Published 4 December 2023, the FSB's third-party risk toolkit is the international framework for how banks and supervisors manage reliance on critical service providers, including cloud and AI vendors. It gives common definitions, tools for identifying critical services, and lifecycle risk-management tools covering supply-chain risk. It followed a June 2023 consultation that drew 26 responses, and the FSB's 2026 AI sound practices cite it as the basis for Sound Practice 12 on third-party AI risk.
| Document | FSB third-party risk toolkit (2023) — Final Report on Enhancing Third-party Risk Management and Oversight: A toolkit for financial institutions and financial authorities |
| Issued by | Financial Stability Board |
| Type | Framework |
| Status | Final |
| Published | Dec 4, 2023 |
| Applies to | Financial institutions, financial authorities and, indirectly, critical third-party service providers (including cloud and AI model providers) |
| Official source | fsb.org ↗ |
| Use cases | Third-party & vendor AI · Cybersecurity · AI governance (general) |
What are the key points of FSB third-party risk toolkit (2023)?
- Final report issued 4 December 2023 after a consultation that closed 22 August 2023 with 26 responses.
- Focuses on 'critical services' whose disruption could affect a firm's critical operations or financial stability, broader than the old outsourcing lens.
- Provides common terms and definitions to reduce regulatory fragmentation across jurisdictions and sectors.
- Tools for financial institutions cover identifying critical services, due diligence, contracting, ongoing monitoring, business continuity and exit, including nth-party supply-chain risk.
- Tools for authorities cover supervising firms' third-party risk management and cross-border cooperation on systemic third-party dependencies.
- Referenced by the FSB's June 2026 AI sound practices (Sound Practice 12) for managing AI model, cloud and data vendors.
What did FSB third-party risk toolkit (2023) change for banks?
It shifted the global framing from 'outsourcing' to holistic third-party and supply-chain risk, the lens now applied to foundation-model and cloud providers that the FSB identifies as the sector's biggest AI concentration risk.
Does the FSB third-party toolkit apply to AI vendors?
Yes. It applies to any critical service, and the FSB's 2026 AI sound practices point to it for managing dependencies on AI model, cloud and data providers.
Is the FSB third-party toolkit binding?
No. It is a non-binding toolkit; US banks are bound by the June 2023 interagency third-party guidance, which the toolkit is broadly consistent with.
| Date | Document | Status |
|---|---|---|
| Aug 6, 2026 | Responses to FSB AI sound practices consultation (Aug 2026) — Public responses to consultation on Sound Practices for Responsible Adoption of Artificial Intelligence (AI) | Final |
| Jul 7, 2026 | Bowman remarks at FSB AI outreach (July 2026) — Opening remarks on sound practices for artificial intelligence (FSB virtual outreach event) | Final |
| Jun 10, 2026 | FSB AI sound practices consultation (June 2026) — Sound Practices for Responsible Adoption of Artificial Intelligence (AI): Consultation report | Proposed |
| Oct 10, 2025 | FSB AI monitoring report (Oct 2025) — Monitoring Adoption of Artificial Intelligence and Related Vulnerabilities in the Financial Sector | Final |
| Oct 10, 2025 | FSB next steps on AI monitoring (Oct 2025) — FSB outlines next steps for authorities on AI monitoring | Final |
| Nov 14, 2024 | FSB AI financial stability report (Nov 2024) — The Financial Stability Implications of Artificial Intelligence | Final |
Follow every document these regulators publish
6 curated AI stories for banking executives · Every morning · Free
Subscribe to BankingNewsAI →