Original Source: Everest Group
In late 2013, the Office of the Comptroller of the Currency (OCC) issued a bulletin “providing guidance to national banks and federal savings associations (collectively, banks) for assessing and managing risks associated with third party relationships.”1 This risk management guidance clarifies regulators’ expectations regarding what banks are expected to do related to third-party risk management.
Discussions with Everest Group bank and service provider clients directly affected by these risk management expectations suggested a wide range of approaches to interpreting and implementing the OCC guidance. Everest Group has synthesized a “market perspective” on how organizations perceive and manage these regulatory risk requirements as they relate to services delivered by third parties. This perspective included the requirements and implementation actions and plans with a representative sample of large and mid-sized (regional) banks, service providers with substantial financial services business, law firms with outsourcing and risk management practices, and regulatory agency staff. While these discussions focused on the risks associated with outsourced solutions, they also touched on activities delivered by offshore internal delivery centers…
Contributors: Everest Group
Categories: SIG U Resource, Whitepaper
SRC Type: Risk Management, Sourcing Management, Third Party Management