On September 11, 2026, the Federal Reserve, FDIC, OCC, and NCUA jointly released proposed guidance that could reshape how banks and credit unions approach third-party risk management (TPRM).
The biggest takeaway isn't that regulators are backing away from third-party risk. Instead, the proposal reinforces a more practical principle: the amount of oversight applied to a third party should be proportionate to the risk that relationship presents.
For community banks and credit unions, that could mean less emphasis on treating every vendor the same and more emphasis on identifying the relationships that can actually create meaningful risk.
The 2023 Interagency Guidance on Third-Party Relationships established a common framework for the Federal Reserve, FDIC, and OCC. Although the guidance was intended to be principles-based, the agencies now acknowledge that it has sometimes been interpreted too broadly.
Detailed considerations and examples intended to help institutions manage third-party relationships may have inadvertently encouraged a checklist approach. Institutions have also struggled to determine which expectations should apply to very different relationships, from core processors and fintech providers to professional services and lower-risk vendors.
The proposed 2026 guidance attempts to address that problem by placing risk assessment at the center of the TPRM process.
The proposal organizes third-party risk management around four primary components:
The sequence matters.
Rather than starting with a standard list of due diligence documents or monitoring requirements, an institution should first understand the risk associated with the relationship. That assessment should consider both the potential magnitude of harm and the likelihood of that harm occurring.
A core processor supporting critical operations should generally receive substantially more scrutiny than a vendor providing a limited administrative service. But the vendor's category alone shouldn't determine the answer. Institutions should consider factors such as access to sensitive information, system connectivity, operational dependency, customer impact, financial exposure, and available controls.
The result should be a TPRM program in which the level of oversight follows the risk, not simply the vendor type.
This is where the proposed guidance could have the greatest practical impact for community financial institutions.
The agencies recognize that institutions can tailor inventories, due diligence, contracts, and ongoing monitoring based on the risk presented by a relationship.
For lower-risk relationships, that may mean less-detailed due diligence, greater reliance on publicly available or alternative information, and less frequent monitoring. Higher-risk relationships may require deeper due diligence, stronger contractual protections, more frequent monitoring, and additional subject-matter expertise.
The goal isn't to prove that every vendor completed the same process.
The goal is to demonstrate that the institution understands the risk and applied an appropriate level of oversight.
That distinction could allow institutions to spend less time administering low-risk vendors and more time managing the third parties that represent meaningful operational, cybersecurity, compliance, financial, or strategic risk.
Another significant part of the proposal is its treatment of residual risk.
The agencies explicitly recognize that third-party risk cannot always be eliminated. This is particularly relevant for community institutions that may have limited negotiating leverage with large technology providers.
A provider may refuse certain contract provisions, decline to provide requested documentation, restrict audit rights, or offer limited alternatives to its standard terms. Those limitations do not automatically mean the institution must avoid the relationship.
Instead, management should understand what risk remains after available mitigating measures and determine whether that residual risk falls within the institution's established risk appetite and tolerances.
That changes the conversation from:
“Did we collect everything our procedure requires?”
to:
“Do we understand the remaining risk well enough to make and document an informed decision?”
For that approach to work, however, institutions need a defined process for documenting exceptions, escalating material risks, accepting residual risk, and reporting significant exposures to the appropriate level of management or the board.
The proposal applies the same proportionality principle to contracts.
Rather than suggesting that every agreement must contain an identical set of provisions, institutions should determine which contractual protections matter based on the risks of the specific relationship.
For a higher-risk provider, that might include information security requirements, service levels, business continuity expectations, incident notification, confidentiality, subcontractor requirements, audit rights, termination provisions, or other protections. A lower-risk relationship may not require the same level of contractual scrutiny.
The proposal also provides useful clarification regarding subcontractors, sometimes referred to as fourth parties.
A vendor's use of a subcontractor does not generally create a separate third-party relationship between the financial institution and that subcontractor. However, institutions should still consider whether subcontractor dependencies increase the risk of the primary relationship.
Again, the expected level of oversight should follow the risk.
The inclusion of the NCUA is important.
The 2023 interagency guidance was issued by the Federal Reserve, FDIC, and OCC. The NCUA has joined the 2026 proposal, and insured credit unions are specifically included within its scope.
If finalized, the guidance would therefore create a more consistent federal approach to third-party risk management across banks and federally insured credit unions.
The guidance is still proposed, so institutions shouldn't immediately overhaul their programs based on language that could change before becoming final.
However, the proposal creates a good opportunity to ask whether your existing program is genuinely risk-based.
Consider evaluating whether:
For many institutions, preparing for the direction of the proposed guidance may not require adding more to the TPRM program. It may require becoming more deliberate about why certain activities are being performed.
Several issues could affect the final guidance.
The agencies are specifically seeking feedback on the scope of third-party relationships covered by the guidance and how higher-risk relationships should be identified. Institutions should also watch for changes involving documentation expectations, reliance on external information, subcontractor oversight, and how much discretion institutions ultimately receive to tailor their programs.
Those details will determine how significant the shift toward proportionality becomes in practice.
The proposed 2026 guidance doesn't make third-party risk management less important. It makes effective risk assessment more important.
Greater flexibility also creates greater responsibility to explain why an institution determined that a particular level of oversight was appropriate.
A strong TPRM program should therefore be able to demonstrate a clear connection between the risk a third party presents and the due diligence, contractual protections, monitoring, escalation, and governance applied to that relationship.
For community banks and credit unions, that could ultimately mean a more efficient TPRM program, one that spends less effort proving that every vendor went through the same process and more effort managing the third parties that actually matter.
Bedel Security can help your institution evaluate its third-party risk management program and identify opportunities to strengthen its risk assessment, governance, oversight, and reporting.
As the proposed guidance moves through the comment process, now is a good time to ask a simple question: Is your TPRM program truly risk-based, or is it still process-based?