FDIC Outsourcing Guidelines
Definition
FDIC Outsourcing Guidelines
FDIC outsourcing guidelines refers to the Federal Deposit Insurance Corporation’s expectations for banks that rely on third parties. The 2008 standalone guidance no longer exists, having been replaced by guidance the FDIC now issues jointly with two other agencies.
For fifteen years the FDIC maintained its own third party guidance, and banks maintained programmes built around it.
That ended in June 2023. The FDIC, the Federal Reserve Board and the Office of the Comptroller of the Currency issued one document in place of three.
The change was not cosmetic — a bank supervised by more than one agency previously reconciled three sets of expectations, and now reconciles one.
Key takeaways
- FIL-44-2008 was rescinded and replaced by interagency guidance in June 2023.
- The guidance explicitly scales with a banking organisation’s risk, complexity and size.
- Using a third party does not reduce the bank’s own responsibility for the activity.
- Federal law allows examiners to review contracted services as if the bank performed them.
How it works
The replacement is stated plainly. The FDIC’s letter announces final guidance on managing risks associated with third-party relationships that will replace each agency’s existing guidance on this topic, and rescinds and replaces FIL-44-2008.
Proportionality is built in — the guidance states that sound third-party risk management takes into account the level of risk, complexity and size of the banking organisation, which matters to community banks in particular.
The non-delegation principle is explicit. A banking organisation’s use of third parties does not diminish or remove its responsibility to perform all activities in a safe and sound manner and in compliance with applicable law.
| Question a bank asks | What the current framework answers |
|---|---|
| Which guidance applies? | The 2023 interagency guidance, across all three agencies |
| Is FIL-44-2008 still live? | No, it was rescinded |
| Does size matter? | Yes, expectations scale with risk, complexity and size |
| Can we transfer responsibility? | No, the bank remains responsible for the activity |
| Can examiners see the provider? | Yes, contracted services are examinable |
| Is there a prescribed contract template? | No, the guidance sets principles rather than clauses |
The examination point has a statutory basis rather than a supervisory one.
Where a bank has services performed by contract, such performance shall be subject to regulation and examination by such agency to the same extent as if such services were being performed by the depository institution itself on its own premises.
The same provision carries a notification duty — the institution must notify its agency of the service relationship within thirty days of the contract or the first performance of the service.
Examples
Community banks feel this framework differently from large institutions, which is the point of the proportionality language. The cases below are drawn from work running today under signed commercial terms.
A community bank uses a core processor and two fintech partners. Its programme is smaller than a regional bank’s, and the guidance’s scaling language is what makes that defensible.
A state savings bank outsources loan servicing offshore. The bank files the service relationship notification and builds examination access into the contract rather than negotiating it later.
A bank partners with a lending platform that sources borrowers. The activity is the bank’s for supervisory purposes, whatever the platform’s marketing says about who owns the customer.
A small institution relies on its processor’s own risk reporting. Examiners ask what the bank independently verified, and the answer has to be more than a received document.
Related terms
Bank supervisory vocabulary is agency specific even where the underlying expectations have merged. Each term here answers to a different authority, which is why they diverge.
- Banking outsourcing: the practice this guidance governs.
- Regulated outsourcing: supervised sector outsourcing across industries.
- Vendor management outsourcing: the programme examiners actually inspect.
- SOC 2 outsourcing: the assurance report banks request from providers.
- Business continuity plan (BCP): the resilience element of any material relationship.
- Compliance outsourcing: contracting the compliance function rather than an operational one.
- Risk outsourcing: moving risk activity out without moving accountability.
FAQ
Is FIL-44-2008 still in force?
No. It was rescinded and replaced by the interagency guidance issued in June 2023.
Does the guidance apply differently to small banks?
The expectations scale. Sound third-party risk management takes account of the risk, complexity and size of the banking organisation.
Can examiners look at our provider?
Yes. Services performed by contract are subject to examination to the same extent as if the bank performed them itself.
Do we have to notify the agency about a provider?
Federal law requires notification of a service relationship within thirty days of the contract or the first performance of the service.
Does the guidance prescribe contract clauses?
No. It sets principles across the relationship life cycle, and the drafting remains the bank’s responsibility.
Does a provider’s own report satisfy oversight?
Not alone. Examiners ask what the bank verified independently.
Review verified partners in the Outsource Accelerator directory and keep providers who accept examination access without renegotiating.







Independent




