In October, the Office of the Comptroller of Currency (OCC) issued new guidance for banks regarding third party risk management, listing one of their reasons for issuing these guidelines as failure by the banks "to perform adequate due diligence and ongoing monitoring of third-party relationships." Current means of assessing third party security risk include annual audits and questionnaires, tools that are useful but which fail to provide the continuous, evidence-based assessments banks need to truly understand their vendor risk, especially when it comes to security risk management.
The OCC suggests that banks need to apply more resources towards evaluating the information security posture of their vendors. Specifically, it recommends that banks: "Determine whether the third party has sufficient experience in identifying, assessing, and mitigating known and emerging threats and vulnerabilities," and "Evaluate the third party’s ability to implement effective and sustainable corrective actions to address deficiencies...."