US federal banking regulators have proposed revised guidance for third-party risk management, seeking to replace existing guidance with a more risk-based framework for banks and credit unions.
The proposal was issued jointly by the Office of the Comptroller of the Currency, Federal Reserve Board, Federal Deposit Insurance Corporation and National Credit Union Administration on September 11, 2026. It is based on supervisory experience and lessons from examinations of financial institutions’ third-party risk practices.
The proposed framework focuses on aligning the level of third-party risk management with the magnitude and likelihood of potential harm associated with each relationship. It also takes into account the size, complexity and risk profile of the financial institution.
This represents an important shift away from approaches that apply broadly similar procedures to every vendor. Under the proposed framework, a bank would be expected to devote greater resources to relationships that could create significant operational, financial, cybersecurity or customer-related consequences.
Third-party relationships have become increasingly important as banks depend on external providers for cloud computing, technology platforms, payment services, data processing, cybersecurity and other critical functions.
The proposed guidance therefore encourages institutions to understand the risks associated with individual relationships rather than treating outsourcing itself as the primary risk indicator.
Due Diligence and Ongoing Monitoring
Banks will still need appropriate processes for evaluating third parties before entering into relationships and monitoring those relationships throughout their lifecycle.
This includes understanding the nature and importance of the service, the potential impact of disruption and the institution’s ability to manage or exit the relationship if circumstances change.
For critical providers, ongoing monitoring and contractual arrangements become particularly important. Banks need sufficient visibility into the provider’s risk environment and appropriate mechanisms to address material problems.
The agencies have also issued a separate statement concerning community banks’ relationships with core service providers, including factors that may be considered in supervisory and enforcement decisions involving these providers.
No One-Size-Fits-All Approach
The proposal specifically states that there should not be a single third-party risk-management model applicable to every banking organisation.
Instead, controls should be proportionate to the institution’s risk profile and the nature of its relationship with each provider. The agencies also state that the proposed guidance would be principles-based and non-binding, rather than establishing enforceable standards.
This distinction is important. The framework is intended to guide supervisory expectations and improve risk management, but failure to follow the guidance itself would not constitute a violation requiring supervisory action.
Comments are due 60 days after publication in the Federal Register, with the OCC listing November 16, 2026 as the comment-period closing date.
Implications for Banks
The proposal is particularly relevant as technology dependencies become deeper and more interconnected.
A bank may have strong internal cybersecurity and operational controls but still face significant exposure if an important technology provider suffers an outage, cyberattack or operational failure.
Third-party risk therefore increasingly overlaps with operational resilience, cybersecurity, concentration risk and business continuity.
Banks may need to map critical dependencies, identify concentration points, assess potential failure scenarios and ensure that contingency and exit arrangements are realistic.
The framework also has relevance for bank-fintech partnerships. As financial institutions increasingly use external technology companies to deliver products and services, understanding the risks created by those relationships becomes an important part of overall risk governance.
For risk managers, one of the most important principles emerging from the proposal is that third-party risk management should be risk-based rather than process-driven.
The proposed approach seeks to ensure that resources are concentrated where third-party failures could cause the greatest harm, while avoiding unnecessary compliance burdens for lower-risk relationships.
The development reinforces a broader lesson for financial institutions: outsourcing a function does not eliminate the risks associated with that function. Effective governance requires banks to understand their external dependencies and maintain appropriate oversight throughout the relationship.
Want to deepen your expertise beyond today’s news?
Explore practical certification courses designed for banking, risk, insurance, compliance, ESG, AI, and emerging technologies professionals.
Learn from industry experts and earn certifications from RMAI and BFSI Sector Skill Council of India.
#Riskmanagementnews