FINANCE, POLICY & MARKETSPublished by Paul Ivinskas
fc.The Financial CurrentDAILY INTELLIGENCEWhat matters across finance
Deep-dive library

Third-party services: innovation, continuity and the 2026 oversight proposal

7 min read · estimatedAI-generated analysis · Methodology
Current version · 3 versions · Publication details

First published . This version published .

Version history

What changed in this update

Broadened the article from a compliance checklist to service delivery, specialization and switching economics; replaced the merchant-finance-only illustration with payment and mortgage-service examples and reconfirmed proposed status.

Compare with an earlier version →
Related research, policy & entities ↓

At a glance

Excerpts from this version
What it covers
Outside providers help financial institutions deliver payments, technology and customer service. The 2026 proposal raises a practical question: how can oversight match the importance of each dependency while preserving the benefits of specialization?
Why it matters
The proposed text discusses tailoring oversight to the organization and the relationship, including monitoring intensity, termination and subcontractors. Risk can change over time, so the initial classification is not a permanent conclusion. A provider that once handled a minor workflow may become much more consequential after additional products depend on it.Read in context
Who it affects
A financial institution buys an outside service to gain something: specialist capability, a quicker launch, access to infrastructure or a lower cost of operating at scale.Read in context
Evidence to watch
At the bank level, a new product, provider incident, acquisition, concentration increase or failed exit test can justify reassessment before the next scheduled review.Read in context
0% through article

Tap a dotted-underlined term for a definition; terms are highlighted once per section. Use Aa in the navigation for reading preferences.

In this article

The business decision comes before the questionnaire

A financial institution buys an outside service to gain something: specialist capability, a quicker launch, access to infrastructure or a lower cost of operating at scale. Those benefits should be explicit. So should the dependency created when customer funds, transaction records or essential workflows rely on another organization.

Analysis: the useful comparison is between workable delivery options, including building internally, using a provider or changing the service offered. An internal platform also has cost, staffing and continuity risks. Outsourcing does not automatically improve resilience or weaken it; the result depends on the service, integration and ability to recover.

Status and scope

The Federal Reserve, FDIC, OCC and NCUA announced proposed third-party risk management guidance on September 11, 2026. The Federal Register notice published September 15 sets a November 16 comment deadline. The agencies intend to replace existing guidance when the new guidance is finalized; the proposal should not be treated as already final.

The September 11 joint announcement describes as non-binding. The OCC bulletin emphasizes relationship-specific risk assessment and says the proposal does not create enforceable standards. That distinction matters: a checklist in guidance and an obligation in a statute, regulation or contract are different sources of authority.

The operating change is differentiation

The proposed text discusses tailoring oversight to the organization and the relationship, including monitoring intensity, termination and subcontractors. Risk can change over time, so the initial classification is not a permanent conclusion. A provider that once handled a minor workflow may become much more consequential after additional products depend on it.

Analysis: start with the activity and failure consequence. A vendor’s annual invoice is a poor stand-in for the damage caused by lost transaction records, erroneous credit decisions or an unavailable servicing channel. Record why the selected oversight is adequate for the dependency actually created.

A practical evidence map

The following is an analytical control design, not an agency-mandated checklist. Each item should have an owner and evidence that can be reproduced.

Scroll horizontally to see all columns.

QuestionUseful evidenceReason it matters
What can fail?Workflow and data-flow mapReveals customer and financial consequences
Who can correct it?Escalation authority and response recordsAvoids responsibility gaps
Can the service be replaced?Tested data export and transition estimateMeasures concentration and exit risk
Is performance deteriorating?Exceptions, complaints and control resultsTests whether the original risk tier still fits

The core-provider statement is separate

OCC Bulletin 2026-47 describes an issued statement about supervision of certain core-provider services to community banks. It addresses how the agencies consider aspects of those relationships and their supervisory and enforcement authorities. It should be read alongside, not collapsed into, the broader proposed guidance.

Analysis: limited negotiating power is a reason to document compensating controls and escalation choices. It is not evidence that service dependence disappeared. A bank can distinguish a contract term it cannot obtain from an operational control it can still test.

Compare total delivery cost and switching difficulty

Hypothetical annual comparison: building a service internally costs $1.2 million. A provider charges $600,000, but integration, vendor management and retained support add $350,000, giving a $950,000 recurring cost. If migration costs $400,000 once, the first-year total is $1.35 million. The recurring saving is $250,000, so simple payback is 1.6 years if savings remain stable. This ignores discounting, service differences, volume growth and any later exit expense.

Analysis: this does not decide whether outsourcing is preferable. It makes the comparison reviewable. A more capable external service could justify a higher cost; a cheaper service could be a poor choice if switching is difficult and recovery is unproven. Institutions and vendors both benefit from agreeing on the evidence that matters for the particular service instead of repeatedly requesting unrelated documentation.

Illustrative applications: payments and mortgage servicing

Hypothetical payment service: a bank’s processor reports that an instruction was accepted, while the customer channel labels it completed before settlement confirmation arrives. Each provider can meet its own narrow response-time target while the overall service gives a misleading result. Testing the complete payment journey, including rejection and correction, can reveal the gap.

Hypothetical mortgage service: an outage prevents staff from viewing a borrower’s recent payment and escrow record. Moving to another interface is not enough if the alternative lacks usable data and transaction history. Recovery depends on reconstructing the customer’s position and providing accurate assistance, not simply restoring a login screen.

These examples illustrate service dependencies; they are not reports of actual incidents or agency-prescribed tests. They show why uptime, accurate records, timely completion and effective customer support are different measures.

Trade-offs and evidence that would change the view

Analysis: proportionate oversight can reduce low-value work and improve attention to consequential exposures. It can also fail if optimistic risk ratings become a reason to stop gathering evidence. Review whether resources actually moved toward higher-impact relationships and whether incident detection improved.

Revisit this article when final guidance changes the text, the comment deadline is amended, or authoritative interpretation clarifies scope. At the bank level, a new product, provider incident, acquisition, concentration increase or failed exit test can justify reassessment before the next scheduled review.

Prioritize by consequence, not questionnaire length

Recommended triage uses three questions: what can fail, how many customers or obligations would be affected, and how quickly the bank can detect and recover. A low-cost data feed can be critical if it determines every payment destination; an expensive research subscription can be much less consequential.

Document the justification for the oversight tier and the trigger for reassessment. Avoid multiplying arbitrary scores into a falsely precise answer. A severe but plausible failure with no workable substitute deserves attention even when its historical incident count is zero. The following matrix is an analytical aid, not a mandated rating system.

Scroll horizontally to see all columns.

DependencyEvidence to prioritizeDecision if evidence is weak
Customer funds or balancesIndependent reconciliation and usable recordsLimit growth; prove recovery before expansion
Credit decisions or noticesVersion control and decision reconstructionConstrain use and validate changed outputs
Sensitive informationAccess, retention and incident escalationReduce data access or pause transfer
Time-critical serviceRecovery test and alternative capacityReduce commitments that exceed tested recovery
Replaceable low-impact serviceBasic ownership and contractual exitUse proportionate periodic review

An evidence gap needs a disposition

A vendor may decline a document because of confidentiality, limited negotiating power or shared-service constraints. Recommended practice is to record what question remains unanswered, what substitute evidence was considered and who accepted the residual exposure. “Vendor declined” is a fact, not a control.

For example, a generic assurance report may not demonstrate that the bank can reconstruct its own customer balances. A targeted data export and reconciliation exercise may answer that narrower question more directly. Conversely, a successful export does not prove that security controls are adequate. Match each evidence item to the failure it can actually test.

Make the exit clause operational

Hypothetical exercise: assume a provider becomes unavailable on a Friday and cannot supply staff assistance. Retrieve bank-controlled data, reconstruct the last reliable position, identify unsettled transactions and communicate service limits. Measure the elapsed time and exceptions rather than recording only that an exit plan exists.

Then compare those results with contractual access rights and the promises made to customers. If the contract permits termination but the migration requires unavailable proprietary support, the exit is incomplete. Define a remediation owner, a decision date and interim limits. This is a recommended operating discipline; the September proposal does not itself impose the particular exercise or timing used here. Revisit the legal baseline only when an authoritative final action changes it.

Judge proportionality by the service delivered

The September 2026 interagency document remains a proposal with a November 16 comment deadline in the Federal Register notice checked for this revision. Its status is separate from the already issued core-provider statement discussed above. Neither should be turned into a universal list of identical requirements for every supplier. [1][2][4]

Analysis: success means better delivery and a clearer understanding of consequential dependencies, with review effort concentrated where failure would matter most. Evidence of shorter launches, fewer unresolved service failures and workable transitions would support that conclusion. Cutting review effort while losing sight of customer-impacting dependencies would not.

Sources

  1. Federal Reserve — September 11 interagency announcementOfficial releaseBack to text: ↑
  2. Federal Register — proposed third-party guidance, September 15Official sourceBack to text: ↑
  3. OCC Bulletin 2026-46 — proposed guidanceOfficial source
  4. OCC Bulletin 2026-47 — core service providersOfficial sourceBack to text: ↑

Flag an error or suggest a correction →Public corrections log →