The question a US bank board ought to be able to answer inside a single meeting — how much of our critical processing runs through one provider, and what happens the morning it stops — is one most boards still cannot.
Most of what is written about third-party risk in US banking is checklist material sold by GRC vendors, and it treats provider concentration as a procurement hygiene issue. It is not. The 2023 interagency guidance, read against the run of stress through the regional-bank sector, moved concentration in cloud and core-banking providers from an IT line item to a risk the board owns and has to be able to evidence. This is a reading of what that shift demands of the technology function, written for the people who have to answer for it.
What the 2023 interagency guidance actually changed
In June 2023 the Office of the Comptroller of the Currency, the Federal Reserve and the FDIC issued their final Interagency Guidance on Third-Party Relationships: Risk Management, replacing the three agencies’ separate and inconsistent guidance with a single principles-based framework. It deliberately declines to set bright-line rules. There is no fixed regulatory definition of a “critical activity” — each bank is expected to determine, for its own operations, what qualifies. And it expects the risk management life cycle to include contingency planning: the guidance asks firms to plan for transitioning an activity in-house or to another provider if the relationship ends.
Free · 4 minutes
Do you know what could take the business down — and have you priced it?
Fourteen questions on concentration, third-party dependence, resilience, and incident readiness — the exposures a board is accountable for whether or not it can see them. Banded finding on screen, full sheet by email.
The word “concentration” is not the headline of the document, but the substance is throughout it — dependency on a single provider, the geography of subcontractors, termination and transition. What changed is where responsibility sits. A board can no longer point to a vendor management policy owned by procurement and treat the matter as closed. If the activity is critical, the board is expected to understand the dependency and the plan for losing it.
Where the concentration actually sits
There are two layers a US bank should look at, and they compound. The first is core processing. A Federal Reserve Bank of Kansas City briefing published in March 2024 put the market structure plainly: Fiserv served around 42% of banks surveyed in 2022, Jack Henry around 21% and FIS around 9%. Collectively the “big three” served more than 70% of the banks surveyed. That is not a competitive market a bank can shop around freely; it is an oligopoly your institution almost certainly already buys from.
The second layer is cloud. A similarly small set of hyperscalers sits underneath the estate — and frequently underneath the core provider itself. A bank can therefore be doubly exposed to the same failure domain without ever having drawn the map: its own workloads and its core processor’s workloads resting on the same cloud region. The 2024 collapse of the banking-as-a-service middleware provider Synapse, which froze customer funds across partner banks and drew a Federal Reserve enforcement action against its partner Evolve Bank & Trust, was a blunt demonstration that concentration is not only about the named vendor on the contract. It is about the chain behind it. Concentration risk hides in the layers a single vendor register never shows.
The questions a board should be asking — the measurable ones
“Do we have a third-party risk policy” is the wrong question, because the answer is always yes and it settles nothing. The questions that actually sort a defensible position from a stated one are measurable:
- Concentration. What share of our critical processing runs through a single provider, and how is that share measured — by volume, by revenue dependency, by number of critical functions touched?
- Substitutability. Is there a genuine alternative provider, and what is the realistic switching time and cost — not the contractual notice period, the actual migration?
- Exit optionality. Can we evidence a tested exit, or do we merely hold a termination clause we have never exercised?
- The chain. What sits beneath our named providers — the same cloud region, the same subcontractor, the same single point of failure two layers down?
These are quantifiable. A firm that can put a number on each of them, and show the working, is in a position it can defend to an examiner and to its own board. A firm that answers in adjectives is not. Quantifying substitutability across the estate is the harder half of the exercise and the one most programmes skip; it is also where the measurement discipline earns its keep.
Why “we have a contract clause” is not an exit plan
The guidance asks for contingency plans to transition a critical activity. A termination-for-convenience clause is not that. Exit optionality that would survive scrutiny means several concrete things at once: the data held in a portable, documented form rather than locked in a proprietary schema; a written runbook for standing up an alternative; and a demonstrated ability to do so within the recovery window the board has actually accepted, not the one the vendor’s marketing implies. Most banks hold the clause and have none of the rest. An untested exit is a plan on paper and an outage in practice — which is the gap between a clause and a capability.
What the US does not have, and why the board carries more
It is worth being clear about the regulatory backdrop, because it shapes where the burden falls. The United Kingdom has built a Critical Third Parties regime that lets regulators place requirements directly on designated providers. The EU’s Digital Operational Resilience Act created an oversight framework for critical ICT third-party providers, reaching the hyperscalers themselves. The United States has the Bank Service Company Act, which gives the agencies authority to examine technology service providers through the FFIEC — but it has no designated-critical-provider regime sitting directly on top of AWS or Fiserv in the way the DORA and CTP regimes now do in Europe.
The practical consequence for a US board is that there is no supervisory backstop standing between the bank and the concentration. No regulator is stress-testing the resilience of your core provider on your behalf. The resilience obligation rests with the institution, and the 2023 guidance makes the board the owner of it. That is a heavier position than European boards occupy, not a lighter one.
Provider concentration is a measured risk the board owns, not an IT detail the board is briefed on. The provider will not fail on a schedule that suits your board calendar. Measure the concentration now, with numbers you can defend, or discover it the morning the processing stops.
Free interactive tool
Website compliance checklist
What your site has to do, based on what it actually does
Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.
Everything that applies
Ordered by what to do first: legal requirements you can close quickly, then larger pieces of work, then what is expected rather than required. Not exhaustive, and not a legal audit.
Dated PDF, yours to keep or circulate.
Free interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.
Most technology problems are not technology problems. They are control problems.
The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming