Insights
publication | BRG

Regulatory Alert: Federal Banking Agencies Propose Revised Third-Party Risk Management Guidance

October 5, 2026

Key Takeaway

Federal regulators have proposed replacing 2023 interagency third-party risk management guidance with a less-prescriptive framework. The proposal would give banks and credit unions more discretion to tailor oversight to the risks of each relationship. A separate joint statement explains how federal banking agencies will supervise core service providers to community banks.

The proposal does not replace the current guidance unless finalized. Comments are due by November 16, 2026.

Background

On September 11, four federal financial regulators requested comment on revised third-party risk management guidance: the Office of the Comptroller of the Currency (OCC), Federal Reserve Board, Federal Deposit Insurance Corporation (FDIC), and National Credit Union Administration (NCUA). The proposal was published in the Federal Register on September 15.

If finalized, the proposal would replace 2023 interagency guidance and rescind related supplemental resources. Until then, the original guidance remains in place. Financial institutions also remain responsible for outsourced activities and related risks when third parties perform services on their behalf.

The Federal Reserve separately proposed a The OCC, Federal Reserve, and FDIC also issued a joint statement on September 11 addressing community banks’ relationships with core service providers.

Proposed Third-Party Risk Management Guidance

The proposal responds to concerns that the 2023 guidance has been applied as a detailed checklist. It would establish four components:

  • Risk identification and assessment: Institutions would identify third-party relationships and assess the likelihood and magnitude of potential harm. The proposal removes the defined concept of “critical activities” and directs institutions to determine which relationships present greater risk.
  • Risk-based oversight: Due diligence, contract terms, monitoring, and termination planning would be tailored to each relationship. The proposal states that no contract terms apply universally, even for higher-risk relationships.
  • Residual risk acceptance: Institutions could accept risks that remain after controls are applied, provided those risks fit within their risk appetite and tolerances.
  • Governance: Institutions would establish clear responsibilities and oversight without following one prescribed governance model.

The agencies would give due consideration to an institution’s reasonable judgment. The proposal also recognizes that newer providers can support responsible innovation and some third-party risks cannot be eliminated.

Why This Matters

The proposal moves away from checklist-based reviews and gives institutions more discretion to focus on their highest-risk third-party relationships.

The joint statement has immediate relevance for community banks and core providers. The agencies will consider three areas when supervising core providers: transparency, contract practices, and technology capabilities. The agencies may also consider opaque pricing, high exit fees, integration restrictions, security weaknesses, and service disruptions when setting the nature and frequency of supervision.

The agencies may act against a core provider that causes a bank to engage in unsafe practices or violate the law. A provider may be treated as an institution-affiliated party and face direct enforcement action.

Greater flexibility will not remove accountability. Examiners still expect institutions to show how they identified material risks, selected controls, monitored performance, and accepted residual exposure.

Next Steps

Financial institutions should consider the following actions:

  • Assess the proposal: compare current policies and procedures with the proposed components and identify where documentation may need to change.
  • Maintain existing controls: avoid dismantling processes based on a proposal that is not finalized.
  • Review risk segmentation: test whether inventories and assessment methods distinguish higher-risk relationships using both likelihood and impact.
  • Evaluate core-provider relationships: review due diligence access, service levels, incident reporting, pricing, integration restrictions, renewal terms, and exit costs.
  • Prepare comments: consider whether the proposal provides enough clarity on reasonable judgment, residual risk, subcontractors, and examination expectations; submit comments by November 16.

Institutions should monitor the final guidance and related examination procedures before making significant program changes.

For further assistance on assessing the potential effects on your third-party risk management program, please reach out to our team.