Regulatory Shift: Federal Agencies Propose New Framework for Third-Party Risk Management

regulatory-shift-federal-agencies-propose-new-framework-for-third-party-risk-management

By PYMNTS | September 11, 2026

In a significant move aimed at modernizing the regulatory landscape for the American financial sector, four major federal agencies have unveiled a comprehensive proposal to redefine how financial institutions oversee their third-party relationships. This initiative, announced on Friday, September 11, 2026, represents a concerted effort by the Federal Deposit Insurance Corp. (FDIC), the Federal Reserve Board, the National Credit Union Administration (NCUA), and the Office of the Comptroller of the Currency (OCC) to harmonize and update the oversight of vendors, service providers, and technological partners.

As the financial ecosystem grows increasingly reliant on outsourced technology, cloud computing, and specialized service providers, the complexity of managing these relationships has become a central challenge for banks and credit unions of all sizes. The proposed guidance seeks to move away from rigid, one-size-fits-all compliance models toward a more nuanced, risk-based approach.


Main Facts: A Unified Regulatory Front

The proposed guidance is a non-binding framework designed to provide financial institutions with a roadmap for assessing, monitoring, and managing the risks inherent in third-party engagements. By issuing this as a joint effort, the four agencies are signaling a move toward greater interagency consistency, which is expected to simplify the compliance burden for institutions that operate under the purview of multiple regulators.

Key objectives of the proposal include:

  • Risk-Based Tailoring: Encouraging institutions to align their oversight practices with the criticality and complexity of specific third-party relationships rather than applying uniform rigor to all vendors.
  • Modernization: Replacing existing, fragmented guidance with a cohesive set of principles that reflect the modern digital landscape.
  • Clarity on Core Providers: Providing explicit guidance on how banks should engage with core service providers, which are often the backbone of community banking operations.
  • Promotion of Innovation: By reducing the "overly broad" compliance burdens that often stifle smaller institutions, the agencies hope to foster an environment where responsible technological innovation can flourish.

The agencies have opened a 60-day public comment period following the publication of the proposal in the Federal Register. This window is a critical opportunity for industry stakeholders, consumer advocacy groups, and technology partners to shape the final policy.


Chronology: The Path to Regulatory Evolution

The announcement on September 11, 2026, is the culmination of years of internal deliberation and public discourse regarding the intersection of banking and technology.

  • Early 2020s: As the shift toward digital banking accelerated, regulators began noting that existing guidance—much of it drafted before the widespread adoption of cloud computing and fintech partnerships—was failing to capture the full spectrum of third-party risk.
  • Mid-2025: Regulatory scrutiny intensified following several high-profile service disruptions at major core technology providers, which left community banks unable to process transactions for days.
  • Early 2026: The agencies began holding closed-door roundtable discussions with community bank CEOs and FinTech leaders to identify the "pain points" in current oversight regimes.
  • September 11, 2026: The formal announcement of the proposed guidance and the release of the companion statement regarding core service providers, marking the beginning of the public comment phase.

Supporting Data: Why the Change Was Necessary

The reliance of the U.S. banking system on a concentrated group of core service providers is a well-documented systemic risk. Data suggests that a handful of companies provide the operating systems for the vast majority of American community banks.

When these providers experience outages or security breaches, the ripple effect is immediate. For a small credit union or community bank, a failure at the core processor can mean a total loss of digital services, including ATM access, online banking, and internal ledger management.

Furthermore, the "burden of compliance" has been a consistent theme in industry surveys. Smaller institutions frequently report that they spend a disproportionate amount of their capital and human resources on third-party due diligence that is often redundant or disconnected from the actual risk posed by the vendor. The proposed guidance aims to address this by allowing institutions to focus their resources on higher-risk relationships, such as those involving sensitive customer data or critical infrastructure, while streamlining the oversight of lower-risk, peripheral service providers.


Official Responses: Empowering Community Banks

The OCC, in particular, has been a vocal proponent of this shift, framing it as a strategy to empower community banks—the institutions that serve as the economic bedrock of local communities.

Comptroller of the Currency Jonathan V. Gould emphasized that the new guidance is intended to liberate these institutions from unnecessary administrative constraints. "We are giving these vital institutions more freedom to do what they do best—serve their customers, support local businesses, strengthen their communities, and drive economic growth across America," Gould stated in the official release.

The sentiment is echoed by the Federal Reserve, which simultaneously released a companion guide specifically for Federal Reserve-supervised community banks. This bespoke approach recognizes that while large, systemic institutions have vast teams to handle third-party risk management (TPRM), smaller community banks often lack the same bandwidth. By providing a "lite" version of the guidance, the Fed hopes to provide smaller banks with a manageable, effective framework for compliance.


Implications: The Future of Banking and FinTech

The implications of this proposal are far-reaching. By providing clearer, more modern standards, the agencies are essentially setting the rules of the road for the next decade of digital banking.

1. The Impact on FinTech Partnerships

FinTechs often struggle to integrate with traditional banks because of the stringent, and sometimes opaque, due diligence requirements imposed by bank legal and compliance departments. If this guidance successfully creates a more standardized, risk-based approach, it could significantly lower the barrier to entry for FinTechs looking to partner with regional and community banks.

2. Supervisory and Enforcement Clarity

One of the most anticipated aspects of the new framework is the clarity regarding how regulators will view core service providers. The joint statement from the Fed, FDIC, and OCC clarifies that the agencies will weigh specific factors when assessing the safety and soundness of these providers. This provides a level of predictability that has been largely missing, as core providers have historically operated in a "gray zone" of regulation.

3. A Focus on "Responsible Innovation"

"Responsible innovation" is a buzzword that is often used but rarely defined in legal terms. By explicitly linking third-party risk management to the goal of fostering innovation, the agencies are signaling that they want banks to experiment with new technologies—provided those banks have a robust, risk-aware framework in place.


Challenges Ahead

While the reception to the proposal has been largely positive, the path to implementation will not be without challenges. Industry experts note several areas that will likely dominate the 60-day comment period:

  • Definition of "Critical": Stakeholders are likely to request more precise definitions of what constitutes a "critical" third-party relationship. Without clear thresholds, institutions may remain overly cautious, applying stringent oversight to services that do not truly warrant it.
  • The "Core" Provider Dilemma: While the agencies are addressing core service providers, many banks argue that the market dynamics are such that they have very little leverage over these massive providers. The question remains whether this guidance will provide banks with the necessary teeth to enforce security and operational requirements on their core providers.
  • Consistency Across Regions: Although the agencies are working in concert, there is always a risk that individual examiners at the local level may interpret the "non-binding" guidance differently. The industry will be looking for assurance that the transition to this new framework will be uniform across the country.

Conclusion

The release of the proposed third-party risk management guidance marks a pivotal moment for the U.S. financial system. As the lines between traditional banking and technology continue to blur, the ability to effectively manage third-party risk is no longer just a compliance exercise—it is a fundamental component of business strategy and systemic stability.

By prioritizing a risk-based approach and explicitly acknowledging the unique needs of community banks, federal regulators are attempting to strike a balance between rigorous oversight and the need for a dynamic, competitive, and innovative financial market. The coming months will be crucial as the financial industry provides its feedback, setting the stage for a new era of bank-vendor relationships that are intended to be safer, more efficient, and better suited for the realities of the modern economy.