Feature Third-Party Risk
NYDFS Said It in October. Examiners Are Checking in 2026. What Your Vendor Program Needs to Reflect the Part 500 Third-Party Guidance.
NYDFS's October 2025 industry letter on third-party cybersecurity risk established that covered entities cannot delegate Part 500 compliance to vendors. With MFA, asset inventory, and annual certification requirements now fully active, examiners are reviewing whether vendor programs actually reflect the guidance — not just acknowledge it. Here's what your TPRM program needs.
Table of Contents
TL;DR
- NYDFS’s October 21, 2025 industry letter established a non-negotiable position: covered entities cannot delegate Part 500 compliance obligations to vendors, only functions
- Examiners are now asking specifically about third-party due diligence documentation, contract provisions, and ongoing oversight in 2026 reviews — not just whether a program exists
- The guidance covers cloud providers, AI vendors, file transfer systems, and FinTech solution providers with a lifecycle framework: due diligence → contracts → ongoing oversight → secure termination
- AI-specific requirements from NYDFS’s October 2024 letter compound this: risk assessments must be updated for AI risks, AI vendor due diligence must be documented, and incident response plans must address AI-related events
The NYDFS Part 500 implementation cycle has moved from adoption to enforcement. The Second Amendment’s final provisions — MFA, asset inventory, and the encryption requirements — took effect November 1, 2025. The annual certification deadline passed April 15, 2026. And starting in 2026 examination cycles, NYDFS examiners are checking not just whether institutions have documented a third-party risk management program, but whether that program actually reflects the expectations NYDFS laid out in its October 2025 industry letter.
The October 2025 guidance is non-binding. That framing causes a lot of institutions to underweight it. The enforcement signal in the letter is explicit: NYDFS “will continue to consider the absence of adequate third-party risk management practices in its examinations, investigations, and enforcement actions.” That’s not guidance. That’s an exam standard.
What the October 2025 Letter Actually Established
On October 21, 2025, NYDFS issued an industry letter addressing risks associated with third-party service providers. The explicit focus: cloud computing, file transfer systems, artificial intelligence tools, and FinTech solution providers — the categories of vendors NYDFS determined are most commonly creating cybersecurity exposure for covered entities.
Three things in the letter warrant attention beyond the headline:
The delegation prohibition is explicit. The Department has observed covered entities “outsourcing critical compliance obligations without sufficient oversight.” This is prohibited. You can outsource the functions — log monitoring, penetration testing, identity management, patch management — but not the compliance accountability. If your current program treats a SOC 2 report from your cloud provider as your own compliance artifact, that’s the problem the letter is addressing.
The lifecycle framing is structural, not advisory. The guidance didn’t just list contract requirements. It established a four-phase lifecycle — initial due diligence, contractual safeguards, ongoing oversight, and secure termination — that NYDFS expects to see as the architecture of your third-party risk management program. Each phase has specific outputs NYDFS expects to find in an examination.
AI vendors get a separate lane. A prior October 2024 NYDFS letter on AI cybersecurity created AI-specific obligations that the 2025 guidance reinforces. Risk assessments must be updated to specifically address AI-related risks from your own AI use, AI vendor dependencies, and AI-related vulnerabilities. AI vendor due diligence must be documented separately. Incident response plans must explicitly address AI-related cybersecurity events. If your TPRM program treats AI vendors the same as generic SaaS vendors, you have a gap.
The Four-Phase Lifecycle NYDFS Expects
Phase 1: Initial Due Diligence
Before onboarding any third-party service provider with access to your systems or NPI, NYDFS expects a risk-based assessment. What “risk-based” means in practice:
- Risk tiering: Not every vendor gets the same depth of review. A vendor with full access to production systems containing NPI for 100,000 customers gets more scrutiny than a vendor with read-only access to anonymized logs. Build a tiering criteria that’s documented and consistent.
- Due diligence questionnaire: Cover at minimum: cybersecurity program description, incident history (last three years), relevant certifications or third-party assessments (SOC 2 Type II, ISO 27001, penetration test results), encryption practices, access controls, and incident notification procedures.
- Documentation review: Request and actually review SOC 2 reports or equivalent. If a vendor can’t produce one, that’s a risk factor to document and escalate — not a reason to skip the onboarding.
- Vendor selection constraints: NYDFS acknowledges that regulated entities sometimes face limited vendor choices (one cloud provider has the required capabilities, one specialized fintech tool exists for a niche function). The guidance expects you to document the constraints and the risk-informed decision, not simply proceed without documentation.
Phase 2: Contractual Safeguards
NYDFS outlined minimum contract provisions that every TPSP agreement should include. These aren’t optional negotiating points — examiners will review them:
| Provision | What NYDFS Expects |
|---|---|
| Access controls | Limit TPSP access to what’s necessary for the contracted service; require MFA for access to your systems |
| Data encryption | Specify encryption standards for data in transit and at rest |
| Cybersecurity event notification | Define the timeframe for vendor notification to you (align with Part 500’s Section 500.17 72-hour notice requirement for incidents affecting your covered entity) |
| Compliance representations | Vendor attests to compliance with applicable laws and regulations, not just “reasonable security” language |
| Data location and transfer restrictions | Where data can be stored, processed, and transferred; cross-border transfer rules |
| Subcontractor requirements | Vendor must notify you before engaging a subcontractor with access to your systems or data; subcontractors must meet equivalent security standards |
| Data use and exit obligations | How data is used during the term; how it’s returned or destroyed at termination; confirmation process |
If you have existing vendor contracts that predate the 2025 guidance and don’t include these provisions, the expectation is that renewals and material amendments incorporate them. Examine your highest-risk vendor agreements first.
Phase 3: Ongoing Oversight
One of the most common TPRM failures NYDFS sees — and the pattern in the OCC Bulletin 2023-17 examination findings — is that institutions perform strong initial due diligence but have no ongoing oversight mechanism. The vendor’s security posture changes, a subcontractor is added, a breach occurs at the vendor but isn’t reported — and the covered entity finds out from the news.
NYDFS expects ongoing oversight to include:
- Periodic re-assessments: Frequency should be risk-tiered. Critical vendors with NPI access should be reassessed annually at minimum; lower-risk vendors can use longer cycles.
- Access reviews: Audit the vendor’s actual access to your systems quarterly. Are they accessing what they need, or has scope expanded beyond the original contract without a corresponding review?
- Incident notification follow-through: When a vendor discloses a cybersecurity event, log it, assess whether your systems or NPI were affected, and document your determination. Examiners will ask about vendor incidents and your response.
- Performance against SLAs: Track whether the vendor is meeting security-relevant service level commitments, not just uptime.
- Annual certification request: Consider requiring vendors to annually attest to their continued compliance with contract terms and applicable security standards.
Phase 4: Secure Termination
This is the phase most programs skip entirely. NYDFS expects a documented offboarding process that:
- Revokes all vendor access to your systems and networks on or before the termination date
- Returns or destroys data per the contract’s exit obligations
- Requires the vendor to confirm in writing that NPI has been returned or destroyed (not just “deleted from active systems”)
- Addresses subcontractor access created during the relationship
- Archives the termination documentation as part of the vendor file
The data destruction confirmation is a specific gap in most programs. Vendors frequently have NPI in backup systems, archived logs, or development environments that aren’t captured in a standard data deletion process. The contract language and the termination checklist should address this explicitly.
AI Vendors: The Separate Compliance Track
The October 2024 NYDFS AI cybersecurity guidance, combined with the October 2025 third-party guidance, creates specific requirements for AI vendor oversight that exceed the standard TPRM framework:
Risk assessment updates: Your Part 500 risk assessment must be updated to specifically analyze AI-related risks — from your own AI use and from your AI vendor dependencies. This isn’t a general “technology risk” category. NYDFS expects AI-specific risk analysis.
AI vendor due diligence: AI vendors should receive a questionnaire that goes beyond standard cybersecurity questions. Add: What training data was used and how was it sourced? How are model outputs monitored for bias or accuracy degradation? What’s the vendor’s process for notifying customers when model behavior changes materially? How does the vendor handle NPI used as model inputs?
Incident response plan updates: Part 500’s Section 500.16 incident response plan requirements apply to AI-related events. Your IRP should have a section addressing AI-specific failure modes: model manipulation (prompt injection, adversarial inputs), AI-enabled fraud against your systems, data exfiltration via AI vendor access, and model drift causing operational failures.
NPI inventory for AI systems: If you’re using AI tools that process consumer NPI — a chatbot that accesses account data, a fraud model that processes transaction history — that NPI needs to be in your data inventory and covered by your AI vendor’s data handling provisions.
What Examiners Are Actually Asking
Based on the Greenberg Traurig and Protiviti analyses of the 2025 guidance and 2026 examination patterns, examiners are moving from asking “do you have a TPRM program?” to asking specific questions about program substance:
- “Show me your vendor risk tier criteria and how it applies to your top 10 vendors by data access.”
- “Pull your contract with [cloud provider] — where are the notification, subcontractor, and data destruction provisions?”
- “What did you do when [vendor] had a security incident last year? Show me the assessment.”
- “How do you validate that terminated vendors have actually destroyed your data?”
- “Walk me through the AI-specific sections of your Part 500 risk assessment.”
If your program can answer those questions with documentation — not a verbal description of what you intend to build — you’re in a defensible position. If the answer is “we’re working on updating our templates,” you’re facing an exam finding.
So What? The Practical Starting Point
For most NYDFS-covered entities, third-party risk management programs exist. The gap between “exists” and “meets October 2025 guidance expectations” is usually in three places:
Contracts: Pull your top 10 vendors by NPI access and score them against the seven minimum provisions NYDFS outlined. Negotiate updates on the next renewal cycle, or sooner for critical vendors. Prioritize vendors where breach or access failure would create the largest Part 500 notification exposure.
Ongoing oversight documentation: Build a tracking mechanism that captures the quarterly access review, annual reassessment, and incident notification log for each vendor. Examiners want to see a record, not a current-state assessment — evidence of activity over time is what distinguishes a functioning program from a framework document.
AI vendor lane: If you use any AI tools that access NPI, create a separate AI vendor questionnaire and add AI risk language to your risk assessments and incident response plan. This is the newest gap in TPRM programs and the one most likely to surface in 2026 examinations.
For a TPRM program that covers the full vendor lifecycle — risk tiering, due diligence questionnaires, contract review framework, ongoing monitoring templates, and offboarding checklists — the Third-Party Risk Management (TPRM) Kit gives you the operational framework your vendor program needs to reflect what NYDFS is now examining.
Further context on NYDFS Part 500 enforcement: See NYDFS Fined a Money Transmitter $250K for Its Risk Assessment, Not the Ransomware for a recent consent order that shows how Part 500 program gaps translate into penalties. For the BaaS enforcement pattern relevant to third-party program design: The Contract Says It’s the Fintech’s Problem. Seven BaaS Consent Orders Say Otherwise. And for the OCC parallel examination framework: The OCC Bulletin 2023-17 Vendor Due Diligence File — What Examiners Expect.
Sources: NYDFS October 2025 Industry Letter on Third-Party Service Providers · Sidley Data Matters — NYDFS Third-Party Guidance Analysis · Inside Privacy — NYDFS Third-Party Guidance · Greenberg Traurig — NYDFS MFA, Asset Inventory, and Third-Party Risk · McDermott — NYDFS Clarifies Third-Party Cybersecurity Risk Management
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Does the NYDFS October 2025 guidance create new compliance requirements?
Which vendors does the NYDFS third-party guidance cover?
Can we outsource our Part 500 compliance to a managed security service provider (MSSP)?
What are the minimum contract provisions NYDFS expects with third-party service providers?
What does NYDFS consider 'adequate' third-party due diligence?
What happens if an examiner finds my third-party risk program doesn't meet the guidance?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Keep reading
Related posts.
Third-Party Risk
OCC's 2026 Third-Party Risk Guidance Rewrite: What Banks Should Change Now
The 2026 third-party risk guidance proposal rewrites vendor tiering and gives community banks leverage with core providers.
Sep 11, 2026
Third-Party Risk
Everest Ransomware Hit Citizens Bank and Frost Bank Through a Vendor Nobody Will Name. Six Class Actions Later, Here's What Your TPRM Program Needs.
In April 2026, the Everest ransomware group claimed 3.65 million records from Citizens Bank and Frost Bank via a shared third-party vendor. Neither bank has named the vendor. Six class actions were filed against the banks. Here is what this means for your TPRM program.
Sep 10, 2026
Third-Party Risk
The FSB Told G20 That Frontier AI Is Your Biggest Third-Party Risk. Your TPRM Program Probably Can't Handle That Yet.
FSB Chair Andrew Bailey's August 2026 letter to G20 finance ministers identified frontier AI as the 'most immediate' cyber threat to financial stability — specifically because it amplifies risk through concentrated critical third-party technology providers. The Citizens Bank vendor breach and Q1 2026 data tell the same story. Here's what your third-party risk program needs to change.
Sep 6, 2026