Le 11 septembre 2026, quatre régulateurs financiers américains ont publié de nouvelles directives proposées sur la gestion des risques liés aux tiers, visant à remplacer le cadre de 2023. Cette initiative cherche à adapter les exigences réglementaires tout en clarifiant les obligations des banques et des caisses d’épargne.
Une refonte du cadre de gestion des risques pour les institutions financières
Les autorités de régulation bancaire aux États-Unis ont demandé des commentaires publics sur un projet de directives destiné à aider les institutions financières à encadrer leurs relations avec des prestataires extérieurs. L’annonce conjointe a été publiée le 11 septembre 2026 à 10h00 EDT par la Federal Deposit Insurance Corporation, la Federal Reserve Board, la National Credit Union Administration et l’Office of the Comptroller of the Currency. Ce texte propose de modifier profondément la manière dont le secteur aborde la sous-traitance et les partenariats externes.
La démarche s’inscrit dans le cadre d’une volonté d’encourager l’innovation responsable tout en maintenant la sécurité du système bancaire. Le public et les acteurs du secteur disposent d’un délai de 60 jours après publication dans le Federal Register pour soumettre leurs observations. Le joint notice carries docket identifiers OCC-2026-0793 for the OCC, OP-1881 for the Board, RIN 3064-ZA58 for the FDIC, and NCUA-2026-1684 for the NCUA.
Les critiques de l’ancien cadre de 2023 et les quatre piliers proposés
Le projet de directives publié par les régulateurs vise à remplacer les orientations inter-agences établies en juin 2023 (88 FR 37920, June 9, 2023), ainsi que plusieurs documents complémentaires et bulletins sectoriels antérieurs. Ces ressources supplémentaires comprennent l’OCC’s May 15, 2002 bulletin on foreign-based third-party service providers, the July 25, 2024 joint statement on banks’ arrangements with third parties to deliver bank deposit products, and the May 3, 2024 guide Third-Party Risk Management: A Guide for Community Banks. D’après les retours des parties prenantes et l’expérience de la supervision, les règles précédentes avaient montré des limites pratiques importantes. Les agences ont écrit que la 2023 Guidance a frequently been interpreted in an overly broad manner and with insufficient focus on tailoring; that its extensive considerations and detailed examples proved difficult to apply across different types of relationships; that it unintentionally incentivized process-driven, check-the-box approaches over risk-focused practices; and that it has been read to discourage arrangements with newer and innovative third parties.
La nouvelle proposition s’articule autour de quatre composantes : risk identification and assessment; risk oversight, covering due diligence and third-party selection, contract negotiation, ongoing monitoring, termination, and cross-cutting topics; residual risk acceptance; and governance. Risk assessments would account for both the magnitude of harm a relationship could cause and the likelihood that the harm will occur. Higher-risk relationships could include those that, if disrupted, subjected to attack, conducted in breach of contract, or otherwise performed under non-business-as-usual circumstances, could cause an actual non-trivial violation of law or regulation, material harm to the banking organization’s financial condition, or significant disruption to its operations or customers, where there is a material likelihood of such outcomes under current or reasonably foreseeable conditions.
Une approche non contraignante axée sur les principes
Le texte repose sur une principles-based approach et se veut non-binding, selon les termes de l’annonce conjointe des agences. Les régulateurs ont précisé que the guidance sets forth no enforceable standards or prescriptive requirements, that non-compliance will not result in supervisory action, and that deviation from the guidance or its examples alone would not be a basis for supervisory action or an adverse examiner finding. Il est également précisé that the agencies may still take action for violations of laws or regulations, unsafe or unsound practices, or other material risks that result from insufficient management of third-party risk, et que the agencies will give due consideration to a banking organization’s reasonable decisions in matters of third-party risk management supervision.
Separately the same day, the Board, the FDIC, and the OCC issued a statement on community banks’ engagement with core service providers, discussing certain factors the agencies will consider in making supervisory and enforcement decisions related to these core providers. Parallèlement à ce projet global, la Federal Reserve Board requested comment on a proposed third-party risk management guide specifically for the community banks it supervises, intended as a companion document to the broader proposal.
La Federal Deposit Insurance Corporation, la Federal Reserve Board, la National Credit Union Administration et l’Office of the Comptroller of the Currency ont indiqué qu’elles constituaient les quatre institutions concernées.