On September 11, 2026, the Federal Reserve Board (FRB), the Federal Deposit Insurance Corporation (FDIC), the Office of the Comptroller of the Currency (OCC), and the National Credit Union Administration (NCUA) (collectively, the “Agencies”) issued proposed interagency guidance (the “Proposed Guidance”) that would replace the Agencies’ 2023 guidance (the “2023 Guidance”) on third-party risk management. For an overview of the 2023 Guidance, please see our prior client alert.
In a joint press release accompanying the Proposed Guidance, the Agencies stated that they would “move away from overly broad, process-driven approaches, make clear that there is no one-size-fits-all approach to third-party risk management, and encourage responsible innovation.”
The Agencies plan on rescinding the 2023 Guidance when the Proposed Guidance is finalized.
Comments on the Proposed Guidance are due by November 16, 2026.
Key Takeaways
- The Proposed Guidance signals a greater acceptance of bank-fintech partnerships and a focus on addressing material financial risks and violations of laws and regulations, in keeping with broader policy priorities.
- The Proposed Guidance retains a principles-based approach focused on tailoring risk management practices toward a bank’s size, complexity, risk profile, and the nature of its third-party relationships.
- Banks would ultimately remain liable under the Proposed Guidance for the actions that their third-party service providers take when performing regulated banking activities. Fintechs should not anticipate any relaxation in scrutiny from their bank partners.
The Proposed Guidance
The Proposed Guidance retains overarching themes from the 2023 Guidance, including a tailored approach to risk management, a focus on higher-risk relationships, and recommended risk management practices at each stage of a third-party relationship. Nevertheless, the Proposed Guidance represents a shift in supervisory approach from what the Agencies characterize as a prescriptive and “overly detailed” framework in the 2023 Guidance toward one focused on material financial risks.
Key differences between the 2023 Guidance and the Proposed Guidance include:
- More Favorable View of Fintech Partnerships: The Agencies acknowledge that the 2023 Guidance has been read to discourage arrangements with newer and innovative third parties because it indicates that they may present elevated risks. The Proposed Guidance recognizes that while a third-party fintech partner may not have a long operational history, permit onsite visits, or be permitted to share certain information that a banking organization requests, a banking organization may determine that other factors offset or compensate for those limitations. The Proposed Guidance also references the May 2026 Executive Order, titled “Integrating Financial Technology Innovation Into Regulatory Frameworks,” which directs the federal government to remove regulatory and supervisory barriers to entry for financial technology companies.
- Restructured Risk Management Components: The Proposed Guidance presents four risk management “components” that banking organizations may consider: (1) identifying and assessing applicable risks; (2) overseeing risks proportionate to their significance; (3) making informed decisions about residual risks and risk acceptance; and (4) establishing appropriate governance practices. These components bear resemblance to the “life cycle” for risk management established by the 2023 Guidance but are less detailed and prescriptive, omitting lists of factors banks should consider in areas such as contract negotiation and ongoing monitoring. The Proposed Guidance notably elevates risk identification and assessment, stating that this approach will enable organizations and examiners to focus on material financial risks and violations of laws and regulations rather than “check-the-box exercises.”
- Elimination of the Critical Activities Framework: Under the 2023 Guidance, banking organizations are expected to apply more rigorous oversight of third-party relationships that support critical activities that could cause a bank to face significant risk in the event of failure, have significant customer impact, or are financially impactful to the bank. Under the Proposed Guidance, banks would be expected to focus on the magnitude and likelihood of the potential harm arising from a third-party relationship. In practice, many third-party relationships that banks previously deemed critical may fall under the definition of “higher risk” third-party relationships in the Proposed Guidance; however, the concept of “critical activities” would be eliminated from the Agencies’ approach. “Higher-risk” relationships are defined as ones that, if disrupted, could (i) result in a non-trivial violation of law or regulation; or (ii) pose material harm to the banking organization’s financial condition (where there is a material likelihood that such disruption may occur).
- Greater Deference to Banks: The Proposed Guidance states that risk assessments are bank-specific and subject to change, and notes that examiners will give consideration to a banking organization’s “reasonable judgment” regarding risk assessments, a level of deference not present in the 2023 Guidance. The Proposed Guidance states that deviation or inconsistency from the Proposed Guidance alone should not serve as the basis for supervisory action and that the Agencies do not expect banking organizations to entirely eliminate third-party risk.
- Relaxed Third-Party Inventory Requirements: Under the 2023 Guidance, the Agencies expect banking organizations to complete and maintain an inventory of all third-party relationships. The Proposed Guidance takes a more flexible approach. While it states that maintaining an inventory of third-party relationships “may be useful” for managing risks, the Proposed Guidance acknowledges that “banking organizations may decide not to maintain extensive inventories of relationships posing limited risk, such as those related to administrative or clerical tasks, professional support services (including auditing and legal advice), or office support services (including physical security).”
- Ability to Leverage New Risk Management Arrangements: In an addition from the 2023 Guidance, the Proposed Guidance would acknowledge that banks can leverage “new arrangements” to mitigate third-party risk, including participating in a co-venture or consortium that collaborates on third-party risk management, participating in a standard-setting organization, or considering the results from services provided by consultants, auditors, or law firms.
- This addition is notable given 2023 remarks by then-FDIC Board member Travis Hill suggesting that the FDIC consider facilitating a public/private standard-setting organization for financial technology companies, and may signal the potential for future action by the FDIC (or the Agencies, more broadly) to facilitate development of such an organization.
- Applicability to Credit Unions: Unlike the 2023 Guidance, the NCUA is included in the Proposed Guidance, suggesting it would apply to credit unions alongside banks.
As with the 2023 Guidance, the Proposed Guidance, if finalized, would be non-binding. The Agencies note that it would not set forth enforceable standards or prescriptive requirements, and, accordingly, non-compliance with the Proposed Guidance would not result in supervisory action against a banking organization.
Our View
If finalized as proposed, the Proposed Guidance would move from a process-driven approach in evaluating banks’ third-party partnerships to an approach focused on identifying and mitigating the risks with the highest likelihood and greatest potential impact. Alongside other actions, such as the recent FDIC and OCC joint final rule on Unsafe or Unsound Practices and Matters Requiring Attention, the Proposed Guidance signals a broader shift in the Agencies’ focus toward prioritizing material financial risks and adopting a tailored approach to supervision.
The Proposed Guidance may also foreshadow an effort by the Agencies to help create a standard-setting organization for fintechs, which could give banks assurance when partnering with fintechs endorsed by such an organization.
At the same time, banks should take note that the Proposed Guidance would reiterate a core principle present in the 2023 Guidance: a bank’s use of third parties does not diminish its responsibility to establish and maintain sound risk management practices and to comply with applicable laws and regulations. A bank is ultimately responsible for activities performed by third parties that implicate these obligations to the same extent as if the activities were performed by the banking organization internally. If the Proposed Guidance is adopted, banks should proceed with caution in modifying third-party risk management policies or practices and should consider that nothing in the Proposed Guidance would constitute an explicit safe harbor from regulatory scrutiny or enforcement actions.
By the same token, fintechs should anticipate incremental, rather than immediate, action from banks to change their third-party risk management policies and practices if the Proposed Guidance is adopted. Given the focus of the Proposed Guidance on the risk identification and assessment stage, fintechs should be prepared to discuss risk mitigation at the outset when engaging in discussions with potential bank partners and should have on hand applicable policies and procedures, such as record retention and Bank Secrecy Act/Anti-Money-Laundering (BSA/AML) policies, that banks may expect to review when performing initial diligence.
Fintechs should also note that the Proposed Guidance does not constitute a wholesale relaxation of the Agencies’ scrutiny of fintechs that partner with banks. In a separate Joint Statement issued on the same day as the Proposed Guidance, the Agencies signaled that they intend to more closely scrutinize service providers that provide critical systems applications and infrastructure to community banking organizations, including bringing enforcement actions directly against these service providers where warranted. Also on the same day, the Federal Reserve separately proposed a companion third-party risk management guide tailored to traditional community banking organizations, and Governor Lisa Cook issued a statement highlighting the need for additional resources to help community banks evaluate complex technology vendors and core service providers.
Taken together, these developments suggest that fintech and other complex technology providers will remain a significant area of supervisory interest even as the Agencies move toward a more flexible and risk-based third-party risk management framework.