Status and scope
The Federal Reserve, FDIC, OCC and NCUA announced proposed third-party risk management guidance on September 11, 2026. The Federal Register notice published September 15 sets a November 16 comment deadline. The agencies intend to replace existing guidance when the new guidance is finalized; the proposal should not be treated as already final.
The September 11 joint announcement describes as non-binding. The OCC bulletin emphasizes relationship-specific risk assessment and says the proposal does not create enforceable standards. That distinction matters: a checklist in guidance and an obligation in a statute, regulation or contract are different sources of authority.
The operating change is differentiation
The proposed text discusses tailoring oversight to the organization and the relationship, including monitoring intensity, termination and subcontractors. Risk can change over time, so the initial classification is not a permanent conclusion. A provider that once handled a minor workflow may become much more consequential after additional products depend on it.
Analysis: start with the activity and failure consequence. A vendor’s annual invoice is a poor stand-in for the damage caused by lost transaction records, erroneous credit decisions or an unavailable servicing channel. Record why the selected oversight is adequate for the dependency actually created.
A practical evidence map
The following is an analytical control design, not an agency-mandated checklist. Each item should have an owner and evidence that can be reproduced.
Scroll horizontally to see all columns.
| Question | Useful evidence | Reason it matters |
|---|---|---|
| What can fail? | Workflow and data-flow map | Reveals customer and financial consequences |
| Who can correct it? | Escalation authority and response records | Avoids responsibility gaps |
| Can the service be replaced? | Tested data export and transition estimate | Measures concentration and exit risk |
| Is performance deteriorating? | Exceptions, complaints and control results | Tests whether the original risk tier still fits |
The core-provider statement is separate
OCC Bulletin 2026-47 describes an issued statement about supervision of certain core-provider services to community banks. It addresses how the agencies consider aspects of those relationships and their supervisory and enforcement authorities. It should be read alongside, not collapsed into, the broader proposed guidance.
Analysis: limited negotiating power is a reason to document compensating controls and escalation choices. It is not evidence that service dependence disappeared. A bank can distinguish a contract term it cannot obtain from an operational control it can still test.
Illustrative application: a merchant-finance platform
Assume a fictional bank uses one provider for application routing and a different provider for statements. The routing provider changes its decision payload; the servicing platform then receives an incomplete loan record. An annual vendor review could look satisfactory while this cross-provider failure remains invisible.
A useful response would trace one transaction from application through booking, funding, customer communication and correction. The bank would identify the source of truth, stop conditions and reconciliation owner. Testing that chain may provide more assurance than collecting another generic assurance report from each vendor separately.
Trade-offs and evidence that would change the view
Analysis: proportionate oversight can reduce low-value work and improve attention to consequential exposures. It can also fail if optimistic risk ratings become a reason to stop gathering evidence. Review whether resources actually moved toward higher-impact relationships and whether incident detection improved.
Revisit this article when final guidance changes the text, the comment deadline is amended, or authoritative interpretation clarifies scope. At the bank level, a new product, provider incident, acquisition, concentration increase or failed exit test can justify reassessment before the next scheduled review.
Prioritize by consequence, not questionnaire length
Recommended triage uses three questions: what can fail, how many customers or obligations would be affected, and how quickly the bank can detect and recover. A low-cost data feed can be critical if it determines every payment destination; an expensive research subscription can be much less consequential.
Document the justification for the oversight tier and the trigger for reassessment. Avoid multiplying arbitrary scores into a falsely precise answer. A severe but plausible failure with no workable substitute deserves attention even when its historical incident count is zero. The following matrix is an analytical aid, not a mandated rating system.
Scroll horizontally to see all columns.
| Dependency | Evidence to prioritize | Decision if evidence is weak |
|---|---|---|
| Customer funds or balances | Independent reconciliation and usable records | Limit growth; prove recovery before expansion |
| Credit decisions or notices | Version control and decision reconstruction | Constrain use and validate changed outputs |
| Sensitive information | Access, retention and incident escalation | Reduce data access or pause transfer |
| Time-critical service | Recovery test and alternative capacity | Reduce commitments that exceed tested recovery |
| Replaceable low-impact service | Basic ownership and contractual exit | Use proportionate periodic review |
An evidence gap needs a disposition
A vendor may decline a document because of confidentiality, limited negotiating power or shared-service constraints. Recommended practice is to record what question remains unanswered, what substitute evidence was considered and who accepted the residual exposure. “Vendor declined” is a fact, not a control.
For example, a generic assurance report may not demonstrate that the bank can reconstruct its own customer balances. A targeted data export and reconciliation exercise may answer that narrower question more directly. Conversely, a successful export does not prove that security controls are adequate. Match each evidence item to the failure it can actually test.
Make the exit clause operational
Hypothetical exercise: assume a provider becomes unavailable on a Friday and cannot supply staff assistance. Retrieve bank-controlled data, reconstruct the last reliable position, identify unsettled transactions and communicate service limits. Measure the elapsed time and exceptions rather than recording only that an exit plan exists.
Then compare those results with contractual access rights and the promises made to customers. If the contract permits termination but the migration requires unavailable proprietary support, the exit is incomplete. Define a remediation owner, a decision date and interim limits. This is a recommended operating discipline; the September proposal does not itself impose the particular exercise or timing used here. Revisit the legal baseline only when an authoritative final action changes it.
Sources
- Federal Reserve — September 11 interagency announcementOfficial release
- Federal Register — proposed third-party guidance, September 15Official source
- OCC Bulletin 2026-46 — proposed guidanceOfficial source
- OCC Bulletin 2026-47 — core service providersOfficial source