Proposed Interagency Guidance Refocuses Third-Party Risk Management on Risk
On September 11, 2026, the Federal Deposit Insurance Corporation (FDIC), Office of the Comptroller of the Currency (OCC), Board of Governors of the Federal Reserve System (Federal Reserve), and National Credit Union Administration (NCUA) issued proposed interagency guidance that would replace the 2023 Interagency Guidance on Third-Party Relationships: Risk Management. The FDIC, OCC, and Federal Reserve also issued a Joint Statement on Community Banks’ Engagement with Core Service Providers.
The proposal reflects a shift in regulatory emphasis, not in accountability. Financial institutions would remain responsible for managing third-party risks and complying with applicable laws and regulations. However, the agencies acknowledge that the 2023 guidance has sometimes been applied too broadly and without sufficient consideration of the risk presented by each relationship. The proposed guidance is intended to reinforce a more tailored, principles-based approach.
A More Tailored, Risk-Based Approach
The central theme of the proposal is proportionality. Third-party risk management practices should be commensurate with the reasonably assessed risk of each relationship and tailored to the institution’s size, complexity, and risk profile. The agencies also caution against overly process-driven programs that treat all third-party relationships as inherently high risk.
In practice, institutions would continue to devote greater attention and resources to relationships that present material operational, compliance, financial, cybersecurity, or strategic risk. Oversight of lower-risk relationships could be scaled accordingly. For community and regional institutions, this approach may provide greater flexibility to focus limited resources on the relationships that matter most, including core processors, cloud providers, payment processors, and other critical service providers.
Focus on Core Service Providers
The Joint Statement addresses how community banks engage with core service providers and identifies factors the federal banking agencies will consider when making supervisory and enforcement decisions related to those services.
The statement is particularly relevant because community banks often rely on a concentrated group of core providers for essential functions such as deposit processing, lending, digital banking, and payments.
Although institutions may have limited leverage or visibility within complex provider environments, they remain responsible for understanding and managing the risks arising from those relationships.
The statement indicates that the agencies intend to consider the practical realities of core provider arrangements when determining the appropriate level of supervisory oversight.
What Financial Institutions Should Consider Now
The proposal is not yet final, and institutions should avoid making wholesale program changes at this stage. It does, however, provide an opportunity to assess whether current third-party risk management practices are appropriately aligned with risk.
Institutions should first evaluate whether their risk-tiering methodology clearly distinguishes critical and higher-risk relationships from those presenting lower risk. Due diligence, contracting, ongoing monitoring, and reporting expectations should be demonstrably linked to those risk assessments.
Institutions should also identify requirements that have become primarily process-driven, including activities performed uniformly across vendors without regard to their risk, criticality, or potential impact. A well-designed program should produce timely, meaningful risk information and enable management and the board to identify emerging risks, prioritize resources, and respond to significant issues. Institutions should consider whether each due diligence, monitoring, and documentation requirement informs a risk decision, satisfies a legal or regulatory obligation, or supports effective oversight. Requirements that do not serve one of these purposes may warrant reconsideration or refinement.
For core service providers, institutions should confirm that governance processes address the risks they can reasonably assess and manage. This includes understanding the services provided, reviewing available assurance reports and other due diligence materials, monitoring performance and incidents, evaluating business continuity considerations, and escalating significant concerns to management and the board.
One principle remains unchanged: outsourcing an activity does not transfer accountability. Institutions remain responsible for operating safely and soundly, protecting customer information, and complying with applicable requirements, regardless of whether an activity is performed internally or by a third party.
Looking Ahead
Comments on the proposed guidance are due November 16, 2026. If finalized, the guidance would replace the 2023 interagency guidance and certain supplemental third-party risk management resources. Because the proposal remains subject to change, institutions should continue to follow existing guidance while monitoring the rulemaking process.
The proposal signals that the agencies are responding to concerns about the burden created by overly broad or uniform interpretations of third-party risk management expectations. The fundamental obligation to manage third-party risk remains intact, but the proposed framework places greater emphasis on judgment, proportionality, and the effective allocation of resources.
Disclaimer of Liability: This publication is intended to provide general information to our clients and friends. It does not constitute accounting, tax, investment, or legal advice; nor is it intended to convey a thorough treatment of the subject matter.