# Bank Third-Party Risk Management: What Do the Interagency Expectations Mean for a Law Firm Being Supervised?

> What the June 2023 Interagency Guidance (88 FR 37920) and CFPB Bulletin 2016-02 mean for a collections law firm under bank vendor oversight, and their limits.

- Source: https://ottoforfirms.com/compliance/vendor-oversight-tprm/
- Publisher: Otto — https://ottoforfirms.com
- Updated: 2026-07-26
- Status: in attorney review. Served noindex and excluded from the sitemap; do not cite as settled.

**In legal review — not indexed.** These explainers are drafted and readable, and stay out of search until an attorney has cleared each one. Anything still to be checked is marked inline.

[All explainers](https://ottoforfirms.com/compliance/)

The June 2023 Interagency Guidance binds the banking organization, not the law firm, and states it "does not have the force and effect of law." It directs the bank through a five-stage lifecycle: planning, due diligence, contract negotiation, ongoing monitoring, termination. The firm experiences it as contract terms and monitoring. Direct examination authority exists but has statutory limits.

## Key facts

- The Interagency Guidance on Third-Party Relationships: Risk Management, 88 FR 37920 (June 9, 2023), rescinded and replaced OCC Bulletins 2013-29 and 2020-10, SR Letter 13-19/CA Letter 13-21, and FDIC FIL-44-2008.
- The guidance states in footnote 2 that "Supervisory guidance does not have the force and effect of law and does not impose any new requirements on banking organizations."
- The guidance covers "any business arrangement between a banking organization and another entity, by contract or otherwise," and says a relationship may exist without a contract or remuneration.
- 12 U.S.C. 1867(c)(1) subjects services a depository institution "causes to be performed for itself" to examination as if performed in-house; subsection (c) reaches only "services authorized under this chapter."
- 12 U.S.C. 5517(e)(1) bars CFPB supervision or enforcement over an attorney's activity that is part of "the practice of law," subject to carve-outs in 5517(e)(2) and (e)(3).
- CFPB Bulletin 2016-02 was not among the 67 guidance documents withdrawn on May 12, 2025 (90 FR 20084), although the adjacent Bulletin 2016-03 was.

## Does the 2023 Interagency Guidance apply directly to a collections law firm?

No. The Interagency Guidance on Third-Party Relationships: Risk Management, published at 88 FR 37920 on June 9, 2023 by the Federal Reserve, FDIC, and OCC and final as of June 6, 2023, is supervisory guidance addressed to banking organizations. It tells a bank how to manage the risks of its third-party relationships; it does not by its own force impose obligations on the third party. A creditor-side collections law firm therefore does not "comply with" the guidance. What the firm experiences is the guidance operating through the bank: due diligence questionnaires before engagement, contract clauses the bank's vendor management function will not waive, periodic reporting and control testing during the relationship, and defined termination and data-return obligations at the end. As of July 2026 the guidance had rescinded and replaced four predecessor issuances — OCC Bulletin 2013-29, OCC Bulletin 2020-10 (the OCC FAQs), Federal Reserve SR Letter 13-19/CA Letter 13-21, and FDIC FIL-44-2008 — so a bank client's questionnaire still citing those documents is running on a rescinded framework. OCC Bulletin 2002-16, on foreign-based third-party service providers, was expressly not rescinded and instead supplements the final guidance. One caution about scope: the guidance never uses the words "law firm," "attorney engagement," or "legal services." Its application to a collections firm is an inference from its deliberately broad terms, not something the agencies spelled out.

## Does the interagency third-party risk management guidance have the force of law?

No, and the agencies say so twice in the document itself. Footnote 2 of the Interagency Guidance on Third-Party Relationships: Risk Management states: "Supervisory guidance does not have the force and effect of law and does not impose any new requirements on banking organizations." Responding to commenters who wanted mandatory minimum standards, the agencies repeated the point: "[T]he agencies underscore that supervisory guidance does not have the force and effect of law and does not impose any new requirements on banking organizations." The guidance describes itself as offering "key principles banking organizations can leverage." This matters in two directions for a collections law firm. It means no examiner can cite the firm for violating the guidance, and it means the firm's actual obligations come from its executed contract with the bank, not from the guidance text. It also means a bank cannot accurately tell a firm that "the regulators require" a particular clause — what the guidance does is describe provisions banks commonly seek. Separately, banking organizations remain required to operate in a safe and sound manner and in compliance with applicable laws and regulations whether an activity is performed internally or through a third party; that underlying obligation is statutory and regulatory, and it is what gives the non-binding guidance its practical force.

## What counts as a third-party relationship under the interagency guidance?

The definition is deliberately wide. The Interagency Guidance on Third-Party Relationships: Risk Management states that it "addresses any business arrangement between a banking organization and another entity, by contract or otherwise," and adds in footnote 6 that "[t]he term 'business arrangement' is meant to be interpreted broadly and is synonymous with the term 'third-party relationship.'" It also states that "[a] third-party relationship may exist despite a lack of a contract or remuneration," and that such relationships "can include, but are not limited to, outsourced services, use of independent consultants, referral arrangements, merchant payment processing services, services provided by affiliates and subsidiaries, and joint ventures." The agencies rejected comments urging them to narrow the term, and removed proposed language that would have excluded customer relationships, "intended to reduce ambiguity." For a collections law firm, this means outside counsel engagements, contingency-fee placement arrangements, and referral relationships all fall inside the perimeter, and so do the firm's own subcontractors to the extent the bank's oversight reaches them. The breadth cuts the other way too: the agencies stated that "the guidance does not suggest that all relationships require the same level or type of oversight or risk management, since different relationships present varying levels of risk."

## Does a collections law firm count as a "critical activity" for its bank client?

That depends on the bank, and the Interagency Guidance on Third-Party Relationships: Risk Management says so explicitly. The guidance identifies characteristics of critical activities as those that could "[c]ause a banking organization to face significant risk if the third party fails to meet expectations," "[h]ave significant customer impacts," or "[h]ave a significant impact on a banking organization's financial condition or operations." It then states: "It is up to each banking organization to identify its critical activities and third-party relationships that support these critical activities. Notably, an activity that is critical for one banking organization may not be critical for another." The guidance also notes that "[s]ome banking organizations may assign a criticality or risk level to each third-party relationship, whereas others identify critical activities and those third parties that support such activities." Litigation and post-charge-off collections touching a large consumer portfolio may well be classified as high-risk on the customer-impact prong even where the dollar volume is small, but a firm cannot determine its own classification and the guidance supplies no test that would let it. The classification drives everything downstream: the guidance provides that "banking organizations engage in more comprehensive and rigorous oversight and management of third-party relationships that support higher-risk activities, including critical activities."

## What will a bank's due diligence ask a collections firm to produce?

The Interagency Guidance on Third-Party Relationships: Risk Management sets out fourteen due diligence topics, lettered a through n, for a banking organization to consider before selecting a third party: strategies and goals; legal and regulatory compliance; financial condition; business experience; qualifications and backgrounds of key personnel and other human resources considerations; risk management; information security; management of information systems; operational resilience; incident reporting and management processes; physical security; reliance on subcontractors; insurance coverage; and contractual arrangements with other parties. The guidance states that due diligence "includes assessing the third party's ability to: perform the activity as expected, adhere to a banking organization's policies related to the activity, comply with all applicable laws and regulations, and conduct the activity in a safe and sound manner," and that its scope "should be commensurate with the level of risk and complexity of the third-party relationship." Notably for firms with long-standing bank relationships, the guidance states that "[r]elying solely on experience with or prior knowledge of a third party is not an adequate proxy for performing appropriate due diligence, as due diligence should be tailored to the specific activity to be performed." A twenty-year relationship does not, under the guidance, exempt a new engagement from a fresh assessment.

## Which contract provisions should a collections firm expect a bank to insist on?

The Interagency Guidance on Third-Party Relationships: Risk Management walks through fifteen contract considerations, lettered a through o, and several are effectively non-negotiable in bank vendor paper. On compliance, it states that "it is important for a contract to specify the obligations of the third party and the banking organization to comply with applicable laws and regulations" and to "provide the banking organization with the right to monitor and be informed about the third party's compliance with applicable laws and regulations, and to require timely remediation if issues arise." On confidentiality, effective contracts "typically prohibit the use and disclosure of banking organization and customer information by a third party and its subcontractors, except as necessary to provide the contracted activities or comply with legal requirements," and specify "when and how the third party will disclose, in a timely manner, information security breaches or unauthorized intrusions." On resilience, contracts often require the third party to supply operating procedures "including specific recovery time and recovery point objectives." On termination, the guidance lists provisions that "[p]rovide for the timely return or destruction of the banking organization's data, information, and other resources" and that "[e]nable the banking organization to terminate the relationship with reasonable notice and without penalty, if formally directed by the banking organization's primary federal banking regulator." That last provision means a bank's regulator can effectively end the engagement without the firm having breached anything. Because the guidance is non-binding, these are provisions banks commonly seek, not terms any bank is required to obtain.

## Can a bank restrict a collections firm's use of subcontractors?

Yes, and the Interagency Guidance on Third-Party Relationships: Risk Management expects it to consider doing so. The guidance treats subcontracting as its own due diligence topic and its own contract consideration. On due diligence, it states that "[a]n evaluation of the volume and types of subcontracted activities and the degree to which the third party relies on subcontractors helps inform whether such subcontracting arrangements pose additional or heightened risk to a banking organization," and directs attention to "how the third party selects and oversees its subcontractors and ensures that its subcontractors implement effective controls," as well as to the "geographic location of a subcontractor or dependency on a single provider for multiple activities." On contracting, it contemplates addressing "when and how the third party should notify the banking organization of its use or intent to use a subcontractor and whether specific subcontractors are prohibited"; whether the contract "should prohibit assignment, transfer, or subcontracting of the third party's obligations to another entity without the banking organization's consent"; "reporting on the subcontractor's conformance with performance measures, periodic audit results, and compliance with laws and regulations"; and the third party's liability for its subcontractors' actions. It also contemplates reserving "the right to terminate the contract without penalty if the third party's subcontracting arrangements do not comply with contractual obligations." For a collections firm, the practical reach is to local counsel networks, process servers, skip-trace and data vendors, print and mail, dialer and telephony providers, payment processors, and any offshore support.

## What ongoing monitoring will a bank perform after a collections engagement starts?

The Interagency Guidance on Third-Party Relationships: Risk Management describes ongoing monitoring as enabling the bank to "(1) confirm the quality and sustainability of a third party's controls and ability to meet contractual obligations; (2) escalate significant issues or concerns, such as material or repeat audit findings, deterioration in financial condition, security breaches, data loss, service interruptions, compliance lapses, or other indicators of increased risk; and (3) respond to such significant issues or concerns when identified." Typical activities are "(1) review of reports regarding the third party's performance and the effectiveness of its controls; (2) periodic visits and meetings with third-party representatives to discuss performance and operational issues; and (3) regular testing of the banking organization's controls that manage risks from its third-party relationships." The guidance adds that "[i]n certain circumstances, based on risk, a banking organization may also perform direct testing of the third party's own controls." For a collections firm this translates into recurring complaint and dispute reporting, call monitoring or scorecard results, exception and error reporting, incident notification, and periodic onsite or virtual assessments — with frequency scaled to the criticality designation the bank assigned. What a given bank actually performs is set by the contract, not by the guidance.

## Can a banking regulator examine a collections law firm directly, not just the bank?

Potentially, but the authority has a statutory limit the guidance does not discuss. Under the Bank Service Company Act, 12 U.S.C. 1867(c) provides that where a depository institution "causes to be performed for itself, by contract or otherwise, any services authorized under this chapter, whether on or off its premises," then under (c)(1) "such performance shall be subject to regulation and examination by such agency to the same extent as if such services were being performed by the depository institution itself on its own premises," and under (c)(2) the institution "shall notify each such agency of the existence of the service relationship within thirty days after the making of such service contract or the performance of the service, whichever occurs first." The limiting phrase is "services authorized under this chapter": chapter 18 defines permissible bank service company activities by reference to what the depository institution shareholder or member is itself authorized to perform (12 U.S.C. 1864), and neither that section nor 12 U.S.C. 1861 enumerates legal representation. Whether a law firm's litigation services fall within the phrase is not resolved by the statutory text, and no source reviewed here resolves it. Separately, the Interagency Guidance states more generally that "[w]hen circumstances warrant, an agency may use its legal authority to examine functions or operations that a third party performs on a banking organization's behalf," and that such examinations "may evaluate the third party's ability to fulfill its obligations in a safe and sound manner and comply with applicable laws and regulations, including those designed to protect customers and to provide fair access to financial services." It does not identify which legal authority, and it adds that "[t]he agencies may pursue corrective measures, including enforcement actions."

## Does the practice-of-law exclusion shield a collections law firm from CFPB supervision?

Only partly, and the boundary is the single most consequential open question for a collections firm. Section 1027(e) of the Dodd-Frank Act, 12 U.S.C. 5517(e)(1), provides that "[e]xcept as provided under paragraph (2), the Bureau may not exercise any supervisory or enforcement authority with respect to an activity engaged in by an attorney as part of the practice of law under the laws of a State in which the attorney is licensed to practice law." Two carve-outs follow. Paragraph (2) preserves Bureau authority over a consumer financial product or service "that is not offered or provided as part of, or incidental to, the practice of law, occurring exclusively within the scope of the attorney-client relationship," or that is provided "with respect to any consumer who is not receiving legal advice or services from the attorney in connection with such financial product or service." Paragraph (3) provides that the exclusion "shall not be construed so as to limit the authority of the Bureau with respect to any attorney, to the extent that such attorney is otherwise subject to any of the enumerated consumer laws or the authorities transferred under subtitle F or H." Because the Fair Debt Collection Practices Act is an enumerated consumer law, paragraph (3) is where most of the argument sits for a collections firm. As of July 2026, how paragraphs (1) and (3) interact for a licensed attorney conducting collections litigation is a question of law that turns on the specific activity and requires case-law analysis this page does not supply. CFPB Bulletin 2016-02 does not mention the exclusion.

## What does CFPB Bulletin 2016-02 add beyond the banking agencies' third-party guidance?

CFPB Compliance Bulletin and Policy Guidance 2016-02, Service Providers, published at 81 FR 74410 and stating that the Bureau released it on its website on October 31, 2016, reissues and amends CFPB Bulletin 2012-03 and addresses the same relationships from the consumer-protection side. It defines a service provider by reference to section 1002(26) of the Dodd-Frank Act as "any person that provides a material service to a covered person in connection with the offering or provision by such covered person of a consumer financial product or service" (12 U.S.C. 5481(26)). It states that "the mere fact that a supervised bank or nonbank enters into a business relationship with a service provider does not absolve the supervised bank or nonbank of responsibility for complying with Federal consumer financial law to avoid consumer harm," and that "[d]epending on the circumstances, legal responsibility may lie with the supervised bank or nonbank as well as with the supervised service provider." It enumerates five steps, introduced as ones that "should include, but are not limited to": conducting thorough due diligence to verify the service provider understands and can comply with Federal consumer financial law; requesting and reviewing the provider's policies, procedures, internal controls, and training materials; including clear contractual compliance expectations "as well as appropriate and enforceable consequences for violating any compliance-related responsibilities, including engaging in unfair, deceptive, or abusive acts or practices"; establishing internal controls and on-going monitoring; and "[t]aking prompt action to address fully any problems identified through the monitoring process, including terminating the relationship where appropriate." The bulletin describes itself as "a non-binding general statement of policy articulating considerations relevant to the Bureau's exercise of its supervisory and enforcement authority," exempt from notice and comment under 5 U.S.C. 553(b). As of July 2026 it remains published and was not among the 67 documents withdrawn at 90 FR 20084 on May 12, 2025 — notably, the adjacent Bulletin 2016-03 was withdrawn and Bulletin 2012-03 was not listed either.

## Does a SOC 2 report or a certification satisfy a bank's third-party risk expectations?

Nothing in either the interagency guidance or CFPB Bulletin 2016-02 treats any artifact as sufficient on its own, and both say the opposite about where responsibility ends up. The Interagency Guidance on Third-Party Relationships: Risk Management permits banks to "refer to conformity assessments or certifications" and to "engage external resources" when performing ongoing monitoring, but frames these as ways "[t]o gain efficiencies or leverage specialized expertise" within a monitoring program the bank still owns; it adds that a banking organization engaging an external party to supplement due diligence has itself established a business arrangement covered by its own third-party risk processes. CFPB Bulletin 2016-02 states flatly that "due diligence does not provide a shield against liability for actions by the service provider," describing it instead as something that "could help reduce the risk that the service provider will commit violations for which the supervised bank or nonbank may be liable." The interagency guidance also contemplates that a bank may be unable to obtain what it wants — a third party "may not allow on-site visits, or may not share (or be permitted to share) information that a banking organization requests" — and treats that as a risk the bank must weigh, not a gap a certificate closes. For a collections firm, a SOC 2 Type II report, an ISO certificate, or a completed standardized questionnaire is evidence a bank can use; it is not a substitute for producing underlying reports, remediating findings, and permitting the monitoring the contract provides for. No software product can make a firm satisfy a bank's third-party risk program, because the determinations that matter — criticality, adequacy of controls, whether a finding was remediated — are made by the bank and its examiners.

## Primary sources

1. [Interagency Guidance on Third-Party Relationships: Risk Management, 88 FR 37920 (June 9, 2023) (Federal Reserve, FDIC, OCC)](https://www.federalregister.gov/documents/2023/06/09/2023-12340/interagency-guidance-on-third-party-relationships-risk-management)
   > This guidance addresses any business arrangement between a banking organization and another entity, by contract or otherwise. A third-party relationship may exist despite a lack of a contract or remuneration.
1. [Interagency Guidance, 88 FR 37920, footnote 2 (statement of legal effect)](https://www.federalregister.gov/documents/2023/06/09/2023-12340/interagency-guidance-on-third-party-relationships-risk-management)
   > Supervisory guidance does not have the force and effect of law and does not impose any new requirements on banking organizations.
1. [CFPB Compliance Bulletin and Policy Guidance; 2016-02, Service Providers, 81 FR 74410 (Oct. 26, 2016)](https://www.federalregister.gov/documents/2016/10/26/2016-25856/compliance-bulletin-and-policy-guidance-2016-02-service-providers)
   > the mere fact that a supervised bank or nonbank enters into a business relationship with a service provider does not absolve the supervised bank or nonbank of responsibility for complying with Federal consumer financial law to avoid consumer harm
1. [CFPB Compliance Bulletin and Policy Guidance 2016-02, Service Providers (Bureau PDF)](https://files.consumerfinance.gov/f/documents/102016_cfpb_OfficialGuidanceServiceProviderBulletin.pdf)
   > This Compliance Bulletin and Policy Guidance is a non-binding general statement of policy articulating considerations relevant to the Bureau's exercise of its supervisory and enforcement authority.
1. [12 U.S.C. § 1867(c) (Bank Service Company Act), Cornell LII](https://www.law.cornell.edu/uscode/text/12/1867)
   > such performance shall be subject to regulation and examination by such agency to the same extent as if such services were being performed by the depository institution itself on its own premises
1. [12 U.S.C. § 5517(e) (Dodd-Frank § 1027(e)), exclusion for practice of law, Cornell LII](https://www.law.cornell.edu/uscode/text/12/5517)
   > the Bureau may not exercise any supervisory or enforcement authority with respect to an activity engaged in by an attorney as part of the practice of law under the laws of a State in which the attorney is licensed to practice law
1. [12 U.S.C. § 1864 (permissible bank service company activities), Office of the Law Revision Counsel](https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title12-section1864&num=0&edition=prelim)
   > A bank service company may provide to any person any service authorized by this section, except that a bank service company shall not take deposits.
1. [CFPB, Interpretive Rules, Policy Statements, and Advisory Opinions; Withdrawal, 90 FR 20084 (May 12, 2025)](https://www.federalregister.gov/d/2025-08286)
1. [OCC Bulletin 2023-17, Third-Party Relationships: Interagency Guidance on Risk Management (rescissions list)](https://www.occ.gov/news-issuances/bulletins/2023/bulletin-2023-17.html)
   > This bulletin rescinds OCC Bulletin 2013-29 ... OCC Bulletin 2020-10
1. [CFPB, Compliance Bulletin and Policy Guidance; 2016-02, Service Providers (Bureau landing page)](https://www.consumerfinance.gov/compliance/supervisory-guidance/compliance-bulletin-and-policy-guidance-2016-02-service-providers/)

---

This is an informational reference, not legal advice, and using it creates no attorney-client relationship. Limitations periods turn on facts this page cannot know — which state's law governs, the contract type, when the claim accrued, and whether anything tolled or revived it. Confirm against the primary source and your own counsel before acting.
