FINANCE, POLICY & MARKETSPublished by Paul Ivinskas
fc.The Financial CurrentDAILY INTELLIGENCEWhat matters across finance
Deep-dive library

Third-party services: innovation, continuity and the 2026 oversight proposal

5 min read · estimatedAI-generated analysis · Methodology
Historical version · 3 versions · Publication details

First published . This version published .

Version history

About this historical version

Added a consequence-based oversight matrix, explicit treatment of unavailable vendor evidence and a practical exit drill. Reconfirmed proposed status and the November 16 comment deadline; preserved earlier analysis.

Compare with an earlier version →
Related research, policy & entities ↓

At a glance

Excerpts from this version
What it covers
The September 2026 proposal favors risk-sensitive oversight but is not final. This revision adds a practical prioritization method, evidence-gap decisions and a contract-to-exit test for consequential providers.
0% through article

Tap a dotted-underlined term for a definition; terms are highlighted once per section. Use Aa in the navigation for reading preferences.

In this article

Status and scope

The Federal Reserve, FDIC, OCC and NCUA announced proposed third-party risk management guidance on September 11, 2026. The Federal Register notice published September 15 sets a November 16 comment deadline. The agencies intend to replace existing guidance when the new guidance is finalized; the proposal should not be treated as already final.

The September 11 joint announcement describes as non-binding. The OCC bulletin emphasizes relationship-specific risk assessment and says the proposal does not create enforceable standards. That distinction matters: a checklist in guidance and an obligation in a statute, regulation or contract are different sources of authority.

The operating change is differentiation

The proposed text discusses tailoring oversight to the organization and the relationship, including monitoring intensity, termination and subcontractors. Risk can change over time, so the initial classification is not a permanent conclusion. A provider that once handled a minor workflow may become much more consequential after additional products depend on it.

Analysis: start with the activity and failure consequence. A vendor’s annual invoice is a poor stand-in for the damage caused by lost transaction records, erroneous credit decisions or an unavailable servicing channel. Record why the selected oversight is adequate for the dependency actually created.

A practical evidence map

The following is an analytical control design, not an agency-mandated checklist. Each item should have an owner and evidence that can be reproduced.

Scroll horizontally to see all columns.

QuestionUseful evidenceReason it matters
What can fail?Workflow and data-flow mapReveals customer and financial consequences
Who can correct it?Escalation authority and response recordsAvoids responsibility gaps
Can the service be replaced?Tested data export and transition estimateMeasures concentration and exit risk
Is performance deteriorating?Exceptions, complaints and control resultsTests whether the original risk tier still fits

The core-provider statement is separate

OCC Bulletin 2026-47 describes an issued statement about supervision of certain core-provider services to community banks. It addresses how the agencies consider aspects of those relationships and their supervisory and enforcement authorities. It should be read alongside, not collapsed into, the broader proposed guidance.

Analysis: limited negotiating power is a reason to document compensating controls and escalation choices. It is not evidence that service dependence disappeared. A bank can distinguish a contract term it cannot obtain from an operational control it can still test.

Illustrative application: a merchant-finance platform

Assume a fictional bank uses one provider for application routing and a different provider for statements. The routing provider changes its decision payload; the servicing platform then receives an incomplete loan record. An annual vendor review could look satisfactory while this cross-provider failure remains invisible.

A useful response would trace one transaction from application through booking, funding, customer communication and correction. The bank would identify the source of truth, stop conditions and reconciliation owner. Testing that chain may provide more assurance than collecting another generic assurance report from each vendor separately.

Trade-offs and evidence that would change the view

Analysis: proportionate oversight can reduce low-value work and improve attention to consequential exposures. It can also fail if optimistic risk ratings become a reason to stop gathering evidence. Review whether resources actually moved toward higher-impact relationships and whether incident detection improved.

Revisit this article when final guidance changes the text, the comment deadline is amended, or authoritative interpretation clarifies scope. At the bank level, a new product, provider incident, acquisition, concentration increase or failed exit test can justify reassessment before the next scheduled review.

Prioritize by consequence, not questionnaire length

Recommended triage uses three questions: what can fail, how many customers or obligations would be affected, and how quickly the bank can detect and recover. A low-cost data feed can be critical if it determines every payment destination; an expensive research subscription can be much less consequential.

Document the justification for the oversight tier and the trigger for reassessment. Avoid multiplying arbitrary scores into a falsely precise answer. A severe but plausible failure with no workable substitute deserves attention even when its historical incident count is zero. The following matrix is an analytical aid, not a mandated rating system.

Scroll horizontally to see all columns.

DependencyEvidence to prioritizeDecision if evidence is weak
Customer funds or balancesIndependent reconciliation and usable recordsLimit growth; prove recovery before expansion
Credit decisions or noticesVersion control and decision reconstructionConstrain use and validate changed outputs
Sensitive informationAccess, retention and incident escalationReduce data access or pause transfer
Time-critical serviceRecovery test and alternative capacityReduce commitments that exceed tested recovery
Replaceable low-impact serviceBasic ownership and contractual exitUse proportionate periodic review

An evidence gap needs a disposition

A vendor may decline a document because of confidentiality, limited negotiating power or shared-service constraints. Recommended practice is to record what question remains unanswered, what substitute evidence was considered and who accepted the residual exposure. “Vendor declined” is a fact, not a control.

For example, a generic assurance report may not demonstrate that the bank can reconstruct its own customer balances. A targeted data export and reconciliation exercise may answer that narrower question more directly. Conversely, a successful export does not prove that security controls are adequate. Match each evidence item to the failure it can actually test.

Make the exit clause operational

Hypothetical exercise: assume a provider becomes unavailable on a Friday and cannot supply staff assistance. Retrieve bank-controlled data, reconstruct the last reliable position, identify unsettled transactions and communicate service limits. Measure the elapsed time and exceptions rather than recording only that an exit plan exists.

Then compare those results with contractual access rights and the promises made to customers. If the contract permits termination but the migration requires unavailable proprietary support, the exit is incomplete. Define a remediation owner, a decision date and interim limits. This is a recommended operating discipline; the September proposal does not itself impose the particular exercise or timing used here. Revisit the legal baseline only when an authoritative final action changes it.

Sources

  1. Federal Reserve — September 11 interagency announcementOfficial release
  2. Federal Register — proposed third-party guidance, September 15Official source
  3. OCC Bulletin 2026-46 — proposed guidanceOfficial source
  4. OCC Bulletin 2026-47 — core service providersOfficial source

Flag an error or suggest a correction →Public corrections log →