BLOG

Third-Party and Fintech Risk: What US and Canadian Regulators Now Require

Third-party and fintech risk oversight for banks under OSFI B-10, US Interagency Guidance, and NYDFS Part 500

By David Chernitzky, CEO, Armour Cybersecurity  ·  Serving Toronto and organizations across North America  ·  Last updated August 25, 2026

Key Takeaways

  • OSFI Guideline B-10 (effective May 1, 2024) requires documented due diligence, ongoing monitoring, and exit planning for third-party and technology service provider arrangements at federally regulated Canadian institutions. It works alongside B-13, which governs the institution’s own technology and cyber risk.
  • The 2023 US Interagency Guidance on Third-Party Relationships (OCC/FDIC/Federal Reserve) significantly raised expectations for how banks manage the full vendor lifecycle.
  • NYDFS Part 500 requires covered entities to assess the cybersecurity practices of third parties who access nonpublic information and to include specific contractual security provisions.
  • API integrations with fintech partners create data and operational risk that contractual provisions alone cannot address. Technical security controls at the integration level are required.
  • Concentration risk, where multiple institutions depend on the same technology service providers, is an explicit concern of OSFI B-10 and US regulators and requires dedicated management.

Why Regulators Are Focused on Third-Party Risk

Banking regulators on both sides of the border have elevated third-party risk management because the risk has elevated. The accelerating adoption of cloud services, fintech partnerships, and API-based open banking architecture means that most financial institutions now depend on a complex web of external providers for core functions. The security of those providers, and the security of the connections between them and the institution, is no longer a secondary concern.

High-profile supply chain attacks have demonstrated that sophisticated threat actors deliberately target vendors that serve multiple financial institutions simultaneously. A single compromise of a widely-used core banking platform, payment processor, or cloud infrastructure provider can reach dozens of institutions through their vendor relationships, bypassing individually strong perimeter controls. Regulators have responded by requiring institutions to actively manage this exposure rather than simply contracting for it.

The result is a regulatory environment where third-party risk management has moved from a legal and procurement function to a cybersecurity and operational risk function, with examiner scrutiny to match.

OSFI B-10: Canadian Requirements for Third-Party Oversight

In Canada, third-party and technology service provider risk is governed by OSFI Guideline B-10, Third-Party Risk Management, effective May 1, 2024. B-10 is the companion to Guideline B-13, which governs its own technology and cyber risk inside the institution; together they cover the FRFI’s own environment and the risk introduced by the parties it relies on. B-10 expects federally regulated financial institutions to take a risk-and-criticality-based approach to managing all arrangements where a third party provides services or handles data on the institution’s behalf, with oversight proportionate to the criticality and sensitivity of each relationship.

Before entering any new vendor or fintech arrangement, B-10 expects documented due diligence covering the provider’s financial strength, operational resilience, security and cyber risk controls, subcontractor relationships, business continuity plans, and incident response capabilities. The due diligence must be documented and reflected in the contractual relationship, including provisions for audit rights, security standards, breach notification timelines, and data handling requirements for higher-risk and critical arrangements.

During the relationship, B-10 requires ongoing monitoring proportionate to the risk and criticality of the arrangement. Annual security questionnaire updates, review of vendor SOC 2 or equivalent audit reports, and monitoring of vendor security disclosures are minimum expectations for higher-risk relationships. The monitoring must be documented. A completed questionnaire filed at onboarding and never revisited does not satisfy B-10’s ongoing oversight expectations.

B-10 also addresses concentration risk explicitly, expecting institutions to assess it across multiple dimensions, including geography, supplier, and subcontractor, and to identify situations where reliance on a small number of providers creates systemic exposure. Where concentration risk is identified, institutions are expected to assess the resilience implications and maintain contingency plans that do not assume the concentrated provider remains continuously available and secure. B-10 further expects institutions to maintain ongoing visibility into their providers’ use of subcontractors, extending oversight to fourth-party risk.

The 2023 US Interagency Guidance on Third-Party Relationships

In June 2023, the OCC, FDIC, and Federal Reserve Board issued joint guidance on third-party risk management that replaced and significantly updated earlier guidance from each agency. The guidance applies to all bank-third party relationships and establishes lifecycle-based expectations that closely parallel OSFI B-10’s approach.

The planning phase requires banks to assess the risks of a proposed third-party relationship before entering into it, considering the nature of the activities, the sensitivity of data involved, the operational criticality of the service, and the provider’s risk profile. The guidance explicitly calls for boards and senior management to be engaged in oversight of higher-risk third-party relationships.

Due diligence requirements cover the third party’s financial condition, business experience, qualifications, risk management practices, information security programme, operational resilience, and incident response capabilities. For fintech partners and technology service providers specifically, the guidance expects assessment of the provider’s cybersecurity controls and their applicability to the specific services being provided.

Ongoing monitoring is where the 2023 guidance goes beyond what many institutions currently practice. The guidance requires regular review of the third party’s financial condition, monitoring of performance and risk management, and review of audit reports, incident notifications, and regulatory examination findings. For higher-risk relationships, periodic on-site visits or independent security assessments may be appropriate.

The guidance also addresses sub-contractor and fourth-party risk, requiring banks to understand and manage the risks arising when their vendors use their own sub-contractors to deliver services. A fintech partner that routes data through its own cloud infrastructure providers creates a chain of dependency that the bank must understand and assess.

NYDFS Part 500: Third-Party Requirements for New York-Licensed Institutions

NYDFS Part 500 requires covered entities to assess the cybersecurity practices of third parties that have access to their systems or nonpublic information, implement policies governing third-party access to systems and data, and include specific cybersecurity provisions in contracts with third parties who have access to nonpublic information.

Required contractual provisions under Part 500 include the third party’s representation that it maintains appropriate cybersecurity controls; notification obligations upon discovery of a cybersecurity event affecting the covered entity’s systems or data; encryption requirements for data in transit and at rest; multi-factor authentication requirements for access to systems containing nonpublic information; and audit rights enabling the covered entity to assess the third party’s cybersecurity programme.

For New York-licensed banks and financial institutions, these contractual requirements are regulatory obligations, not negotiating points. A vendor that declines to include required provisions is a vendor the institution cannot onboard without regulatory exposure. Building a standard contract template that includes Part 500 provisions, reviewed by legal counsel familiar with the regulation, is a necessary infrastructure investment.

What These Frameworks Require in Practice

Taken together, these overlapping regulatory frameworks establish a common set of expectations for financial institution third-party risk management: a documented risk-based programme; due diligence before onboarding; contractual provisions covering security standards and breach notification; ongoing monitoring throughout the relationship; board and senior management engagement for higher-risk relationships; and documented exit planning.

The most common gap Armour identifies in financial institution third-party programmes is the distance between policy and practice. Institutions often have a vendor risk policy that describes a programme their actual practices do not match. Questionnaires are sent but not reviewed against defined standards. Vendor audit reports are received but not assessed for relevance to the institution’s specific relationship. Monitoring cycles are defined but not executed consistently. These gaps become findings when examiners assess whether the programme is operating as documented.

How API Integrations Change the Risk Picture

Fintech partnerships and open banking integrations introduce technical risk that contractual provisions alone cannot address. An API connection that is improperly scoped, uses long-lived credentials without rotation, or lacks rate limiting creates an exploitable vulnerability regardless of what the contract says about security standards.

API security assessment covers authentication mechanism design, token scope and lifecycle management, data exposure in API responses, rate limiting and abuse prevention, and audit logging of API activity. These assessments should be conducted before a new integration goes live and periodically during the relationship, particularly after significant changes to either party’s platform.

Armour Cybersecurity includes API and integration security assessment within the scope of financial institution penetration testing engagements. The findings are mapped to OSFI B-10 and B-13, NYDFS Part 500, and the 2023 Interagency Guidance requirements to produce evidence that satisfies regulatory expectations alongside the security improvement.

Across the 260+ organizations Armour Cybersecurity protects in 52+ industries, the institutions that clear a third-party examination cleanly are the ones whose vendor programme is a living operation rather than a policy binder, an inventory that is actually current, questionnaires that are actually read against a standard, monitoring cycles that actually run on schedule, and API integrations that were security-tested before go-live. Armour builds third-party risk management programmes for banks, credit unions, and fintechs that examiners find operating exactly as documented.

Frequently Asked Questions

Do the US interagency guidance requirements have regulatory force?

The 2023 Interagency Guidance is not a regulation with direct legal penalties, but it is enforced through the examination process. When OCC, FDIC, or Federal Reserve examiners assess third-party risk management during safety and soundness reviews, the guidance defines what they look for. A programme that falls short of guidance expectations generates examination findings, which carry real consequences: remediation requirements, increased examination frequency, and in serious cases, formal enforcement actions. NYDFS Part 500 third-party provisions, by contrast, are regulatory requirements with direct penalty exposure.

How should we handle a vendor that refuses to complete our security questionnaire?

A vendor that declines to provide evidence of its cybersecurity controls is a vendor whose risk cannot be assessed. Under OSFI B-10 and the 2023 Interagency Guidance, onboarding a vendor without completing due diligence is itself a compliance gap. For lower-criticality, lower-risk vendors this situation may be manageable with alternative assessment approaches. For vendors with access to sensitive data or core systems, refusal to cooperate with due diligence is typically grounds to decline or discontinue the relationship.

What is the right cadence for ongoing vendor monitoring?

Risk classification drives monitoring cadence. Critical vendors, those with access to cardholder data, customer personal financial information, or core banking system functions, warrant annual or semi-annual review including updated questionnaires and current audit report review. Moderate-risk vendors may be reviewed annually. Lower-risk vendors may be reviewed every two to three years, with event-triggered review when the vendor discloses a security incident or material business change. The cadence must be documented in the vendor risk programme and actually executed on schedule to satisfy examiner expectations.

How do we manage fourth-party risk when our vendors use sub-contractors?

Fourth-party risk management starts with contractual visibility: requiring vendors to notify the institution of material sub-contractors and changes to sub-contractor relationships. For critical vendors, the due diligence should include review of the vendor’s own third-party risk management practices to assess whether they apply adequate oversight to sub-contractors who handle the institution’s data. OSFI B-10 and the 2023 Interagency Guidance both address this and expect institutions to understand the sub-contractor dependencies of their critical service providers.

The Bottom Line

Third-party and fintech risk is now examined, not assumed. OSFI B-10 in Canada, the 2023 Interagency Guidance in the US, and NYDFS Part 500 in New York have converged on the same demand: a documented, risk-based programme that runs the full lifecycle of every vendor relationship, due diligence before onboarding, contractual security terms, monitoring that actually happens, concentration and fourth-party risk assessed, and integrations security-tested before they go live. The institutions that pass do not have better policies; they have policies their practice matches. Armour Cybersecurity helps banks, credit unions, and fintechs build third-party risk management programmes that satisfy OSFI B-10 and B-13, US Interagency Guidance, and NYDFS Part 500, with the API and integration testing that fintech partnerships demand, so the vendor programme an examiner reviews is the one the institution actually operates.

Leave the first comment