subcontractors: the expectation would stop at the agency level, not cascade to every software provider it uses.
- Examiners should be trained to apply the guidance as a risk-calibrated framework rather than a universal checklist. The groups flagged inconsistency across agencies and regions as a significant pain point, with some examiners treating the guidance as a mandatory compliance scorecard regardless of the risk level of the relationship.
- AI tools used for due diligence and vendor monitoring should be explicitly encouraged, and the governance requirements for those tools should be proportionate to the decisions they support.
- A “common app” for vendor due diligence should be developed through public-private collaboration.
The longer-term picture
The report also raises questions the groups acknowledge won’t be resolved quickly. These include whether the Bank Service Company Act, which gives regulators authority to directly examine companies that provide services to banks, should be more aggressively used against dominant vendors that refuse to cooperate with reasonable oversight requests. The groups stop short of recommending immediate action on this front but encourage regulators to study whether the Act’s scope is adequate for the current technology landscape.
On AI specifically, the report is notably candid: the technology offers genuine promise for automating due diligence and improving monitoring, but shouldn’t be used as a stand-in for regulatory clarity. The groups push back against what they describe as an industry tendency to treat “AI will figure this out” as an answer to hard policy questions.




