2026年9月29日

Federal Banking Agencies Issue Proposed Updates to Interagency Third-Party Risk Management Guidance and Joint Statement on Core Service Providers

Share

On September 11, 2026, the Board of Governors of the Federal Reserve System (the “Federal Reserve”), the Federal Deposit Insurance Corporation (“FDIC”), the National Credit Union Administration (“NCUA”), and the Office of the Comptroller of the Currency (“OCC,” and collectively, the “Agencies”) announced that the Agencies are inviting comment on a proposal to revise their guidance regarding third-party risk management practices (the “Proposed TPRM Guidance”).1 The Federal Reserve, FDIC, and OCC separately issued (without invitation for comment) a Joint Statement on Community Banks’ Engagement with Core Service Providers (the “Joint Statement”).2 In addition, the Federal Reserve invited comment on a proposed Third-Party Risk Management Guide for Traditional Community Banking Organizations (the “Community Bank Guide”), which would be an additional resource for Federal Reserve-supervised community banks with total assets below $30 billion.3

The Proposed TPRM Guidance, if finalized, would replace the guidance on third-party risk management practices adopted by the Federal Reserve, FDIC, and OCC in 2023 (the “2023 Guidance”),4 as well as several supplemental resources, including the Joint Statement on Deposit Product Arrangements with Third Parties, adopted in July 2024, and a third-party risk management guide for community banks revised most recently in May 2024. The Joint Statement supplements the proposed guidance revisions by explaining how the Federal Reserve, FDIC, and OCC will evaluate core providers to community banking organizations, including provider transparency, contract features, and technology investments, in risk-based supervisory and enforcement decisions.

The Proposed TPRM Guidance represents a further step toward implementing a shift in the Agencies’ supervisory tone and approach: away from a prescriptive, process-oriented framework and toward a better-tailored, risk-based one. Toward this same end, on September 10, 2026, the OCC and FDIC finalized a joint rule codifying a regulatory definition of an “unsafe or unsound practice” and establishing standards for the issuance of matters requiring attention (“MRAs”), accompanied by updated policies and procedural manuals to guide examiners. The Community Bank Guide would provide Federal Reserve-supervised traditional community banks with a practical resource for operationalizing the Proposed TPRM Guidance’s principles, consistent with Vice Chair for Supervision Michelle Bowman’s long record of sensitivity to the needs of these banking organizations.

The Joint Statement places a supervisory spotlight on core providers that serve community banking organizations and identifies potential bases of enforcement jurisdiction over these providers.
Comments on the Proposed TPRM Guidance and Community Bank Guide must be received on or before November 16, 2026.

Background

The 2023 Guidance, published by the Federal Reserve, FDIC, and OCC in June 2023, was intended to promote consistency across the federal banking agencies in the supervision of banking organizations’ third-party relationships. The overarching message of the 2023 Guidance is that sound third-party risk management takes into account the level of risk, complexity, and size of the banking organization, as well as the nature of the specific third-party relationship.

The 2023 Guidance articulates a principles-based, risk-tiered framework for managing third-party relationships across a continuous life cycle consisting of five stages: planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination. Each of the five stages includes numerous considerations. For example, it provides 17 considerations for contract negotiations, including right to audit, confidentiality and integrity, operational resilience and business continuity, dispute resolution, and subcontracting.

Since its issuance, however, the Agencies have identified four principal concerns based on stakeholder feedback and supervisory experience.

  • Difficulty Applying and Tailoring in Practice: Because the 2023 Guidance addressed a broad range of third-party relationships, banking organizations struggled to determine how to apply and tailor specific examples to certain banking relationships.
  • Harm Based on Activity vs. Relationship: The “critical activities” framework focused on the activity conducted by the third party rather than the likelihood of harm posed by the relationship.
  • Perceived Prescriptiveness: Despite its principles-based intent, the 2023 Guidance was read by many as establishing prescriptive requirements.
  • Eliminating vs. Mitigating Risk: The 2023 Guidance has been read to discourage arrangements with newer and innovative third parties, due to an implied need to eliminate risk instead of manage risk.
  • Community Bank Core Provider Concentration: In parallel, the Joint Statement responds to a narrower but related concern: community banking organizations’ reliance on core providers in a concentrated market where limited negotiating leverage may constrain due diligence, contract negotiation, and ongoing monitoring. The Federal Reserve, FDIC, and OCC frame the Joint Statement as a way to provide community banks with greater clarity regarding risk-based supervision and enforcement of core provider services.
  • Federal Reserve Community Bank Guide: Separately, the Federal Reserve proposed a companion Third-Party Risk Management Guide for Traditional Community Banking Organizations, defined as Federal Reserve-supervised institutions with total assets below $30 billion. The proposed Community Bank Guide would organize third-party risk by vendor categories—including core, IT infrastructure, cybersecurity, payments and digital banking, loan management, card issuing, and BSA/AML and fraud—and would discuss operational resilience, information security, compliance, and financial resilience considerations specific to traditional community banks.

Proposed Guidance

In its overview, the Proposed TPRM Guidance reiterates that banking organizations have the “ultimate responsibility to establish and maintain sound risk management practices and comply with applicable laws and regulations,” and that use of third parties does not diminish these responsibilities. Similar to the 2023 Guidance, the Proposed TPRM Guidance defines third-party relationships broadly to mean “a business arrangement between a banking organization and an entity or individual for the provision of one or more products, services, and other activities that support the banking organization.”

Taking into account each banking organization’s size, complexity and risk profile, the Proposed TPRM Guidance recommends four considerations to manage third-party risk: (1) identifying and assessing applicable risks; (2) overseeing risks proportionate to their significance; (3) making informed decisions about residual risks and risk acceptance; and (4) establishing appropriate governance practices.

1. Identifying and Assessing Applicable Risk

The Proposed TPRM Guidance highlights that essential first steps in any third-party risk management program are the threshold disciplines of risk identification and assessment. Together, due diligence, contract structuring, and ongoing monitoring establish the foundation upon which all subsequent risk management activities rest.

  • Third-Party Relationship Identification: Banking organizations are encouraged to maintain a third-party relationship inventory that identifies and categorizes third-party relationships. The level of detail and frequency of updates will depend on the complexity of the banking organization. Additionally, banking organizations may decide not to fully include lower-risk relationships (e.g., those involving routine administrative functions, professional support services, or office support services) in their inventories.
  • Risk Identification: The Proposed TPRM Guidance directs banking organizations to identify the specific risks each prospective or existing relationship presents. The guidance does not expect identification of every conceivable risk but does expect identification of the risks most relevant to its operations.
  • Risk Assessment: According to the Proposed TPRM Guidance, third-party relationships do not all present the same degree of risk, and no single methodology is prescribed for conducting risk assessments. As a general matter, assessments should weigh both the potential severity of harm and the probability that such harm will materialize. Given that banking organizations have “extensive experience in assessing risk,” the Proposed TPRM Guidance states that “examiners will give due consideration to a banking organization’s reasonable judgment regarding the banking organization’s risk assessments.”
2. Overseeing Risks Proportionate to Their Significance

The Proposed TPRM Guidance emphasizes that effective risk oversight must be proportionate to the risks presented by each third-party relationship and consistent with the banking organization’s size, complexity, and risk profile. Failure to prioritize and tailor oversight according to risk can increase the magnitude and likelihood of harm arising from higher-risk relationships. The Proposed TPRM Guidance provides high-level illustrations to consider, if relevant.

Due Diligence and Third-Party Selection: The depth of due diligence should be calibrated to the risk presented by the relationship and the organization’s individual business needs. Depending on the circumstances, due diligence may encompass assessment of the third party’s business conditions or effectiveness of its risk mitigation or other business practices. The Proposed TPRM Guidance recognizes that banking organizations may rely on sufficient supplemental sources where a third party is unwilling or unable to provide certain due-diligence information, while noting that alternative sources may not be sufficient where the third party cannot provide information or cooperation reasonably necessary for due diligence, ongoing monitoring, and risk assessments.

Contract Negotiation: Contrary to the enumerated contract provisions in the 2023 Guidance, the Proposed TPRM Guidance provides that “there are no generally applicable expected contract terms for third-party relationships, even for higher-risk relationships.” Banking organizations are expected to tailor contract negotiations to their individual needs and circumstances. The Proposed TPRM Guidance clarifies that the mere presence or absence of a specific contractual term would not, standing alone, be a sufficient basis for an adverse supervisory finding.

Relevant contractual considerations may include allocation of responsibility, service level agreements, confidentiality, information security, use of subcontractors, operational resilience plans, and termination provisions. The level of negotiation and terms generally should be informed by the level of risk, the banking organization’s business needs, and the banking organization’s negotiating power. The Agencies encourage banking organizations to maintain and periodically review an inventory of third-party contracts to confirm that existing provisions continue to address pertinent risks.

Ongoing Monitoring: Ongoing monitoring is the process by which banking organizations assess third-party performance and changes in risk over the life of a relationship, including associated reporting to the board and senior management. Ongoing monitoring may enable banking organizations to confirm the quality of controls and performance of contractual obligations, identify significant issues or concerns, and respond to risks when identified. The Agencies provide examples of ongoing monitoring, including reviewing updates to materials provided by third parties, performing onsite visits, control testing, monitoring public information, and reviewing customer complaints.

The frequency and depth of monitoring should reflect the risk, complexity, and nature of the relationship. Higher-risk relationships may warrant more comprehensive or frequent monitoring and additional staffing with relevant expertise. Lower-risk relationships may require less extensive or less frequent oversight. Because the risk profile of a third-party relationship may change over time, banking organizations should be prepared to adapt their monitoring practices accordingly.

Termination: A banking organization may terminate a third-party relationship for various reasons, including contract expiration or breach, regulatory non-compliance, performance concerns, or a strategic decision to bring an activity in-house or switch providers. Ultimately, the Agencies will give consideration to a banking organization’s reasonable determinations to terminate an existing third party and find an alternative third party that better aligns with its risk appetite and tolerances.

Cross-Cutting Oversight Topics: The Proposed TPRM Guidance provides examples to help understand how risks and mitigations may span oversight stages and may be complementary or redundant. Ultimately, these examples are provided to help each banking organization’s third-party risk mitigation management.

  • Subcontractors: While the use of subcontractors may heighten risk by lessening the banking organization’s control over activities, banking organizations remain responsible for complying with laws and regulations, regardless of a third party’s use of subcontractors. The Proposed TPRM Guidance includes examples of effective risk management, including negotiating and monitoring compliance with contractual terms governing subcontractor use and assessing the adequacy of the third party’s own risk management programs.
  • Co-ventures, Consortia, and Risk Management Service Providers: Banking organizations may leverage collaborative arrangements, such as consortia for joint due diligence, standard-setting organizations, and third-party consultants or auditors. The Agencies acknowledge the many benefits of these relationships, and that effective risk management must remain grounded in the banking organization’s own specific circumstances. The Agencies encourage use of technology for effective third-party oversight, where appropriate and while considering any additional risks, and note that collaborative activities among banking organizations must comply with antitrust laws.
  • Insurance, Indemnification, and Limitations on Liability: As with the 2023 Guidance, the Proposed TPRM Guidance encourages negotiating certain contract provisions to reduce risk. Subject to appropriate due diligence, credible indemnification provisions, insurance, or guarantees may help mitigate risk and lower the overall risk profile of the relationship.
  • Operational Resilience Planning: Effective risk oversight for higher-risk relationships may include due diligence, contractual obligations, and monitoring related to operational resilience, including alternative back-up providers, data backup at physically and logically separated sites, and the ability to resume operations and preserve data following disruption events or cyberattacks.
3. Making Informed Decisions About Residual Risk and Risk Acceptance

Taking into account the need to conduct activities in a safe and sound manner and information available, the third-party risk management process involves determining when and to what extent elements of risk oversight may not be practicable and what is an acceptable level of residual risk. The Proposed TPRM Guidance highlights that “risk acceptance is ultimately a fact- and circumstance-specific consideration, commensurate with a banking organization’s size, complexity, and risk profile and with the nature of its third-party relationships.”

As a result, the Agencies do not expect banking organizations to eliminate risks. There will be cases where banking organizations will have residual risk or cases where they cannot significantly mitigate a risk. In these cases, the Proposed TPRM Guidance acknowledges that a third-party relationship may remain beneficial and necessary for the organization to operate effectively and competitively in a rapidly evolving marketplace.

4. Establishing Appropriate Governance Practices

The last section of the Proposed TPRM Guidance addresses the governance framework that banking organizations should consider adopting to support effective third-party risk management. Ultimately, sound governance is foundational to identifying, assessing, and managing the risks arising from third-party relationships. The Proposed TPRM Guidance provides practices that banking organizations may choose to adopt, including establishing: (a) clear roles and responsibilities; (b) an appropriate risk appetite and appropriate risk tolerances related to risks from third-party relationships; (c) appropriate reporting to senior management and the board; and (d) a process for conducting periodic independent reviews to assess the effectiveness of the banking organization’s third-party risk management practices.

The Proposed TPRM Guidance also recommends that a banking organization is able to identify and assess its third-party relationship risks, prioritizing risk management in relation to the assessed risk levels of such relationships and its risk appetite and tolerances. Finally, the Agencies recommend documenting key elements of risk management for the third-party relationships. Ultimately, the Agencies commit to giving “due consideration to a banking organization’s reasonable governance decisions when evaluating its practices.”

Companion Joint Statement on Core Providers

The Joint Statement focuses on community banking organizations’ (“CBOs”) relationships with “core providers,” which the Federal Reserve, FDIC, and OCC describe as third parties that provide critical systems applications and infrastructure supporting the operation and essential functions of one or more lines of business, including transaction processing, account management, payments processing, customer relationship management, compliance and reporting, online banking, and other material functions.

The Joint Statement treats core providers as among community banking organizations’ most material, complex, and highest-risk third-party relationships, while acknowledging that market concentration can limit community banks’ negotiating power and make it harder to obtain due diligence information, negotiate contract terms, or conduct effective ongoing monitoring.

Rather than prescribing new contract terms for community banks, the Joint Statement identifies provider practices that may inform supervisory allocation and enforcement decisions, including transparency with community banks, contractual features that impede exit or supplemental services, technology investments, computer security incidents, end-of-support and end-of-life asset management, and demonstrated operational resilience capabilities. It also notes that certain core providers may qualify as institution-affiliated parties under the Federal Deposit Insurance Act where they are integral to the functioning of a community bank and the delivery of banking products and services, thereby permitting the Federal Reserve, FDIC, or OCC to bring an enforcement action against such core providers under section 8 of that Act.

What Remains from the 2023 Guidance?

While the Proposed TPRM Guidance highlights the need to deviate from the elaborate structure and overly prescriptive messaging of the 2023 Guidance, it does retain many of the core concepts. Below are high-level concepts that remain from the 2023 Guidance.

  • The Ultimate Responsibility Rests with the Banking Organization: Both sets of guidance make it clear that a banking organization’s use of third parties does not diminish its responsibilities.
  • Third-Party Relationships are Broadly Defined: The definition of “third-party relationships” is largely unchanged and means a business relationship between a banking organization and an entity.
  • Tailoring to Size, Complexity, and Risk Profile: Both sets of guidance encourage adopting risk management practices to be commensurate with the banking organization’s size, complexity, and risk profile.
  • Level of Oversight is Tied to Risk: Neither set of guidance requires a “one-size-fits-all approach,” but both encourage tying the level of oversight to risk.
  • Risk Management Life Cycle Framework: The Proposed TPRM Guidance retains the 2023 Guidance’s core oversight stages—due diligence, third-party selection, contract negotiation, ongoing monitoring, and termination.
  • Ongoing Monitoring as a Focus: Both the Proposed TPRM Guidance and 2023 Guidance highlight ongoing monitoring of third parties, including tracking performance, controls, and emerging risks.
  • Termination Planning: Planning for the end of a third-party relationship is a key focus for both sets of guidance.
  • Attention to Subcontractor Risks: Both versions require attention to sub-contracting risk, and that the oversight obligation continues to flow through the primary third party rather than demanding direct bank-to-subcontractor oversight.

What are the Key Changes?

As noted above, the Proposed TPRM Guidance looks to eliminate the perceived prescriptiveness of the 2023 Guidance, most notably by eliminating the lists of considerations and replacing them with less structured examples. The Joint Statement extends the same risk-based and burden-reduction theme to community banks’ relationships with core providers. Below, we highlight some of the key changes reflected in the Proposed TPRM Guidance and Joint Statement.

  • NCUA Joins Proposed TPRM Guidance: The NCUA, which did not join the 2023 Guidance, has now joined the other Agencies in co-proposing the new framework, bringing federally insured credit unions within the scope of the interagency approach for the first time.
  • Federal Reserve Issues Companion Guide for Traditional Community Banks: The Federal Reserve separately proposed a Third-Party Risk Management Guide for Traditional Community Banking Organizations—defined as Federal Reserve-supervised institutions with total assets below $30 billion—that would serve as a companion to the Proposed TPRM Guidance. The proposed Community Bank Guide organizes third-party risk management around four overarching considerations (operational resilience, system and information security, compliance with rules and regulations, and financial resilience), and provides vendor-by-vendor guidance for eight categories of third parties most common to traditional community banks: core providers; IT infrastructure providers; cybersecurity providers; payment processing and digital banking providers; loan management system providers; card issuing and processing providers; BSA/AML and financial crime platform providers; and fraud prevention and detection providers.
  • Triggers Move from Critical Activities to Harm: While the 2023 Guidance relied on “critical activities” to trigger heightened oversight, the Proposed TPRM Guidance ties heightened oversight to magnitude and likelihood of harm.
  • Reframed Contract Negotiation Recommendations: The 2023 Guidance contains enumerated contract negotiation considerations, which includes details as to relevance. The Proposed TPRM Guidance eliminates the “checklist” of contract terms and does not provide expected terms.
  • Agencies’ Deference to Bank’s Judgment and Non-Enforceable Framing: In addition to repeatedly emphasizing that the size, complexity, and risk profile of each banking organization will drive the risk profile for third-party relationships, the Agencies specifically provide that non-compliance with the Proposed TPRM Guidance, or deviation from its examples, would not alone result in supervisory action or an adverse finding. At the same time, the Proposed TPRM Guidance preserves the Agencies’ ability to act with respect to violations of law or regulation, unsafe or unsound practices, or other material risks that result from insufficient management of third-party risk.
  • Regulatory Impact/Deregulatory Positioning. The 2023 Guidance does not include an executive-order analysis, while the Proposed TPRM Guidance is expected to be a “deregulatory action” under EO 14192 because it would provide supervisory clarity that may result in greater efficiencies and streamlining in banking organizations’ third-party risk management functions. This framing supports arguments for proportionate compliance budgets tied to assessed risk.
  • Core Provider Supervision as a Targeted Companion Action: The Joint Statement complements the Proposed TPRM Guidance’s broader flexibility theme by identifying core-provider practices that may shape supervisory attention for community banking organizations, including transparency, contract features, and technology capabilities. It gives community banks a clearer framework for elevating core-provider concerns without turning the Proposed TPRM Guidance back into a universal checklist.
  • Federal Reserve Community Bank Resources: The proposed Community Bank Guide provides Federal Reserve-supervised traditional community banks with a more targeted supervisory framework for their highest-risk third-party relationships. It translates the Proposed TPRM Guidance’s high-level principles into practical, vendor-specific risk management considerations for traditional community banking organizations (“TCBOs”). Because the Community Bank Guide is non-enforceable and would not establish de facto supervisory standards, it is intended to serve as a resource rather than a compliance checklist.

Practical Implications and Next Steps

Together, the Proposed TPRM Guidance and Joint Statement should afford banking organizations greater flexibility to tailor third-party risk management programs to the actual risk profile of each relationship, while establishing a more targeted supervisory framework for core providers to community banks. By replacing enumerated lists of contract terms and oversight considerations with high-level illustrations, expressly framing the guidance as non-enforceable, and deferring to a banking organization’s reasonable judgment, the Proposed TPRM Guidance may support greater efficiencies and more proportionate compliance investments while reducing barriers to engaging newer and innovative third-party providers. The inclusion of the NCUA as a co-proposing agency also extends the interagency framework to federally insured credit unions for the first time, broadening the population of institutions that will need to assess the Proposed TPRM Guidance’s impact on their existing programs.

At the same time, as banking organizations increasingly rely on third parties for critical technology and data-processing functions, these relationships expand the attack surface for cybersecurity threats, including unauthorized access to sensitive customer data, ransomware, and supply chain compromises. The Proposed TPRM Guidance’s discussion of operational resilience planning—including examples such as alternative back-up providers, data backup at physically and logically separated sites, and the ability to resume operations and preserve data following disruption events or cyberattacks—should be read together with the Joint Statement’s focus on core providers’ technology investments, computer security incidents, end-of-support and end-of-life asset management, and demonstrated operational resilience capabilities.

Banking organizations should use the comment period—which closes November 16, 2026—to evaluate how the Proposed TPRM Guidance aligns with their existing risk management frameworks and to advocate for additional clarity where the principles-based approach may leave material compliance questions unresolved. In particular, institutions may consider whether the guidance provides sufficient direction on the permissible scope of reliance on alternative diligence sources, the practical boundaries of the Agencies’ stated deference to a banking organization’s reasonable judgment, whether the guidance should apply only to third parties subject to written agreements, and whether additional third-party risk management guidance documents, interpretive letters, or other resources should be rescinded.

Traditional community banks supervised by the Federal Reserve should also consider whether the proposed Community Bank Guide provides the appropriate level of detail for their needs—detailed enough to be a practical resource but not so prescriptive as to establish de facto supervisory standards. The Federal Reserve specifically requests comment on whether the $30 billion asset threshold appropriately defines the scope of “traditional community banking organizations,” whether the eight vendor categories cover the third-party relationships most relevant to TCBOs, and whether “deposit placement networks” should be added as an additional vendor category.

 


 

1 Proposed Third-Party Risk Management Guidance, 91 Fed. Reg. 58,536 (Sept. 15, 2026).

2 Bd. of Governors of the Fed. Rsrv. Sys. et al., Joint Statement on Community Banks’ Engagement with Core Service Providers (Sept. 11, 2026).

3 Proposed Third-Party Risk Management Guide for Traditional Community Banking Organizations, 91 Fed. Reg. 58,438 (Sept. 15, 2026).

4 Interagency Guidance on Third-Party Relationships: Risk Management, 88 Fed. Reg. 37,920 (June 9, 2023).

最新のInsightsをお届けします

クライアントの皆様の様々なご要望にお応えするための、当事務所の多分野にまたがる統合的なアプローチをご紹介します。
購読する