Skip to main content
Ground to sky angle of skyscrapers in London's financial district.

What the Agencies’ TPRM Overhaul Signals for Bank Oversight

Explore how the proposed TPRM guidance may affect banks and vendor risk programs.

On September 11, 2026, the Federal Reserve Board (FRB), FDIC, Office of the Comptroller of the Currency (OCC), and National Credit Union Administration (NCUA) jointly proposed the most significant rewrite of the third-party risk management (TPRM) framework since the 2023 Interagency Guidance took effect. Rather than reorganizing the same prescriptive framework, the proposal reflects a deliberate shift in supervisory philosophy. The proposal moves toward a model centered on the magnitude and likelihood of risk a third-party relationship presents to an institution.

Alongside the proposal, the FRB, FDIC, and OCC issued a Joint Statement on Community Banks’ Engagement With Core Service Providers, and the FRB separately proposed a companion implementation guide for traditional community banking organizations (TCBOs). Together, these actions reflect a recalibration of the theory underlying third-party oversight, away from prescriptive process and toward proportionate, risk-based judgment.

What’s Actually Changing: The Proposed Guidance Against the 2023 TPRM Guidance

The agencies have indicated that the 2023 guidance was, in practice, interpreted too broadly as institutions applied extensive diligence and monitoring across a wide range of third-party relationships without adequately weighing the actual magnitude and likelihood of risk. Further, a framework organized around whether an activity was “critical” encouraged process-driven compliance rather than judgment, which diverted resources from the relationships that pose the greatest real exposure.

By reorganizing guidance around risk identification and assessment as the foundation, the proposal asks institutions to make risk, not taxonomy, the starting point of every oversight decision.

Key Topic Areas Across the Issuance

Topic2023 Guidance1Text of Proposed Guidance2What This Means
Stated Purpose of the Guidance
  • Focused on managing risk throughout the entire third-party relationship life cycle.
  • Emphasized developing and implementing controls throughout planning, due diligence, contracting, monitoring, and termination.
  • Focuses on aligning oversight activities to the assessed risk level of each relationship.
  • Emphasizes risk-based tailoring and proportionality.
  • The proposal shifts the focus from demonstrating complete life-cycle coverage to demonstrating that oversight activities are proportionate to the level of risk presented by the relationship.
Basis for Heightened Oversight
  • Called for risk management practices to be tailored to an institution’s size, complexity, risk profile, and third-party relationships.
  • In practice, heightened oversight was largely associated with relationships supporting “critical activities.”
  • Argues that the current framework focuses too heavily on the activity being performed rather than the actual risk posed by the relationship.
  • Shifts heightened oversight decisions to the magnitude and likelihood of harm.
  • The framework shifts from a chronological process model to a risk-centered model.
  • Institutions may need to revisit program structure, documentation, and reporting, not just individual procedures.
Organizing StructureOrganized around a five-stage life cycle:
  • Planning
  • Due diligence and selection
  • Contract negotiation
  • Ongoing monitoring
  • Termination
Organized around four risk-based components:
  • Risk identification and assessment
  • Risk oversight
  • Residual risk acceptance
  • Governance
  • The framework shifts from a chronological process model to a risk-centered model.
  • Institutions may need to revisit program structure, documentation, and reporting, not just individual procedures.
Residual Risk Acceptance
  • Residual risk was addressed indirectly through monitoring and governance activities.
  • No standalone requirement existed for residual risk acceptance.
  • Establishes residual risk acceptance as a distinct program component.
  • Calls for documented approval of decisions to accept remaining risk after controls are applied.
  • Institutions should consider formalizing a residual risk sign-off process.
  • Decisions to accept risk will require documented rationale and accountability.
Diagnosis of Current PracticeThe 2023 Guidance contains no comparable guidance.
  • States that institutions often applied enhanced oversight too broadly.
  • Suggests the 2023 framework unintentionally encouraged process-driven compliance instead of prioritizing higher-risk relationships.
  • Examiners may place greater emphasis on whether resources are focused on the relationships presenting the greatest risk.
  • The quality of risk-based decision-making may matter more than the completeness of documentation.
“Should” Language & Prescriptiveness
  • Emphasized that supervisory guidance is not law and does not create new regulatory requirements.
  • Acknowledges that institutions often interpreted examples and “should” statements as mandatory requirements.
  • Notes that this contributed to checklist-driven compliance approaches
  • Institutions should avoid treating examples in the proposed guidance as mandatory controls.
  • Documentation should demonstrate deliberate, risk-based choices rather than universal adoption of every suggested practice.
Engagement With Fintech & Innovative Third PartiesThe 2023 Guidance contains no comparable guidance.
  • Recognizes that the 2023 framework may have discouraged relationships with newer or innovative providers.
  • Acknowledges that these firms can provide valuable products, services, and economic opportunities.
  • Institutions may have greater flexibility to pursue fintech partnerships.
  • Risk management expectations remain, but innovation itself is no longer implicitly treated as a risk factor.
Tailoring by Size & Complexity
  • Directed institutions to consider their size, complexity, risk profile, and third-party relationships when designing oversight programs.
  • Retains the same principle of tailoring oversight to institutional characteristics and relationship risk.
  • The principle is not new.
  • What changes is the mechanism for applying it, with greater emphasis on risk-magnitude assessments as the basis for tailoring oversight.
Governance Expectations
  • Expected board and senior management oversight throughout the third-party relationship life cycle.
  • Retains governance as a core component.
  • Places greater emphasis on demonstrating why a particular level of oversight was selected for a relationship.
  • Governance shifts from evidencing process adherence to evidencing risk-based judgment.
  • Board and management reporting should clearly explain the rationale behind oversight decisions.

Joint Statement on Community Banks’ Engagement With Core Service Providers

Alongside the proposal, the FRB, FDIC, and OCC separately issued a Joint Statement on Community Banks’ Engagement With Core Service Providers, addressing community banks’ relationships with the small number of firms that provide core processing and related infrastructure. The statement is not a new rule and does not alter existing TPRM guidance; rather, it flags four areas of supervisory concern that examiners will weigh when assessing these relationships:

  • Provider transparency. Whether core providers furnish community banks with sufficient information to understand and monitor the services they receive.
  • Contracting practices. Whether contract terms, including exit and termination rights, leave community banks with adequate negotiating leverage and flexibility.
  • Technology resiliency. Whether providers maintain the operational resilience and incident-response capacity needed to support the banks that depend on them.
  • Market concentration. Whether reliance on a small number of dominant core providers concentrates risk across the banking system.

Notably, the statement explains that these four factors may influence supervisory and enforcement decisions involving certain core providers directly, not only the community banks that use them. Institutions should read this as a signal that examiners may scrutinize core provider relationships more closely going forward, and that community banks should be prepared to demonstrate they understand, and have pressure-tested, the transparency, contracting, resiliency, and concentration risk posed by their core providers.

The FRB’s Companion TPRM Guide for TCBOs

In addition, the FRB proposed a companion TPRM guide for TCBOs. The guide is intended to help TCBOs operationalize the principles in the broader interagency proposal, articulating how those high-level principles can be applied in practice and providing risk management considerations on a vendor-by-vendor basis across eight categories:

  • Core service providers
  • Information technology infrastructure
  • Cybersecurity
  • Payment processing and digital banking
  • Loan management systems
  • Card issuing and processing
  • Bank Secrecy Act (BSA)/anti-money laundering and financial crime platforms
  • Fraud prevention and detection

The guide would not be a rule, and institutions would not be required to take action. The FRB has indicated the guide is intended only for TCBOs and not designed for community banking organizations with more complex business models or third-party relationship profiles. Comments are due 60 days after Federal Register publication.

The updated guidance reinforces that the agencies want documented evidence that institutions consciously chose a level of oversight commensurate with its risk. Governance remains the capstone, but its expectations shift from demonstrating process adherence to demonstrating reasoned calibration or recalibration. Importantly, this does not relax accountability for institutions. Outsourcing an activity still does not outsource responsibility for its risks. What changes is where institutional effort should concentrate.

What Institutions Should Do Now

While the guidance remains a proposal and is non-binding, institutions should not wait for the comment period to close before mobilizing. Below are practical steps you can take as the proposal works its way toward finalization:

  • Revisit vendor tiering criteria. Where tiering is currently anchored to a fixed “critical activities” list, begin mapping relationships instead to assessed magnitude and likelihood of harm, and document the rationale for each tier assignment.
  • Build a residual risk sign-off step into the program. Institutions should formalize a discrete step where the decision to accept residual risk, after tailoring oversight, is documented and approved.
  • Refresh governance documentation. Board and senior management reporting should be updated to demonstrate not just that oversight occurred, but why the chosen level of oversight was appropriate for each relationship’s risk profile.
  • Consider submitting a comment letter. Institutions with practical experience applying the 2023 guidance, particularly around fintech engagement, core provider negotiating leverage, or examiner interpretation of “should” language, have a 60-day window to shape the final guidance.

How Forvis Mazars Can Help

In the heavily regulated banking industry, leaders face more challenges than ever, from striving to meet shareholder and regulatory expectations to pursuing digital innovation. Our team can help you redesign vendor tiering and residual risk sign-off, refresh board and senior management reporting, benchmark core provider relationships against the Joint Statement, and right-size your TPRM program. We have the skills and experience in financial services that you can trust, combining a focus on delivering an Unmatched Client Experience® with the resources of a global firm. Serving you is our passion and privilege.

If you have any questions or need assistance, please reach out to a professional at Forvis Mazars.

  • 12023 Interagency Guidance on Third-Party Relationships: Risk Management, Federal Register 88 FR 37920 (Document 2023-12340).
  • 2Proposed Third-Party Risk Management Guidance, OCC nr-ia-2026-77a.pdf.

Related FORsights

Like what you see?
Subscribe to receive tailored insights directly to your inbox.