SecBriefs
← Industry Reports
Federal Reserve / FDIC / NCUA / OCCFederal Reserve / FDIC / NCUA / OCC
INDUSTRY REPORTRegulation & Policy9 min read

US Regulators Recast Third-Party Risk Around Materiality — and Put Core Providers Under Sharper Scrutiny

US federal banking regulators are proposing to replace the 2023 interagency third-party risk management guidance with a more principles-based, risk-tailored approach. A companion statement says core-provider transparency, contract features and technology practices can influence supervisory resource allocation for community-bank service providers.

Federal Reserve / FDIC / NCUA / OCC
2026

Proposed Third-Party Risk Management Guidance and Joint Statement on Community Banks’ Engagement with Core Service Providers

REGULATION & POLICY · SECBRIEFS ANALYSIS
THE SHORT VERSION

Executive Takeaway

The proposal shifts the center of gravity from broad, uniform process toward risk-based prioritization: banks should align the depth of third-party oversight with the reasonably assessed risk of each relationship, while continuing to comply with applicable law. If finalized, the agencies plan to rescind and replace the 2023 interagency guidance.

This is not a transfer of accountability to vendors. The proposal states that banking organizations remain responsible for sound risk management even when activities are performed by affiliates, highly regulated service providers, subcontractors or other third parties. For community banks, the separate core-provider statement is especially significant because it puts provider transparency, restrictive contract terms and technology resilience directly into the agencies’ supervisory allocation framework.

Key Findings

  1. 01

    The proposed interagency guidance would replace the 2023 third-party risk management guidance if finalized and would emphasize a principles-based, risk-tailored approach.

  2. 02

    The proposal says third-party risk management should be prioritized around material financial risks, compliance with laws and regulations, and the risk profile of each relationship.

  3. 03

    A banking organization retains ultimate responsibility for sound risk management and legal compliance when activities are outsourced, including to affiliates, regulated service providers and subcontractors.

  4. 04

    The companion core-provider statement says supervisory allocation may take account of provider transparency, contract features and technology practices.

  5. 05

    Examples of relevant transparency include timely due-diligence information, enforceable service-level measures and disclosure of operational or security incidents affecting service delivery.

  6. 06

    Examples of problematic contract or business practices include opaque pricing or billing, unsupported or undefined deconversion fees, and restrictions that make exit or integration with alternative providers harder.

  7. 07

    Technology considerations include security-incident history, management of end-of-support or end-of-life assets, and demonstrated operational-resilience capabilities.

What the Data Says

60 days

Comment period

Comments on the proposed guidance are due 60 days after Federal Register publication.

3 focus areas

Core-provider supervision

The companion statement highlights transparency, contract features and technology as factors in supervisory allocation decisions.

Remains with the bank

Accountability

Outsourcing does not diminish the banking organization’s responsibility for sound risk management and compliance.

What It Doesn’t Say / Limitations

This is proposed guidance, not a final rule or final supervisory standard. The comment deadline is tied to Federal Register publication rather than the press-release date. The proposal also notes that consumer-compliance considerations may be relevant but are not directly addressed in the proposed guidance.

The package is not institutionally unanimous. Governor Michael Barr dissented and raised concerns about the proposed focus on “material financial risk” and possible supervisory gaps, while Governor Lisa Cook supported the review but invited feedback on whether more specificity is needed for cybersecurity, consumer protection, records management and AML responsibilities. Those disagreements increase the importance of monitoring the final text.

Why It Matters

Banks have long known that outsourcing does not outsource accountability, but this package could materially change how examiners and institutions prioritize third-party oversight. The most practical implications sit in risk-tiering methodology, evidence supporting vendor-risk decisions, contract leverage, incident transparency and the ability to exit or supplement critical providers.

For community banks dependent on a small number of core providers, the companion statement is particularly important because it explicitly acknowledges limited negotiating power and due-diligence challenges while signaling that provider behavior itself can shape supervisory attention.

Who Should Care

  • US banks and credit unions
  • Community banks
  • Third-party and vendor-risk teams
  • CISOs and operational-resilience leaders
  • Procurement and legal teams
  • Fintech and core-banking providers
  • Compliance and internal-audit teams
SECBRIEFS VIEW

SecBriefs Assessment

The most important signal is not “less third-party risk management.” It is a move toward more defensible prioritization. Institutions will need to show why oversight depth matches actual risk, while preserving evidence that cyber, resilience, legal and compliance obligations remain covered.

The core-provider statement also creates a useful board-level lens: where transparency is poor, exit is difficult, service levels are hard to enforce or technology is aging, concentration risk is no longer just a procurement problem. It becomes a supervisory and operational-resilience concern.

What To Do Now

  1. Compare current third-party risk-tiering and review depth against the proposed material-risk and relationship-specific approach.
  2. Identify critical core-provider due-diligence gaps, especially around security reports, service levels, operational incidents and ongoing monitoring.
  3. Review exit, deconversion, pricing, billing and integration clauses for provisions that could restrict the bank’s ability to reduce risk or change providers.
  4. Document where cybersecurity, resilience, consumer-protection, records-management and AML responsibilities sit across bank and provider teams.
  5. Reassess end-of-life technology dependencies and provider recovery capabilities for critical banking services.
  6. If the proposal materially affects the institution, prepare evidence-based comments before the Federal Register comment window closes.
ORIGINAL REPORT

Proposed Third-Party Risk Management Guidance and Joint Statement on Community Banks’ Engagement with Core Service Providers

Publisher
Federal Reserve / FDIC / NCUA / OCC
Published
URL
https://www.federalreserve.gov/newsevents/pressreleases/bcreg20260911a.htm
View on publisher site(opens in a new tab)
RELATED DECISION INTELLIGENCE

Follow the evidence chain

Move from the current signal to its topic context, supporting briefs, decision analysis and deeper research.

Get the next SecBriefs report analysis

Clear analysis of major cybersecurity reports, delivered by SecBriefs.