Regulators Propose Risk-Based Vendor Oversight For Community Lenders
Plan could ease reviews of lower-risk mortgage technology while preserving lender responsibility for vendor failures
Federal regulators are proposing a revised approach to third-party oversight that could reduce process-heavy vendor reviews for community banks and credit unions, including those operating mortgage businesses.
The proposal is not mortgage-specific, but it would apply to the mortgage operations of federally supervised banks and credit unions that rely on outside technology and service providers.
The Federal Reserve, Federal Deposit Insurance Corp., Office of the Comptroller of the Currency, and National Credit Union Administration proposed directing institutions to tailor their oversight to the risks presented by each third-party relationship.
For mortgage lenders, that could mean reviewing a limited-use software provider differently from a loan-origination system, income-verification tool, automated underwriting platform, or servicer that handles borrower data, credit decisions, or payments.
The agencies said the proposed framework would help institutions focus their resources on relationships presenting the greatest potential harm while avoiding “overly process-driven strategies” that treat every third party as inherently high risk.
If finalized, the proposal would replace the third-party-risk guidance issued by the OCC, Fed, and FDIC in 2023 and establish a common framework that also includes the NCUA.
The proposal would be nonbinding. The OCC said failure to follow the guidance would not, by itself, result in supervisory action.
What It Could Mean For Mortgage Operations
Banks and credit unions use third parties throughout the mortgage process, including for applications, pricing, credit reports, income and employment verification, appraisals, closing services, document preparation, and servicing.
The 2023 guidance already called for a flexible, risk-based approach. The new proposal would further emphasize tailoring and discourage institutions from applying broadly uniform processes to vendors with different levels of risk.
If examiners apply the framework as intended, community lenders could spend less time documenting lower-risk relationships and concentrate their resources on vendors handling borrower data, credit decisions, payments, or critical operations.
The agencies would consider an institution’s size, complexity, and risk profile, along with the nature of each third-party relationship.
The framework would not relieve a lender of responsibility for consumer harm, legal violations, data breaches, or operational failures involving its vendors. Existing fair-lending, privacy, information-security, and consumer-protection requirements would continue to apply.
Independent mortgage banks are not directly supervised by the four agencies and are not the proposal’s primary audience. They could still experience indirect effects through warehouse banks, depository partners, service providers, and increased technology competition from banks and credit unions.
Regulators Address Core-Provider Leverage
The Fed, FDIC, and OCC also issued a separate statement addressing community banks’ relationships with core service providers. The NCUA did not join that statement.
The three banking regulators acknowledged that community institutions may struggle to obtain information from core providers, monitor their performance, negotiate contract protections, or replace critical systems.
Those limitations can be significant in mortgage lending, where changing a core banking, loan-origination, or servicing platform can be costly and disruptive. Smaller lenders may also lack the leverage to secure audit rights, data access, liability protections, and favorable termination provisions.
Regulators said they would consider those circumstances when determining the appropriate level of supervisory oversight. They also retained their authority to act when a core provider causes a community bank to engage in unsafe or unsound practices or violate the law.
The statement could shift some supervisory attention toward a core provider’s conduct when a community bank lacks the leverage or information needed to control the resulting risk.
Barr Warns Of Compliance Gaps
The proposal did not receive unanimous support at the Federal Reserve.
Fed Gov. Michael Barr dissented, warning that the proposal could create confusion and leave gaps in supervisory coverage.
Barr objected to its use of a “material financial risk” standard, arguing that it could make supervisors less likely to require corrective action before a vendor problem becomes serious.
He also raised concerns about the proposals’ exclusion of consumer-compliance matters. Barr said the approach could leave banks without clear guidance or require them to operate under overlapping frameworks.
That concern has direct implications for mortgage vendors whose products affect underwriting, fair lending, disclosures, privacy, servicing communications, and loss mitigation.
Barr also noted that a separate guide proposed for traditional community banks would not cover institutions with complex business models or third-party profiles, including complex bank-fintech partnerships.
Fed Gov. Lisa Cook supported reconsidering the existing framework but called for public feedback on whether regulators should provide greater detail about cybersecurity, consumer protection, record management, and anti-money-laundering responsibilities in bank-fintech relationships.
The agencies released the proposal and supporting documents Sept. 11. Comments will be due 60 days after publication in the Federal Register. A fixed deadline had not been posted as of Sept. 14.
For community mortgage lenders, the proposal could reduce unnecessary vendor-review work. It would not change their underlying responsibility to understand what their technology does, monitor the risks it creates, and protect borrowers when problems occur.