Published 4 December 2023, the FSB's third-party risk toolkit is the international framework for how banks and supervisors manage reliance on critical service providers, including cloud and AI vendors. It gives common definitions, tools for identifying critical services, and lifecycle risk-management tools covering supply-chain risk. It followed a June 2023 consultation that drew 26 responses, and the FSB's 2026 AI sound practices cite it as the basis for Sound Practice 12 on third-party AI risk.
OFFICIAL TEXT: fsb.org ↗ · FINAL · FSB
| Document | FSB third-party risk toolkit (2023) — Final Report on Enhancing Third-party Risk Management and Oversight: A toolkit for financial institutions and financial authorities |
| Issued by | Financial Stability Board |
| Type | Framework |
| Status | Final |
| Published | Dec 4, 2023 |
| Applies to | Financial institutions, financial authorities and, indirectly, critical third-party service providers (including cloud and AI model providers) |
| Official source | fsb.org ↗ |
| Use cases | Third-party & vendor AI · Cybersecurity · AI governance (general) |
What are the key points of FSB third-party risk toolkit (2023)?
- Final report issued 4 December 2023 after a consultation that closed 22 August 2023 with 26 responses.
- Focuses on 'critical services' whose disruption could affect a firm's critical operations or financial stability, broader than the old outsourcing lens.
- Provides common terms and definitions to reduce regulatory fragmentation across jurisdictions and sectors.
- Tools for financial institutions cover identifying critical services, due diligence, contracting, ongoing monitoring, business continuity and exit, including nth-party supply-chain risk.
- Tools for authorities cover supervising firms' third-party risk management and cross-border cooperation on systemic third-party dependencies.
- Referenced by the FSB's June 2026 AI sound practices (Sound Practice 12) for managing AI model, cloud and data vendors.
What did FSB third-party risk toolkit (2023) change for banks?
It shifted the global framing from 'outsourcing' to holistic third-party and supply-chain risk, the lens now applied to foundation-model and cloud providers that the FSB identifies as the sector's biggest AI concentration risk.
Does the FSB third-party toolkit apply to AI vendors?
Yes. It applies to any critical service, and the FSB's 2026 AI sound practices point to it for managing dependencies on AI model, cloud and data providers.
Is the FSB third-party toolkit binding?
No. It is a non-binding toolkit; US banks are bound by the June 2023 interagency third-party guidance, which the toolkit is broadly consistent with.
| Date | Document | Status |
|---|---|---|
| Aug 31, 2026 | FSB Chair's letter to G20 (Aug 2026) — FSB Chair's letter to G20 Finance Ministers and Central Bank Governors: August 2026 — risks arising from frontier artificial intelligence models | Final |
| Aug 6, 2026 | Responses to FSB AI sound practices consultation (Aug 2026) — Public responses to consultation on Sound Practices for Responsible Adoption of Artificial Intelligence (AI) | Final |
| Jul 7, 2026 | Bowman remarks at FSB AI outreach (July 2026) — Opening remarks on sound practices for artificial intelligence (FSB virtual outreach event) | Final |
| Jun 10, 2026 | FSB AI sound practices consultation (June 2026) — Sound Practices for Responsible Adoption of Artificial Intelligence (AI): Consultation report | Proposed |
| Oct 10, 2025 | FSB AI monitoring report (Oct 2025) — Monitoring Adoption of Artificial Intelligence and Related Vulnerabilities in the Financial Sector | Final |
| Oct 10, 2025 | FSB next steps on AI monitoring (Oct 2025) — FSB outlines next steps for authorities on AI monitoring | Final |
Follow every document these regulators publish
the daily brief · six sourced stories · in your inbox by 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning