Regulasyon
Banking Agencies Propose Replacing 2023 Third-Party Risk Guidance

The Federal Deposit Insurance Corporation, the Federal Reserve Board, the National Credit Union Administration, and the Office of the Comptroller of the Currency on Setyembre 11, 2026 requested public comment on proposed guidance to assist financial institutions with managing risks associated with third-party relationships. The proposal focuses on a principles-based approach and, as with all supervisory guidance, is non-binding, according to the agencies’ joint announcement, issued for release at 10:00 a.m. EDT. When finalized, the federal bank regulatory agencies plan to rescind existing third-party risk management guidance and replace it with the finalized version to promote consistency and prudent innovation in the banking industry.
Comments on the proposed guidance are due 60 days after publication in the Federal Register. The joint notice carries docket identifiers OCC-2026-0793 for the OCC, OP-1881 for the Board, RIN 3064-ZA58 for the FDIC, and NCUA-2026-1684 for the NCUA.
Separately the same day, the Board, the FDIC, and the OCC issued a statement on community banks’ engagement with core service providers, and the Federal Reserve Board requested comment on a proposed third-party risk management guide specifically for the community banks it supervises, intended as a companion document to the broader proposal.
Proposed Replacement for the 2023 Framework
According to the Federal Register notice, any finalized guidance would replace the Interagency Guidance on Third-Party Relationships: Risk Management published in 2023 (88 FR 37920, Hunyo 9, 2023), along with the Supplemental TPRM Resources: the OCC’s Mayo 15, 2002 bulletin on foreign-based third-party service providers, the Hulyo 25, 2024 joint statement on banks’ arrangements with third parties to deliver bank deposit products, and the Mayo 3, 2024 guide Third-Party Risk Management: A Guide for Community Banks.
The agencies wrote that, based on stakeholder feedback and supervisory experience, the 2023 Guidance has frequently been interpreted in an overly broad manner and with insufficient focus on tailoring; that its extensive considerations and detailed examples proved difficult to apply across different types of relationships; that it unintentionally incentivized process-driven, check-the-box approaches over risk-focused practices; and that it has been read to discourage arrangements with newer and innovative third parties.
The proposed guidance presents four components: risk identification and assessment; risk oversight, covering due diligence and third-party selection, contract negotiation, ongoing monitoring, termination, and cross-cutting topics; residual risk acceptance; and governance. Risk assessments would account for both the magnitude of harm a relationship could cause and the likelihood that the harm will occur. Higher-risk relationships could include those that, if disrupted, subjected to attack, conducted in breach of contract, or otherwise performed under non-business-as-usual circumstances, could cause an actual non-trivial violation of law or regulation, material harm to the banking organization’s financial condition, or significant disruption to its operations or customers, where there is a material likelihood of such outcomes under current or reasonably foreseeable conditions.
The notice states that the guidance sets forth no enforceable standards or prescriptive requirements, that non-compliance will not result in supervisory action, and that deviation from the guidance or its examples alone would not be a basis for supervisory action or an adverse examiner finding. It adds that the agencies may still take action for violations of laws or regulations, unsafe or unsound practices, or other material risks that result from insufficient management of third-party risk. The text also states the agencies will give due consideration to a banking organization’s reasonable decisions in matters of third-party risk management supervision.
The agencies state the proposal would encourage responsible innovation consistent with Executive Order 14405 on integrating financial technology innovation into regulatory frameworks. The Office of Information and Regulatory Affairs determined the proposal is not a significant regulatory action under Executive Order 12866, and the notice states that, if finalized as proposed, it is expected to be a deregulatory action under Executive Order 14192 because it would provide supervisory clarity that may result in greater efficiencies and streamlining in third-party risk management functions.
Among its specific questions, the notice asks whether the guidance should apply only to third parties subject to a written agreement with the banking organization, and whether it would be helpful to include a list of characteristics that generally indicate that a third-party relationship is high risk.
Core Providers, Community Banks, and the Board Vote
The joint statement on community banks’ engagement with core service providers addresses community banking organizations’ relationships with third parties that provide the critical systems applications and infrastructure supporting their essential functions, including transaction processing, account management, payments processing, customer relationship management, compliance and reporting, and online banking. The agencies state that a significant percentage of the core provider market is represented by just a few large providers, which limits community banks’ negotiating power, and that community banks report challenges obtaining reasonable due diligence information, negotiating contract terms, and conducting effective ongoing monitoring.
The statement identifies three sets of factors the agencies will consider when making supervisory allocation decisions for core providers, such as the nature, extent, and frequency of examinations. Transparency factors include a provider’s willingness to supply reasonably relevant and timely due diligence information, its use of and compliance with service level agreements carrying measurable performance standards, timely disclosure of operational issues and security incidents, and complex billing practices that are difficult to reconcile to services received. Contract-feature factors include opaque pricing structures, extensive back billing windows during which a provider may issue retroactive charges, unsupported or contractually undefined deconversion fees, and excessive limitations on unaffiliated service providers integrating with the core platform. Technology factors include the number and severity of computer security incidents, management of end-of-support and end-of-life assets, and demonstrated operational resilience capabilities.
On enforcement, the agencies state they may have a reasonable basis to determine that certain core providers qualify as institution-affiliated parties under 12 U.S.C. 1813(u)(3), as persons who participate in the conduct of the affairs of an insured depository institution, and that they may bring actions against core providers under statutory authorities including 12 U.S.C. 1818 and 1867. The statement says this does not eliminate or reduce a community bank’s own responsibility for safe and sound practices and compliance with applicable laws and regulations. The statement follows agency outreach that included an OCC request for information on community banks’ engagement with core service providers, published Nobyembre 28, 2025 (90 FR 54882).
The Board’s proposed guide for traditional community banking organizations, filed as Docket OP-1880, defines that group as banking organizations with less than $30 billion in assets that focus on serving their local communities. It is not intended for organizations with more complex business models or third-party relationship profiles, such as complex bank-fintech partnerships. The guide’s first section discusses four overarching topics: operational resilience, system and information security, compliance with rules and regulations, and financial resilience. Its second section addresses eight vendor categories: core service providers, information technology infrastructure providers, cybersecurity providers, payment processing and digital banking providers, loan management system providers, card issuing and processing providers, Bank Secrecy Act/anti-money laundering and financial crime platform providers, and fraud prevention and detection providers. The Board states the guide would not be a rule and that banking organizations would not be required to take the actions described, and it asks commenters whether the guide’s level of detail is calibrated to remain useful without establishing de facto supervisory standards.
A Board staff memo dated Agosto 28, 2026 recommended issuing both proposals and lists the Board documents the agencies would rescind alongside final guidance: the 2023 Guidance, issued through SR 23-4; the 2024 community bank guide, issued through SR 24-2/CA 24-1; and the joint statement on banks’ arrangements with third parties to deliver bank deposit products and services, issued through SR 24-5. The FDIC and NCUA signature blocks on the joint Federal Register notice are dated Setyembre 10, 2026.
The Board approved the package on Setyembre 9, 2026, per the Board’s voting record, which categorizes the action as proposed guidance. Chairman Warsh, Vice Chair Jefferson, Vice Chair for Supervision Bowman, Governor Cook, Governor Powell, and Governor Waller voted in favor. Governor Barr voted against; there were no abstentions.
In a dissenting statement, Barr said the interagency guidance incorporates a new material financial risk standard for supervisors to take action, which he argued makes it less likely that banks will correct problems before they become material risks to the firm. He wrote that the proposal’s due consideration language “may be misinterpreted to mean agencies will give deference to the bank’s views on third-party risk management, rather than making an independent judgment.” He also objected that the proposals exclude consumer compliance matters, which he said could leave a gap in risk coverage or require banks to comply with two sets of guidance, and that the community bank guide does not address complex bank-fintech partnerships.
Governor Cook said in a separate statement that she supported taking a fresh look at the guidance as banks manage larger, more complex vendor relationships. She welcomed comments on whether the agencies should provide greater specificity on effective risk management practices relating to cybersecurity and on the allocation of responsibilities for consumer protection, record management, and anti-money laundering in bank-fintech partnerships, and she said she strongly supported the proposed guide for traditional community banking organizations.












