
Federal banking regulators are proposing a new approach to how banks and credit unions oversee the technology companies, payment processors and other outside businesses they rely on to provide financial services. The Federal Reserve Board, Federal Deposit Insurance Corporation, National Credit Union Administration and Office of the Comptroller of the Currency jointly announced the proposed third-party risk management guidance on September 11. The proposal would replace existing federal guidance and encourage financial institutions to focus their oversight on the actual risks posed by individual third-party relationships rather than treating every vendor the same way.
For consumers, the proposal doesn’t create new requirements for managing a bank account or change federal deposit insurance. Instead, it addresses what happens behind the scenes when a financial institution relies on another company to help deliver its products and services.
Banks Increasingly Depend on Outside Companies
Modern financial institutions rarely provide every service entirely through their own employees and technology. Banks and credit unions may rely on outside companies for payment processing, cloud computing, account technology, lending platforms and other important operations. Those relationships can help institutions offer new products and technology more efficiently, but they can also introduce operational, compliance, financial and other risks.
Federal regulators therefore expect financial institutions to identify and manage risks associated with their third-party relationships. The proposed guidance is designed to make that oversight more closely match the level of risk presented by each relationship.
Regulators Want Oversight to Match the Actual Risk
Under the proposal, banks and credit unions would be encouraged to tailor their third-party risk management practices to the reasonably assessed risks of individual vendor relationships. A relationship involving a company that supports a critical banking function, for example, may deserve substantially more attention than a vendor providing a less important service.
Regulators say this risk-based approach could help institutions prioritize material financial risks, compliance with laws and regulations, and the allocation of internal resources.
The guidance would also allow institutions to consider their own size, complexity and risk profile when determining how third-party relationships should be managed. That could be particularly important for smaller community banks and credit unions that don’t have the same staffing and compliance resources as the nation’s largest financial institutions.
The Agencies Want to Move Away From a ‘Check-the-Box’ Approach
The proposal represents a shift from federal third-party risk management guidance issued in 2023. Regulators say supervisory experience and industry feedback have shown that the existing guidance can be interpreted too broadly and without enough emphasis on tailoring oversight to actual risk.
Its numerous considerations and detailed examples may also have encouraged institutions to focus on processes and documentation rather than determining which third-party relationships create the greatest risks. The agencies also expressed concern that the existing approach could be interpreted as discouraging relationships with newer or innovative service providers.
The proposed replacement instead takes a principles-based approach designed to give financial institutions more flexibility while still requiring them to manage meaningful risks.
What Could This Mean for Bank Customers?
Consumers aren’t being asked to perform new security checks or take any action because of the proposal. Instead, third-party risk management is largely an issue for the financial institutions that consumers trust with their money and personal information. A bank customer may never know how many outside companies are involved behind the scenes when they use mobile banking, transfer money, apply for a loan or access other financial services.
Problems involving an important service provider, however, can potentially disrupt the services a financial institution offers or create other operational and compliance risks.
Community Banks Are Getting Additional Attention
The four-agency proposal isn’t the only third-party risk initiative regulators announced. The Federal Reserve, FDIC and OCC separately issued a statement addressing how community banks work with core service providers. That statement discusses factors regulators will consider when making supervisory and enforcement decisions involving services provided to community banking organizations.
The Federal Reserve also proposed a separate third-party risk management guide specifically for traditional community banking organizations under its supervision. Together, the initiatives reflect an effort to make federal oversight more responsive to the size of an institution and the actual risks associated with the outside companies it uses.
Existing Guidance Would Eventually Be Replaced
The proposal does not immediately eliminate the current third-party risk management framework. Federal regulators say that when the new guidance is finalized, they plan to rescind and replace existing guidance in an effort to promote consistency and what they describe as prudent innovation in the banking industry. The agencies also emphasize that this is supervisory guidance rather than a binding regulation.
That distinction means the proposal is intended to explain regulators’ supervisory expectations and risk-management principles rather than create a new set of legally binding requirements by itself. Banks and credit unions would still remain responsible for complying with applicable laws and regulations regardless of whether they perform an activity themselves or rely on an outside provider.
The Public Can Comment Through November 16
The proposal is open for public comment following its publication in the Federal Register. Comments are due November 16, 2026. The OCC identifies the proposal as Docket ID OCC-2026-0793, while the Federal Reserve identifies the joint proposal as OP-1881.
Financial institutions, technology companies, consumer organizations and members of the public can submit comments addressing the proposed approach before regulators finalize the guidance. For everyday bank and credit union customers, no immediate action is required, but the proposal provides a look at how regulators are reconsidering the oversight of the outside technology and service companies increasingly involved in delivering modern financial services.
What to Read Next
A Practical Guide to Banking Habits That Make It Harder to Trace a Home-Repair Scam
The $18 Trillion Piggy Bank: American Homeowners Have Never Had This Much Equity
Your Emergency Fund Is $20,000 — Is That Too Much Cash to Keep Sitting in the Bank?

Amanda Blankenship is Chief Editor at District Media, Inc., leading content strategy, quality assurance, and editorial operations across high-traffic personal finance sites like SavingAdvice.com and CleverDude.com. A Wingate University graduate with a BA in Communications (Journalism focus), she brings over a decade of experience in digital publishing, writing, and team leadership in the personal finance space.






Leave a Reply