Federal Banking Agencies Propose Overhaul of Third-Party Risk Management Guidance, Issue Community Bank Guide, and Heighten Focus on Core Service Providers
On September 11, 2026, the federal banking agencies issued three significant actions that would collectively reshape the regulatory landscape for third-party risk management:
- First, the FDIC (Federal Deposit Insurance Corporation), Federal Reserve Board, NCUA (National Credit Union Administration), and OCC (Office of the Comptroller of the Currency) jointly proposed new guidance to replace the agencies’ 2023 third-party risk management framework, emphasizing risk-based, tailored oversight rather than uniform vendor-management requirements.
- Second, the Federal Reserve Board proposed a companion guide for Federal Reserve-supervised community banks with less than $30 billion in assets, providing practical, non-binding examples for implementing third-party risk management principles. Comments on the proposals are due on or before November 16, 2026.
- Third, the FDIC, OCC, and Federal Reserve issued a joint statement signaling increased supervisory attention to large core service providers, highlighting concerns regarding transparency, restrictive contract practices, and the potential classification of certain providers as institution-affiliated parties subject to direct enforcement authority.
Proposed Third-Party Risk Management Guidance
The proposed third-party risk management guidance would replace the agencies’ 2023 third-party risk management framework with one centered on risk-based, tailored oversight rather than uniform vendor-management requirements.
Key Changes from the 2023 Guidance
The agencies state that the 2023 guidance has been interpreted too broadly, leading institutions to apply extensive controls regardless of actual risk. The proposal reorients third-party risk management around three themes: (1) tailoring oversight to each relationship based on the institution’s size, complexity, and risk profile, and on the nature and magnitude of potential harm; (2) shifting away from checklist approaches to focus resources where material financial and compliance risks actually exist; and (3) de-emphasizing “critical activities” as a basis for heightened oversight in favor of assessing the specific risks of each relationship and the likelihood and severity of harm.
New Risk Assessment Framework
The guidance proposes that banking organizations consider the following four components when managing third-party risk: (1) identifying and assessing applicable risks; (2) overseeing risks proportionate to their significance; (3) making informed decisions about residual risks and risk acceptance; and (4) establishing appropriate governance practices.
Because not all third-party relationships present the same level of risk, the guidance notes that risk assessments should account for both the magnitude of harm the third-party relationship could cause the banking organization or its customers and the likelihood that the harm will occur. Higher-risk relationships warrant more intensive oversight where there is a material likelihood that such legal or regulatory violation, financial harm, or operational disruption may occur under current or reasonably foreseeable conditions. Lower-risk relationships (e.g., administrative, clerical, consulting, legal, audit, and office support services) may warrant significantly lighter oversight and less extensive documentation.
Greater Flexibility in Due Diligence and Monitoring
Further, institutions need not maintain the same level of inventory and documentation for every third party; large institutions may need detailed inventories, while community banks may use simpler tracking. The guidance notes that due diligence should focus on identifying the most relevant and material risks rather than every conceivable risk. Monitoring should be proportional to risk, with high-risk relationships warranting more frequent reviews and low-risk relationships requiring less intensive oversight. On-site reviews, audits, and similar tools may not always be practical or necessary.
Contracting and Residual Risk
The agencies also acknowledge the reality that many vendors provide standard contracts, banks may lack negotiating leverage, and some desired protections may be unavailable. Regardless, an institution may still proceed with a relationship when it reasonably understands the risks and determines that residual risk falls within its risk appetite. This is a significant shift from interpretations of the 2023 guidance that led institutions to seek extensive contractual protections regardless of vendor criticality.
Affiliates, Regulated Third Parties, and Fintech
Relationships conducted within an enterprise-wide risk management framework or involving heavily regulated providers may present lower risk, although a provider’s regulated status does not automatically mitigate all risks. The agencies also acknowledge that prior guidance may have discouraged partnerships with newer or innovative firms and seek to avoid unnecessarily impeding bank-fintech relationships through a more flexible, risk-based approach. In practice, banks evaluating fintech partnerships should focus due diligence and oversight on the specific risks presented by the relationship, including data security, regulatory compliance, and operational resilience, rather than applying heightened oversight solely because a provider is newer or non-traditional. At the same time, banks remain responsible for complying with applicable laws and regulations, conducting appropriate risk assessments, and ensuring relationships are consistent with safe and sound banking practices.
Non-Binding Nature of the Guidance
The guidance does not create enforceable requirements, and a failure to follow a particular example is not, in itself, grounds for supervisory criticism. Supervisory action would still be based on legal violations, unsafe or unsound practices, or material risk-management deficiencies. See our prior client alert on supervisory actions here.
Key Takeaway for Legal, Compliance, and Vendor-Management Teams
The proposal represents a significant recalibration of third-party risk management expectations, encouraging institutions to ask whether they have reasonably identified material risks, assessed their significance, and applied proportionate oversight rather than check-the-box exercises. If finalized, the guidance could reduce the burden for lower-risk relationships, focus oversight on genuinely high-risk providers, increase flexibility in due diligence and contracting, encourage bank-fintech partnerships, and support reliance on documented risk-based judgments.
Proposed Third-Party Risk Management Guide for Community Banks
The Federal Reserve Board is also seeking comment on a proposed third-party risk management guide for Federal Reserve-supervised community banks with less than $30 billion in assets.
The guide is a practical, non-binding companion to the broader interagency guidance, translating high-level principles into day-to-day practices for traditional community banking organizations with relatively straightforward business models. It does not create new requirements or supervisory standards. Drawing on supervisory observations, examination materials, and industry practices, the guide focuses on the types of vendors most commonly used by community banks and emphasizes that risk management should be proportionate to each bank’s size, complexity, and risk profile. The Board seeks comment on whether the document strikes the right balance between being helpful and avoiding the creation of de facto examination expectations.
Joint Statement on Community Banks’ Engagement with Core Service Providers
Separately, the FDIC, OCC, and Federal Reserve issued a statement addressing concerns about community banks’ relationships with large core service providers that dominate critical banking infrastructure (such as core processing, payment processing, online banking, customer relationship management, and compliance systems). The agencies recognize that community banks often have limited alternatives and little negotiating power. The statement also acknowledges that core providers unreasonably limit a bank’s ability to conduct initial due diligence and ongoing monitoring or negotiate favorable contract terms that address the bank’s needs to identify, assess, and address risk.
Key regulatory signals include: (1) examiners will account for community banks’ limited leverage when evaluating third-party risk management; (2) the agencies will increase supervisory attention to core providers that limit transparency, such as those failing to provide timely due diligence information or adequate disclosure of outages and cybersecurity incidents; (3) problematic contract provisions—including opaque pricing, excessive deconversion fees, and restrictions on integration with other providers—will influence how supervisory resources are allocated; (4) providers that underinvest in technology and operational resilience can expect greater scrutiny; and (5) certain core providers may be deemed “institution-affiliated parties” under the Federal Deposit Insurance Act (FDIA) because they participate in the conduct of a bank’s affairs, potentially subjecting them to direct enforcement actions.
The agencies’ discussion of enforcement authority may be the most significant legal development in these issuances. If regulators determine that a core provider qualifies as an “institution-affiliated party” under the FDIA, the agencies may have authority to pursue supervisory or enforcement actions directly against the provider, rather than solely against the bank. Banks and core providers should carefully assess whether their relationships could support such a determination.
Additionally, this statement may impact banks’ abilities to conduct due diligence and obtain information related to their core providers as well as assist in negotiation of often extremely one -side master agreements. It remains to be seen how involved a role the regulatory agencies will take in these long-standing practices, but such a shift could result in substantial transparency and a focus on creating more mutually beneficial partnerships between banks and their core providers.
Despite this increased focus on core providers, the agencies reiterate that outsourcing does not transfer responsibility, and community banks retain accountability for safe and sound operations and legal compliance. For legal, vendor-management, and compliance teams, the most consequential aspects are the focus on vendor transparency, deconversion fees, restrictive contract provisions, interoperability limitations, and the possibility that major core providers may face direct enforcement authority as institution-affiliated parties.
Conclusion and Key Takeaways for Banks
Taken together, the agencies’ September 11, 2026, actions signal a meaningful shift toward risk-based, institution-specific third-party risk management. The proposed interagency guidance emphasizes tailored oversight, while the community bank guide provides practical implementation examples, and the core provider statement addresses longstanding concerns regarding vendor market power and contract practices.
Although the community bank guide is directed to institutions with less than $30 billion in assets, its practical approaches may be useful to larger institutions as well. Banks should consider:
- Reassess existing vendor-management programs. Boards and senior management should evaluate whether existing third-party risk management frameworks are calibrated to actual risk rather than relying on uniform controls across all vendor relationships. Compliance officers should lead a gap analysis comparing existing programs against the proposed risk-based framework.
- Right-size due diligence and monitoring. Vendor-management teams have an opportunity to reduce the compliance burden for lower-risk relationships while concentrating oversight resources on genuinely high-risk providers. Documentation and monitoring intensity should be proportionate to the risks each relationship presents. Risk and compliance functions should work together to develop tiered oversight protocols.
- Document risk-based judgments. As the agencies shift from procedural compliance to substantive risk assessment, institutions should ensure that their risk-based decisions are well-documented and supported by a clear rationale. Legal teams should develop or update templates and approval processes to capture these risk-acceptance decisions in a manner that will withstand examination scrutiny.
- Review core provider contracts. The joint statement’s focus on opaque pricing, excessive deconversion fees, and interoperability restrictions puts core provider contracts under a regulatory spotlight. Legal and vendor-management teams should review existing agreements for provisions that may attract supervisory attention—particularly pricing transparency, exit and deconversion terms, and restrictions on integration with third-party technology providers—and factor these issues into future contract negotiations and renewals.
- Leverage new resources. The Federal Reserve’s proposed community bank guide, once finalized, is intended to provide practical tools and examples tailored to smaller institutions. Community banks should monitor the rulemaking process and prepare to incorporate the guide into their vendor-management programs.
- Submit comments. Banks, trade associations, and other stakeholders should consider submitting comments, particularly on whether the proposals strike the right balance between flexibility and supervisory expectations. Legal and government-affairs teams should coordinate internally to identify priorities for comment.
Looking Ahead
Comments on the proposed interagency guidance and community bank guide are due 60 days after publication in the Federal Register. Following the comment period, the agencies may issue final guidance reflecting stakeholder feedback. In the meantime, banks should expect increasing supervisory focus on risk-based tailoring and proportional oversight and consider whether their current third-party risk management programs align with these emerging expectations.
Our Bank Regulatory team is available to assist institutions in assessing and enhancing their third-party risk management programs to align with the agencies’ proposed framework and evolving supervisory expectations.