Federal Banking Agencies and NCUA Propose New Approach to Third-Party Risk Management
On September 11, 2026, the Federal Reserve, OCC, FDIC, and—for the first time—NCUA jointly published proposed interagency guidance on third-party risk management (TPRM). The proposal would rescind and replace the existing 2023 Interagency Guidance on Third-Party Relationships: Risk Management (2023 Guidance), along with the supplemental resources the agencies have issued since then, including the 2024 Community Bank Guide and the 2024 Joint Statement on Banks' Arrangements with Third Parties to Deliver Bank Deposit Products. Comments on the proposal are due November 16, 2026.
The proposal would be a significant recalibration. The agencies acknowledge in the proposal that the 2023 Guidance was treated in practice as a prescriptive checklist by banking organizations and examiners alike, producing an overly process-driven compliance framework that failed to prioritize material risk. The proposal, instead, would use a principles-based approach focused on material relationships and risk.
A redline of the proposal against the 2023 Guidance shows at a high level that the proposal is a major rewriting of TPRM guidance by the agencies.
Key Takeaways
- "Critical activities" concept would be replaced by an assessment of the magnitude and likelihood of risk. The 2023 Guidance organized expectations around whether a third party supported a "critical activity," defined as an activity that could cause a banking organization to face significant risk if the third party fails to meet expectations, has significant customer impacts, or significantly affects a banking organization's financial condition or operations.
The proposal would abandon that term entirely. In its place, the agencies propose a holistic risk assessment focused on the magnitude of harm the relationship could cause (including non-trivial legal or regulatory violations, material financial harm, or significant operational disruption) and the likelihood that this harm would actually occur under current or reasonably foreseeable conditions. "Core" activities would be subject to separate considerations.
A banking organization would be able to reasonably conclude that a third-party relationship involving a "critical activity" under the 2023 Guidance is nevertheless lower risk if the probability of harm is low or mitigating controls reduce residual risk to acceptable levels.
- Scope of "third-party relationships" would be narrowed to only those underwritten agreements. The 2023 Guidance defined a third-party relationship broadly as "any business arrangement between a banking organization and another entity, by contract or otherwise," and expressly stated that a relationship could exist "despite a lack of a contract or remuneration."
The proposal would narrow this to "a business arrangement between a banking organization and an entity or individual for the provision of one or more products, services, and other activities that support the banking organization," and go further, noting that arrangements lacking a written agreement or clear consideration are "unlikely to constitute a third-party relationship."
The proposal would state that "the use of subcontractors alone does not typically create an independent third-party relationship or create a presumption of direct banking organization oversight of any subcontractors." This proposed change illustrates the larger effort by the agencies to rein in past regulatory overreach, as the 2023 Guidance held banking organizations responsible for the actions not only of third-party relationships, but also fourth- and fifth-party relationships.
- Fintech relationships would be reframed as sources of innovation, not always elevated risk. The agencies acknowledge the 2023 Guidance has been interpreted as discouraging bank-fintech partnerships. The proposal would take a different tone, describing fintechs as providers of "innovative services and solutions that enhance access to financial products and services and create economic opportunities."
- Residual risk would be acceptable. The proposal would plainly state that the agencies "do not expect banking organizations to eliminate third-party risk. Some residual risk is unavoidable." The proposal would further acknowledge that in some cases "the materiality of the risk does not justify the oversight required to significantly mitigate it" and that a necessary and beneficial third-party relationship may proceed even where the banking organization "cannot significantly mitigate a risk."
- The proposal would be expressly non-enforceable, and deference would be given to banking organizations. For the first time, the proposal would indicate that "non-compliance with this guidance will not result in supervisory action against a banking organization," and "[d]eviation from or inconsistency with this proposed guidance or any examples herein … will not alone be a basis for supervisory action." The proposal would also introduce explicit deference language, stating that "examiners will give due consideration to a banking organization's reasonable decisions in matters of third-party risk management supervision." This would be a remarkable change in examiner practice consistent with other supervisory changes at the agencies designed to limit regulatory discretion and give greater consideration of the actions of the business organizations they regulate.
What Would Change
- The life-cycle model would be replaced with a risk-management framework with specific components. The 2023 Guidance organized TPRM around a five-stage life cycle: Planning, Due Diligence and Third-Party Selection, Contract Negotiation, Ongoing Monitoring, and Termination, plus separate Governance and Supervisory Reviews sections. The 2026 proposal replaces this with four "Risk Management Components" that banking organizations may consider when managing third-party risk:
- identifying and accessing applicable risk;
- overseeing risks proportionate to their significance (which encompasses due diligence, contract negotiation, ongoing monitoring, and termination as sub-elements);
- making informed decisions about residual risks and risk acceptance; and
- establishing appropriate governance practices.
- Detailed lists would be removed and replaced with a principles-based approach. The 2023 Guidance included 17 enumerated contract-negotiation considerations and more than 15 ongoing-monitoring factors. The proposal would remove these and replace them with high-level principles and illustrative examples, indicating that there are no generally expected contract terms for third-party relationships as a supervisory matter. The proposal would emphasize that a banking organization may tailor contract negotiation and risk oversight to its size, complexity, and risk profile, as well as the nature of the third-party relationship.
- Governance provisions would be streamlined. The 2023 Guidance included detailed governance provisions, including specific references to the board's role in approving contracts for critical activities and the need for independent reviews. The proposal would significantly streamline governance expectations, stating there is "no one right way for a banking organization to structure" governance practices and that due to variations in size, complexity, and risk profile, "the agencies will give due consideration to a banking organization's reasonable governance considerations."
- Affiliates and regulated entities would get clearer treatment. The 2023 Guidance refused to assume lower risk for affiliates of banking organizations, stating that "affiliate relationships may not always present lower risks." The proposal would acknowledge that affiliate arrangements operating "within an organization-wide enterprise risk management framework with which the banking organization is familiar, may be lower-risk and can enable the banking organization to rely on alternative oversight mechanics such as staff overlaps." The proposal would also permit consideration of a third party's own regulatory status in the risk assessment, while appropriately cautioning that the "mere presence of a regulatory scheme may not necessarily serve to mitigate risks." Thus, a reasoned risk assessment would still be required but may take into consideration the overlap of staff and risk management obligations of third parties.
- Banking organizations would be encouraged to use shared assessments and third-party reviews. The 2023 Guidance cautioned against relying on supplemental due diligence performed by external parties, emphasizing that such diligence "does not abrogate the responsibility of the banking organization to manage third-party relationships in a safe and sound manner and consistent with applicable laws and regulations." While continuing to indicate that effective risk management must be based on the banking organization's own specific circumstances and performance criteria, the proposal would encourage banking organizations to leverage co-ventures, consortia, and standard-setting organizations to manage third-party risk, indicating that such arrangements and certifications could "create new efficiencies, provide banking organizations additional leverage in conducting due diligence on, negotiating with, or monitoring third parties, and facilitate access to new technologies and strategic expertise" and "may be adequate for a banking organization's due diligence needs, depending on facts and circumstances."
What Would Not Change
- Banking organizations would remain fully responsible for third-party risk. The proposal would reiterate that a banking organization's use of third parties "does not diminish its responsibility to meet [safety and soundness and legal compliance] requirements to the same extent as if the activities were performed by the banking organization internally."
- Higher-risk relationships would still require rigorous oversight. Core service providers, for example, would be identified in the proposal as "likely to be assessed by most banking organizations as higher risk." Combined with the Joint Statement on Community Banks' Engagement with Core Service Providers, which is already effective, the proposal signals that the agencies will be far less tolerant of what might be perceived as non-"transparent" and "rigid" approaches of core service providers. The proposal's emphasis on proportionality would mean that higher-risk third-party relationships will continue to demand comprehensive due diligence, detailed contract provisions, and robust ongoing monitoring. The agencies seek comment on whether the interagency guidance should include a list of characteristics that generally indicate that a third-party relationship is high risk, and, if so, what characteristics should be included in the list.
Federal Reserve's Proposed TPRM Guide for So-Called "Traditional Community Banking Organizations"
Separately, the Federal Reserve published a proposed guide on TPRM for "traditional community banking organizations" (TCBOs). The guide is intended to help banking organizations supervised by the Federal Reserve with less than $30 billion in assets that focus on serving their local communities implement the principles articulated in the proposed interagency guidance on TPRM that would still apply to them. The Federal Reserve, however, indicates that the proposed guide is not intended for TCBOs with more complex business models or third-party relationship profiles, such as complex bank-fintech partnerships, but provides no additional detail on the meaning of a "complex business model or third-party relationship profile." Comments on the proposed guide are due November 16, 2026.
The proposed guide is organized around two main sections. The proposed guide would first address four overarching risk management topics that the Federal Reserve views as highest priority for TCBOs across their third-party relationships:
- operational resilience,
- system and information security,
- compliance with rules and regulations, and
- financial resilience.
The proposed guide would then address the risk management topics across eight categories of third-party vendors that smaller banking organizations often engage with:
- core service providers,
- information technology infrastructure providers,
- cybersecurity providers,
- payment processing and digital banking providers,
- loan management system providers,
- card issuing and processing providers,
- Bank Secrecy Act/anti-money laundering and financial crime platform providers, and
- fraud prevention and detection providers,
and provide vendor-specific risk management considerations and, in some cases, guidance on transitioning to a new provider.
This proposed guide is meant to be complementary to the proposed interagency guidance and is understood to be an initiative of Vice Chair for Supervision Michelle Bowman. Whether TCBOs believe it distracts from the more general principles-based approach will likely play out in the comments.
Our Take
The proposed interagency guidance and the Federal Reserve's proposed guide for "traditional community banking organizations" are a welcome course correction. The result of the 2023 Guidance was a rigid, one-size-fits-all compliance framework that required banking organizations to devote enormous resources to check-the-box exercises across their entire vendor inventories, regardless of risk, while higher-risk relationships did not always receive the attention they deserved. The proposals' shift to a principles-based, risk-proportionate framework should allow banking organizations to better allocate resources, focusing on the relationships that pose material financial, operational, and legal risk. The new statements on non-enforcement and examiner deference to the considerations of the banking organizations should give banking organizations a stronger foundation to push back on supervisory findings in the appeals processes newly revised by the agencies.
For community banks in particular, the proposals could be transformative. Going forward, community banks will need to rely on third-party providers to keep up with (or keep close to) technological changes. The proposals expressly recognize that third parties can provide opportunities for innovation. The proposals would put smaller banking organizations in an improved position with their larger and more technologically sophisticated competitors. Under the 2023 Guidance, community banks faced the same sprawling compliance expectations as the largest institutions, despite having a fraction of the staff and resources. The result was that "too big to fail" actually became "too small to succeed" and the 2023 Guidance played a role in the shrinkage of the number of community banks by nearly 70%. The proposals would give smaller banking organizations the ability to direct resources towards the relationships that matter the most, including innovative fintech and technology partnerships that will allow these banking organizations to grow and succeed. In addition, the Joint Statement on Community Banks' Engagement with Core Service Providers should alleviate some of the pressure on community banks by requiring what the agencies view as greater cooperation by core service providers, whether or not such requirement is justified.
And third-party service providers stand to benefit as well. The removal of language that discouraged bank-fintech partnerships and the reframing of TPRM as a risk-based exercise rather than a risk-avoidance exercise should meaningfully reduce the compliance friction that made it difficult for technology companies—including digital asset and cryptocurrency firms—to establish and maintain relationships with banking organizations.
+++
Michael Treves is an associate and Max Bonici and Steve Gannon are partners in DWT's Washington, D.C., office. For questions or more insights, please reach out to the authors or another member of our financial services team. To stay informed, sign up for our alerts.