THIRD PARTYCURRENT
Regulation & Standards · Primary-source analysis

Federal Reserve guide makes information gaps a risk decision

The community-bank guide says unavailable due-diligence evidence should lead to alternative information, controls, or monitoring—not an unexplained pass or a silent stop in the review.

Third Party Current editorial graphic. Source material: Federal Reserve — Third-Party Risk Management: A Guide for Community Banks; analysis and presentation by Third Party Current.

Missing evidence needs a disposition

The direct answer in the Federal Reserve's community-bank guide is not that every unavailable document blocks a relationship or that every missing answer can be waived. The guide says a bank may consider alternative information, controls, or monitoring when it cannot obtain desired due-diligence information. That turns the gap into a recorded risk decision: what was requested, why it mattered, what was unavailable, what other evidence was considered, what uncertainty remains, and who accepted any conditions.

A third-party workflow should therefore distinguish an unanswered request from a negative finding, a guarded source, an expired artifact, a management exception, and a completed review. Collapsing each state into incomplete makes escalation difficult; converting each into acceptable hides uncertainty. The retained record should connect the gap to the activity, risk assessment, reviewer, compensating control, monitoring frequency, contract term, approval, and trigger for reopening the decision.

The activity sets the diligence boundary

The guide defines due diligence around a particular third party's ability to perform the proposed activity as expected. It also illustrates that an established provider can require new review when the bank adds a service outside the current contract. Familiarity with the legal vendor does not answer questions about a new product, integration, data flow, customer interaction, implementation plan, subcontractor, or service obligation.

The useful risk object is consequently more specific than a vendor profile. A platform should connect the legal entity to the proposed activity, product or service, contract, systems, information, customer population, locations, downstream dependencies, accountable bank owners, and planned controls. Existing evidence may be reused only where its source, scope, date, and subject still match. The workflow should show the reuse decision instead of copying an old conclusion into the new record.

Risk determines rigor without becoming a score

The guide says not all relationships present the same risk and describes more comprehensive and rigorous oversight for relationships supporting higher-risk or critical activities. It identifies possible criticality signals such as significant loss if expectations are not met, significant customer impact, or significant effect on operations or financial condition. These are planning and governance inputs, not a universal numeric threshold supplied by the guide.

A defensible implementation preserves the factors, evidence, methodology version, responsible reviewers, and resulting treatment. Higher rigor may change the required expertise, evidence depth, contract provisions, monitoring, testing, contingency planning, issue escalation, or board reporting. The system should also allow the assessment to change as the activity, provider, data access, reliance, performance, or environment changes rather than treating onboarding criticality as permanent.

The guide is supervisory guidance, not a product certificate

The Federal Reserve says the guide does not impose new requirements, create a safe harbor, or replace the interagency guidance. It offers considerations, examples, and potential information sources across the relationship life cycle. A provider can map a workflow to those considerations, but the mapping does not establish that a bank's program is effective or that a regulator has approved the product.

Buyers should test a representative high-risk activity with incomplete evidence. The demonstration should show the original request, alternate source, evidence limit, control owner, contract condition, residual uncertainty, approval, monitoring event, escalation, and exportable history. This analysis reports the guide's operating boundary; it does not determine whether any bank, relationship, control, or oversight approach is safe, sound, compliant, or sufficient.

What we will watch next

Third Party Current will watch for later primary-source evidence that changes the maintained company, capability, or standards record. The next useful evidence may include implementation documentation, release details, regulator findings, corrected methods, product packaging, customer-observable workflow, or a subsequent company statement. Until then, the dated source and its stated boundary remain attached to this analysis.

Primary source: Federal Reserve — Third-Party Risk Management: A Guide for Community Banks · Official supervisory guide.

Source boundary: This article independently analyzes the Federal Reserve's May 2024 community-bank guide. It is not legal, banking, supervisory, compliance, risk, procurement, or technology advice and does not determine the adequacy of any third-party relationship or risk-management program.

Editorial record: Published July 29, 2026; last reviewed July 29, 2026. Corrections policy.