On September 11, 2026, the Federal Reserve Board (FRB), FDIC, Office of the Comptroller of the Currency (OCC), and National Credit Union Administration (NCUA) jointly proposed the most significant rewrite of the third-party risk management (TPRM) framework since the 2023 Interagency Guidance took effect. Rather than reorganizing the same prescriptive framework, the proposal reflects a deliberate shift in supervisory philosophy. The proposal moves toward a model centered on the magnitude and likelihood of risk a third-party relationship presents to an institution.
Alongside the proposal, the FRB, FDIC, and OCC issued a Joint Statement on Community Banks’ Engagement With Core Service Providers, and the FRB separately proposed a companion implementation guide for traditional community banking organizations (TCBOs). Together, these actions reflect a recalibration of the theory underlying third-party oversight, away from prescriptive process and toward proportionate, risk-based judgment.
What’s Actually Changing: The Proposed Guidance Against the 2023 TPRM Guidance
The agencies have indicated that the 2023 guidance was, in practice, interpreted too broadly as institutions applied extensive diligence and monitoring across a wide range of third-party relationships without adequately weighing the actual magnitude and likelihood of risk. Further, a framework organized around whether an activity was “critical” encouraged process-driven compliance rather than judgment, which diverted resources from the relationships that pose the greatest real exposure.
By reorganizing guidance around risk identification and assessment as the foundation, the proposal asks institutions to make risk, not taxonomy, the starting point of every oversight decision.
Key Topic Areas Across the Issuance
| Topic | 2023 Guidance1 | Text of Proposed Guidance2 | What This Means |
|---|---|---|---|
| Stated Purpose of the Guidance |
|
|
|
| Basis for Heightened Oversight |
|
|
|
| Organizing Structure | Organized around a five-stage life cycle:
| Organized around four risk-based components:
|
|
| Residual Risk Acceptance |
|
|
|
| Diagnosis of Current Practice | The 2023 Guidance contains no comparable guidance. |
|
|
| “Should” Language & Prescriptiveness |
|
|
|
| Engagement With Fintech & Innovative Third Parties | The 2023 Guidance contains no comparable guidance. |
|
|
| Tailoring by Size & Complexity |
|
|
|
| Governance Expectations |
|
|
|
Joint Statement on Community Banks’ Engagement With Core Service Providers
Alongside the proposal, the FRB, FDIC, and OCC separately issued a Joint Statement on Community Banks’ Engagement With Core Service Providers, addressing community banks’ relationships with the small number of firms that provide core processing and related infrastructure. The statement is not a new rule and does not alter existing TPRM guidance; rather, it flags four areas of supervisory concern that examiners will weigh when assessing these relationships:
- Provider transparency. Whether core providers furnish community banks with sufficient information to understand and monitor the services they receive.
- Contracting practices. Whether contract terms, including exit and termination rights, leave community banks with adequate negotiating leverage and flexibility.
- Technology resiliency. Whether providers maintain the operational resilience and incident-response capacity needed to support the banks that depend on them.
- Market concentration. Whether reliance on a small number of dominant core providers concentrates risk across the banking system.
Notably, the statement explains that these four factors may influence supervisory and enforcement decisions involving certain core providers directly, not only the community banks that use them. Institutions should read this as a signal that examiners may scrutinize core provider relationships more closely going forward, and that community banks should be prepared to demonstrate they understand, and have pressure-tested, the transparency, contracting, resiliency, and concentration risk posed by their core providers.
The FRB’s Companion TPRM Guide for TCBOs
In addition, the FRB proposed a companion TPRM guide for TCBOs. The guide is intended to help TCBOs operationalize the principles in the broader interagency proposal, articulating how those high-level principles can be applied in practice and providing risk management considerations on a vendor-by-vendor basis across eight categories:
- Core service providers
- Information technology infrastructure
- Cybersecurity
- Payment processing and digital banking
- Loan management systems
- Card issuing and processing
- Bank Secrecy Act (BSA)/anti-money laundering and financial crime platforms
- Fraud prevention and detection
The guide would not be a rule, and institutions would not be required to take action. The FRB has indicated the guide is intended only for TCBOs and not designed for community banking organizations with more complex business models or third-party relationship profiles. Comments are due 60 days after Federal Register publication.
The updated guidance reinforces that the agencies want documented evidence that institutions consciously chose a level of oversight commensurate with its risk. Governance remains the capstone, but its expectations shift from demonstrating process adherence to demonstrating reasoned calibration or recalibration. Importantly, this does not relax accountability for institutions. Outsourcing an activity still does not outsource responsibility for its risks. What changes is where institutional effort should concentrate.
What Institutions Should Do Now
While the guidance remains a proposal and is non-binding, institutions should not wait for the comment period to close before mobilizing. Below are practical steps you can take as the proposal works its way toward finalization:
- Revisit vendor tiering criteria. Where tiering is currently anchored to a fixed “critical activities” list, begin mapping relationships instead to assessed magnitude and likelihood of harm, and document the rationale for each tier assignment.
- Build a residual risk sign-off step into the program. Institutions should formalize a discrete step where the decision to accept residual risk, after tailoring oversight, is documented and approved.
- Refresh governance documentation. Board and senior management reporting should be updated to demonstrate not just that oversight occurred, but why the chosen level of oversight was appropriate for each relationship’s risk profile.
- Consider submitting a comment letter. Institutions with practical experience applying the 2023 guidance, particularly around fintech engagement, core provider negotiating leverage, or examiner interpretation of “should” language, have a 60-day window to shape the final guidance.
How Forvis Mazars Can Help
In the heavily regulated banking industry, leaders face more challenges than ever, from striving to meet shareholder and regulatory expectations to pursuing digital innovation. Our team can help you redesign vendor tiering and residual risk sign-off, refresh board and senior management reporting, benchmark core provider relationships against the Joint Statement, and right-size your TPRM program. We have the skills and experience in financial services that you can trust, combining a focus on delivering an Unmatched Client Experience® with the resources of a global firm. Serving you is our passion and privilege.
If you have any questions or need assistance, please reach out to a professional at Forvis Mazars.