Strunk
  • Compliance
  • Profitability
    • Pricing Manager
    • Overdraft Privilege
    • Econocheck
  • Connect
    • The Strunk Perspective
    • Contact Us
  • Login
  • DEMO
  • Menu Menu
  • X
  • LinkedIn

Technology Service Provider Contracts

September 4, 2019/in Banks, Credit Unions, Financial Services, Uncategorized, Vendor Manager/by Joel Lawrence

Understanding the increasing dependence that financial institutions have on technology service providers, bank regulators have ramped up their efforts to require banks to appropriately handle third-party risk management. The Federal Deposit Insurance Corporation (FDIC) has identified gaps noted by some examiners regarding several technology service provider contracts that were inadequate under existing guidance. These contracts were missing or inadequately addressed key provisions, such as:

  • Requiring the service provider to maintain a business continuity plan,
  • Lacking standards for data recovery along with appropriate remedies when a recovery standard is missed.
  • Defining key terms in the contracts relevant to business continuity and/or incident response.

Contracts lacking these provisions violate the Interagency Guidelines Establishing Information Security Standards, as promulgated under the Gramm-Leach-Bliley Act.

Vendors that provide technology-related services can create special risks for depository institutions that must be properly addressed in their service contracts. The FDIC indicated that it plans to hold boards and senior management of financial institutions accountable for controlling those risks, in accordance with the requirements of the law and its existing regulatory guidance.

Financial Institutions should be willing to hold their service providers accountable and negotiate an appropriate contract. All financial institutions should have provisions that they review for all of their contracts, along with a robust vendor management program that will help uncover any weakness in business continuity and data recovery early in the process.

Share this entry
  • Share on Facebook
  • Share on X
  • Share on WhatsApp
  • Share on Pinterest
  • Share on LinkedIn
  • Share on Tumblr
  • Share on Vk
  • Share on Reddit
  • Share by Mail
https://strunkaccess.com/wp-content/uploads/2019/09/hurricane.jpg 675 1200 Joel Lawrence https://strunkaccess.com/wp-content/uploads/2022/03/Strunk-Original-300x100.png Joel Lawrence2019-09-04 06:54:542019-09-03 09:35:15Technology Service Provider Contracts

Recent Articles

  • Banks Can Increase Customer Satisfaction & Fee Income at the Same TimeMay 7, 2025 - 10:00 am
  • Options for ODP Manager AccessApril 24, 2025 - 10:00 am
  • How can Strunk’s Vendor Manager software support your organization’s Third-Party Risk Management process?April 9, 2025 - 10:00 am
  • Bankers Look for Ways to Make More MoneyApril 2, 2025 - 10:00 am

GRC Topics

  • Banks
  • COCC
  • Compliance
  • Credit Unions
  • Financial Services
  • FINSYNC
  • Markets
  • Overdraft Privilege
  • Perspectives
  • Policy Manager
  • Pricing Manager
  • Risk Manager
  • Sales
  • Secure Checking
  • SOC2
  • Tips
  • Uncategorized
  • Vendor Manager
  • WBA
Schedule A Demo

An independent certified public accountant has examined Strunk’s operations and found them to be in compliance with the AICPA’s Trust Service Principles. It was determined that Strunk meets the Security, Availability, Processing Integrity, Confidentiality, and Privacy criteria for SOC 2 established by the AICPA.

© Copyright - Strunk | Privacy Policy | Security Policy | Business Continuity Policy
Scroll to top