The business decision comes before the questionnaire
A financial institution buys an outside service to gain something: specialist capability, a quicker launch, access to infrastructure or a lower cost of operating at scale. Those benefits should be explicit. So should the dependency created when customer funds, transaction records or essential workflows rely on another organization.
Analysis: the useful comparison is between workable delivery options, including building internally, using a provider or changing the service offered. An internal platform also has cost, staffing and continuity risks. Outsourcing does not automatically improve resilience or weaken it; the result depends on the service, integration and ability to recover.
Status and scope
The Federal Reserve, FDIC, OCC and NCUA announced proposed third-party risk management guidance on September 11, 2026. The Federal Register notice published September 15 sets a November 16 comment deadline. The agencies intend to replace existing guidance when the new guidance is finalized; the proposal should not be treated as already final.
The September 11 joint announcement describes as non-binding. The OCC bulletin emphasizes relationship-specific risk assessment and says the proposal does not create enforceable standards. That distinction matters: a checklist in guidance and an obligation in a statute, regulation or contract are different sources of authority.
The operating change is differentiation
The proposed text discusses tailoring oversight to the organization and the relationship, including monitoring intensity, termination and subcontractors. Risk can change over time, so the initial classification is not a permanent conclusion. A provider that once handled a minor workflow may become much more consequential after additional products depend on it.
Analysis: start with the activity and failure consequence. A vendor’s annual invoice is a poor stand-in for the damage caused by lost transaction records, erroneous credit decisions or an unavailable servicing channel. Record why the selected oversight is adequate for the dependency actually created.
A practical evidence map
The following is an analytical control design, not an agency-mandated checklist. Each item should have an owner and evidence that can be reproduced.
Scroll horizontally to see all columns.
| Question | Useful evidence | Reason it matters |
|---|---|---|
| What can fail? | Workflow and data-flow map | Reveals customer and financial consequences |
| Who can correct it? | Escalation authority and response records | Avoids responsibility gaps |
| Can the service be replaced? | Tested data export and transition estimate | Measures concentration and exit risk |
| Is performance deteriorating? | Exceptions, complaints and control results | Tests whether the original risk tier still fits |
The core-provider statement is separate
OCC Bulletin 2026-47 describes an issued statement about supervision of certain core-provider services to community banks. It addresses how the agencies consider aspects of those relationships and their supervisory and enforcement authorities. It should be read alongside, not collapsed into, the broader proposed guidance.
Analysis: limited negotiating power is a reason to document compensating controls and escalation choices. It is not evidence that service dependence disappeared. A bank can distinguish a contract term it cannot obtain from an operational control it can still test.
Compare total delivery cost and switching difficulty
Hypothetical annual comparison: building a service internally costs $1.2 million. A provider charges $600,000, but integration, vendor management and retained support add $350,000, giving a $950,000 recurring cost. If migration costs $400,000 once, the first-year total is $1.35 million. The recurring saving is $250,000, so simple payback is 1.6 years if savings remain stable. This ignores discounting, service differences, volume growth and any later exit expense.
Analysis: this does not decide whether outsourcing is preferable. It makes the comparison reviewable. A more capable external service could justify a higher cost; a cheaper service could be a poor choice if switching is difficult and recovery is unproven. Institutions and vendors both benefit from agreeing on the evidence that matters for the particular service instead of repeatedly requesting unrelated documentation.
Illustrative applications: payments and mortgage servicing
Hypothetical payment service: a bank’s processor reports that an instruction was accepted, while the customer channel labels it completed before settlement confirmation arrives. Each provider can meet its own narrow response-time target while the overall service gives a misleading result. Testing the complete payment journey, including rejection and correction, can reveal the gap.
Hypothetical mortgage service: an outage prevents staff from viewing a borrower’s recent payment and escrow record. Moving to another interface is not enough if the alternative lacks usable data and transaction history. Recovery depends on reconstructing the customer’s position and providing accurate assistance, not simply restoring a login screen.
These examples illustrate service dependencies; they are not reports of actual incidents or agency-prescribed tests. They show why uptime, accurate records, timely completion and effective customer support are different measures.
Trade-offs and evidence that would change the view
Analysis: proportionate oversight can reduce low-value work and improve attention to consequential exposures. It can also fail if optimistic risk ratings become a reason to stop gathering evidence. Review whether resources actually moved toward higher-impact relationships and whether incident detection improved.
Revisit this article when final guidance changes the text, the comment deadline is amended, or authoritative interpretation clarifies scope. At the bank level, a new product, provider incident, acquisition, concentration increase or failed exit test can justify reassessment before the next scheduled review.
Prioritize by consequence, not questionnaire length
Recommended triage uses three questions: what can fail, how many customers or obligations would be affected, and how quickly the bank can detect and recover. A low-cost data feed can be critical if it determines every payment destination; an expensive research subscription can be much less consequential.
Document the justification for the oversight tier and the trigger for reassessment. Avoid multiplying arbitrary scores into a falsely precise answer. A severe but plausible failure with no workable substitute deserves attention even when its historical incident count is zero. The following matrix is an analytical aid, not a mandated rating system.
Scroll horizontally to see all columns.
| Dependency | Evidence to prioritize | Decision if evidence is weak |
|---|---|---|
| Customer funds or balances | Independent reconciliation and usable records | Limit growth; prove recovery before expansion |
| Credit decisions or notices | Version control and decision reconstruction | Constrain use and validate changed outputs |
| Sensitive information | Access, retention and incident escalation | Reduce data access or pause transfer |
| Time-critical service | Recovery test and alternative capacity | Reduce commitments that exceed tested recovery |
| Replaceable low-impact service | Basic ownership and contractual exit | Use proportionate periodic review |
An evidence gap needs a disposition
A vendor may decline a document because of confidentiality, limited negotiating power or shared-service constraints. Recommended practice is to record what question remains unanswered, what substitute evidence was considered and who accepted the residual exposure. “Vendor declined” is a fact, not a control.
For example, a generic assurance report may not demonstrate that the bank can reconstruct its own customer balances. A targeted data export and reconciliation exercise may answer that narrower question more directly. Conversely, a successful export does not prove that security controls are adequate. Match each evidence item to the failure it can actually test.
Make the exit clause operational
Hypothetical exercise: assume a provider becomes unavailable on a Friday and cannot supply staff assistance. Retrieve bank-controlled data, reconstruct the last reliable position, identify unsettled transactions and communicate service limits. Measure the elapsed time and exceptions rather than recording only that an exit plan exists.
Then compare those results with contractual access rights and the promises made to customers. If the contract permits termination but the migration requires unavailable proprietary support, the exit is incomplete. Define a remediation owner, a decision date and interim limits. This is a recommended operating discipline; the September proposal does not itself impose the particular exercise or timing used here. Revisit the legal baseline only when an authoritative final action changes it.
Judge proportionality by the service delivered
The September 2026 interagency document remains a proposal with a November 16 comment deadline in the Federal Register notice checked for this revision. Its status is separate from the already issued core-provider statement discussed above. Neither should be turned into a universal list of identical requirements for every supplier. [1][2][4]
Analysis: success means better delivery and a clearer understanding of consequential dependencies, with review effort concentrated where failure would matter most. Evidence of shorter launches, fewer unresolved service failures and workable transitions would support that conclusion. Cutting review effort while losing sight of customer-impacting dependencies would not.
Sources
- Federal Reserve — September 11 interagency announcementOfficial releaseBack to text: ↑
- Federal Register — proposed third-party guidance, September 15Official sourceBack to text: ↑
- OCC Bulletin 2026-46 — proposed guidanceOfficial source
- OCC Bulletin 2026-47 — core service providersOfficial sourceBack to text: ↑