{"id":972,"date":"2023-06-09T17:22:46","date_gmt":"2023-06-09T21:22:46","guid":{"rendered":"https:\/\/blogs.duanemorris.com\/techlaw\/?p=972"},"modified":"2023-06-09T17:22:46","modified_gmt":"2023-06-09T21:22:46","slug":"privacy-laws-banks-fintech-new-u-s-guidance-on-risk-management-for-third-party-relationships","status":"publish","type":"post","link":"https:\/\/blogs.duanemorris.com\/techlaw\/2023\/06\/09\/privacy-laws-banks-fintech-new-u-s-guidance-on-risk-management-for-third-party-relationships\/","title":{"rendered":"Privacy Laws + Banks + FinTech = New U.S. Guidance on Risk Management for Third-Party Relationships"},"content":{"rendered":"<p>Three federal agencies jointly issued a guidance that banks are expected to monitor their financial technology partners to ensure compliance with privacy, fair lending, and anti-money laundering laws.<\/p>\n<p>The \u201cInteragency Guidance on Third-Party: Risk Management\u201d was issued jointly by: (1) Board of the Federal Reserve System [OP-1752], (2) Department of the Treasury Office of the Comptroller of the Currency [OCC-2021-0011], and (3) Federal Deposit Insurance Corporation [RIN 3064-ZA26], with a final guidance date of June 6, 2023 (\u201cGuidance\u201d).\u00a0 The Guidance offers the three U.S. agencies\u2019 views on sound risk management principles for banking organizations when developing and implementing risk management practices for all stages in the life cycle of third-party relationships.<\/p>\n<p><u>Prior guidance is rescinded and replaced by the Guidance <\/u><\/p>\n<p>The Guidance rescinds and replaces the following previously issued guidance by the three federal agencies:<\/p>\n<ul>\n<li><span style=\"text-decoration: underline\">Board\u2019s 2013 guidance<\/span>: SR Letter 13-19\/CA Letter 13-21, \u201cGuidance on Managing Outsourcing Risk\u201d (December 5, 2013, updated February 26, 2021)<\/li>\n<li><span style=\"text-decoration: underline\">FDIC\u2019s 2008 guidance<\/span>:\u00a0 FIL-44-2008, \u201cGuidance for Managing Third-Party Risk\u201d (June 6, 2008)<\/li>\n<li><span style=\"text-decoration: underline\">OCC\u2019s 2013 Guidance and its 2020 frequently asked questions<\/span>: OCC Bulletin 2013-29, \u201cThird-Party Relationships: Risk Management Guidance,\u201d and OCC Bulletin 2020-10, \u201cThird-Party Relationships: Frequently Asked Questions to Supplement OCC Bulletin 2013-29.\u201d Additionally, the OCC also issued foreign-based third-party guidance, OCC Bulletin 2002-16, \u201cBank Use of Foreign-Based Third-Party Service Providers: Risk Management Guidance,\u201d which is not being rescinded but instead supplements the final guidance.<\/li>\n<\/ul>\n<p>The Guidance seeks to establish a consistent approach which puts the onus on banks to obtain information from and ensure compliance from its third-party fintech relationships.\u00a0 In other words, banks are responsible for knowing how their fintech partners: (1) are operating and (2) are complying with applicable federal law.<\/p>\n<p><u>Obligations concerning privacy laws and cross-border flow of information\u00a0 <\/u><\/p>\n<p>The Guidance discusses factors to consider when evaluating whether to enter into a relationship with a third party, including the compliance of privacy laws.\u00a0 Regarding contracts between a bank and a foreign-based third party, the Guidance notes the importance of:<\/p>\n<ul>\n<li>privacy laws<\/li>\n<li>cross-border flow of information<\/li>\n<li>choice-of law and jurisdictional provisions that provide dispute adjudication<\/li>\n<\/ul>\n<p>In sum, the 68-page Guidance sets forth a bank\u2019s risk management obligations when contracting with third-party fintech.\u00a0 As privacy laws and cross-border flow of information continually increase, the Guidance sets forth the criteria to analyze within these contracts.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Three federal agencies jointly issued a guidance that banks are expected to monitor their financial technology partners to ensure compliance with privacy, fair lending, and anti-money laundering laws. The \u201cInteragency Guidance on Third-Party: Risk Management\u201d was issued jointly by: (1) Board of the Federal Reserve System [OP-1752], (2) Department of the Treasury Office of the &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/blogs.duanemorris.com\/techlaw\/2023\/06\/09\/privacy-laws-banks-fintech-new-u-s-guidance-on-risk-management-for-third-party-relationships\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Privacy Laws + Banks + FinTech = New U.S. Guidance on Risk Management for Third-Party Relationships&#8221;<\/span><\/a><\/p>\n","protected":false},"author":265,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"ppma_author":[976],"class_list":["post-972","post","type-post","status-publish","format-standard","hentry","category-infotechtelecom"],"authors":[{"term_id":976,"user_id":265,"is_guest":0,"slug":"srwiggins","display_name":"Sheila Raftery Wiggins","avatar_url":"https:\/\/blogs.duanemorris.com\/techlaw\/wp-content\/uploads\/sites\/17\/2021\/12\/wigginssheila-100x100.jpg","0":null,"1":"","2":"","3":"","4":"","5":"","6":"","7":"","8":""}],"_links":{"self":[{"href":"https:\/\/blogs.duanemorris.com\/techlaw\/wp-json\/wp\/v2\/posts\/972","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.duanemorris.com\/techlaw\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.duanemorris.com\/techlaw\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/techlaw\/wp-json\/wp\/v2\/users\/265"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/techlaw\/wp-json\/wp\/v2\/comments?post=972"}],"version-history":[{"count":0,"href":"https:\/\/blogs.duanemorris.com\/techlaw\/wp-json\/wp\/v2\/posts\/972\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.duanemorris.com\/techlaw\/wp-json\/wp\/v2\/media?parent=972"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/techlaw\/wp-json\/wp\/v2\/categories?post=972"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/techlaw\/wp-json\/wp\/v2\/tags?post=972"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/techlaw\/wp-json\/wp\/v2\/ppma_author?post=972"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}