The Federal Financial Institutions Examination Council is a coordinating body, and it examines no bank directly. What it does produce is examiner handbooks that the OCC, the Federal Reserve, the FDIC, and the NCUA use when they evaluate how a financial institution manages third-party risk.
Knowing which booklet an examiner will open, and where the June 2023 interagency guidance fits alongside those booklets, changes how you organize your evidence. This guide explains which IT Examination Handbook booklets cover outsourcing and third-party risk, and how the framework applies to both banks and credit unions.
See our complimentary datasheet regarding enterprise risk management to learn more about how different kinds of risks are handled.

What the FFIEC Is and Its Role in Third-Party Risk
The FFIEC is an interagency body that prescribes uniform standards, and report forms for the examination of financial institutions. Its members are the OCC, the Federal Reserve Board, the FDIC, the NCUA, the CFPB, and the State Liaison Committee.
Supervision and examinations of institutions stay with the individual member agencies, each of which regulates its own set of banks or credit unions. What the council contributes is common material. For technology and outsourcing risk that material is the FFIEC IT Examination Handbook.
The handbook booklets outline how examiners assess an institution's oversight of service providers. Expectations stay consistent across agencies because they draw from the same source.
The FFIEC IT Examination Handbook Booklets That Cover Outsourcing
The FFIEC IT Examination Handbook is a series of booklets, each covering a domain of technology risk. Several bear directly on how you manage service providers, and knowing which is which helps you organize evidence before an examination.
The table below maps the booklets most relevant to outsourcing technology services and third-party risk to their focus and their bearing on vendor oversight.
| Booklet | Primary focus | Relevance to third-party risk |
|---|---|---|
| Outsourcing Technology Services | Risk management of outsourced technology functions | Core booklet for vendor selection, contracts, and oversight of outsourced services |
| Architecture, Infrastructure, and Operations (AIO) | IT architecture, infrastructure, and operations | 2021 booklet that superseded the older Operations booklet; covers reliance on external providers for infrastructure and operations |
| Business Continuity Management | Resilience and continuity planning | Addresses continuity of outsourced services and provider recovery expectations |
| Development and Acquisition | Systems development, acquisition, and project management | Covers acquiring software and services from third parties, including build-versus-buy decisions |
| Information Security | Safeguarding information assets | Extends security expectations to data and systems handled by service providers |
The Third-Party Risk Lifecycle in FFIEC Guidance
FFIEC guidance and the 2023 interagency guidance describe third-party risk as a lifecycle rather than a one-time approval. The stages are:
- Planning
This is where you decide whether to outsource an activity and assess the risk the arrangement would introduce.
- Due diligence and selection
Thid is the evaluation of a prospective provider's financial condition, controls, security posture, and track record.
- Contract negotiation
This stage turns findings into enforceable terms covering performance, security, audit rights, subcontracting, and exit.
- Ongoing monitoring
Monitoring confirms the provider still meets its obligations and that the institution's risk assessment stays current.
- Termination
This covers the orderly wind-down of a relationship, including return or destruction of data and continuity of service during transition.
A practical walkthrough of the third-party risk lifecycle makes these stages easier to operationalize. Throughout the lifecycle the board and senior management remain responsible for activities performed by a service provider.
How FFIEC Guidance Applies to Banks and Credit Unions
Both banks and credit unions fall under the framework, though the supervisory path differs.
Banks answer to the OCC, the Federal Reserve, or the FDIC depending on charter, and those three agencies issued the 2023 interagency guidance that sets the lifecycle expectation. Their examiners draw on the FFIEC IT Examination Handbook when they assess technology and outsourcing risk.
Credit unions are supervised by the NCUA. The NCUA follows FFIEC handbook principles and applies its own supervisory guidance to third-party relationships. Because the NCUA did not join the 2023 interagency guidance, a credit union's frame of reference is the FFIEC handbook material together with NCUA guidance, rather than the interagency document that applies to banks.
The practical expectations, sound due diligence, clear contracts, and ongoing oversight, look similar across both, since they trace back to the shared FFIEC framework. What differs is the specific document set each institution should cite in its own program.
Preparing for an FFIEC-Aligned Examination
Start with a complete inventory of third-party relationships. Tier that inventory by criticality. Keep due-diligence records, contracts, and monitoring results organized. The same discipline underpins building a third-party risk management program that holds up outside of examination season.
Mapping your controls to the relevant handbook booklets makes the examination smoother. Platforms like Predict360, built for this work, can reduce the manual effort of holding it together.
This solution includes a third-party and vendor risk management module that maintains a centralized vendor inventory, applies criticality tiering, and generates monitoring and reporting outputs. Capabilities like these help an institution keep vendor records, risk ratings, and evidence in one place.
Frequently Asked Questions
Which FFIEC handbook booklets cover outsourcing and vendor risk?
The most relevant booklets are Outsourcing Technology Services; Architecture, Infrastructure, and Operations; Business Continuity Management; Development and Acquisition; and Information Security.
What is the third-party risk lifecycle in FFIEC guidance?
The lifecycle, consistent with the 2023 interagency guidance, runs through five stages: planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination. Across all of them, the board and senior management retain responsibility for activities performed by a service provider.
How should a bank prepare for an FFIEC-aligned third-party risk examination?
Maintain a complete, criticality-tiered inventory of third-party relationships, and keep due-diligence, contract, and monitoring evidence organized for each one. Map your controls to the relevant handbook booklets so an examiner can trace expectation to evidence. Address business continuity and concentration risk explicitly, including reliance on single providers and their subcontractors.
If you are building or refining your program, a structured look at how to use third-party risk monitoring software is a useful next step toward turning this framework into working practice.
The Predict360 Enterprise Risk Management Software ensures managers have complete visibility of enterprise risk on a single dashboard.
Request Demo- Cloud-Based
- Risk Repository
- Assess Risks
- Real-time Monitoring