In legal review — not indexed
These definitions are drafted and readable, and stay out of search until an attorney has cleared each one.
TPRM
TPRM — TPRM, or third-party risk management, is the bank discipline of identifying and managing the risks arising from business arrangements with outside parties — including the law firms and agencies to which it places collections work — across the full life cycle of the relationship.
The governing document is the Interagency Guidance on Third-Party Relationships: Risk Management, issued June 6, 2023 by the Federal Reserve, FDIC, and OCC and published at 88 Fed. Reg. 37920 (June 9, 2023); it rescinded OCC Bulletin 2013-29 and OCC Bulletin 2020-10. Its scope is deliberately broad: it "addresses any business arrangement between a banking organization and another entity, by contract or otherwise," and "a third-party relationship may exist despite a lack of a contract or remuneration." The life cycle it prescribes runs planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination, with a governance layer of oversight and accountability, independent reviews, and documentation and reporting. Guidance is not law and imposes no new requirements, but it is the template examiners use, and it is why firms receive questionnaires, testing requests, and sampling demands from bank clients rather than from the CFPB directly.
Primary sources
See also
- ExaminationAn examination is a supervisory review conducted by a prudential regulator or the CFPB to assess compliance with federal consumer financial law, obtain information about an entity's activities and compliance systems, and detect risks to consumers and markets.
- SamplingSampling is the selection of a subset of accounts, calls, letters, or files for transaction testing, sized and structured to support a conclusion about the compliance of the whole population.
- AttestationAn attestation is a formal assertion about the design or operation of controls — either a management certification or an independent practitioner's report such as a SOC report — relied on by a bank in lieu of, or alongside, its own testing of a third party.
- Consent orderA consent order is a negotiated administrative order in which a respondent agrees, without necessarily admitting the findings, to conduct requirements, compliance obligations, and monetary relief enforceable by the issuing agency.
This is an informational reference, not legal advice, and using it creates no attorney-client relationship. Limitations periods turn on facts this page cannot know — which state's law governs, the contract type, when the claim accrued, and whether anything tolled or revived it. Confirm against the primary source and your own counsel before acting.