{"id":584,"date":"2026-09-17T13:01:13","date_gmt":"2026-09-17T17:01:13","guid":{"rendered":"https:\/\/blogs.duanemorris.com\/bankinglaw\/?p=584"},"modified":"2026-09-17T13:01:14","modified_gmt":"2026-09-17T17:01:14","slug":"overhauled-third-party-risk-management-guidance-what-banks-and-their-vendors-need-to-do-now","status":"publish","type":"post","link":"https:\/\/blogs.duanemorris.com\/bankinglaw\/2026\/09\/17\/overhauled-third-party-risk-management-guidance-what-banks-and-their-vendors-need-to-do-now\/","title":{"rendered":"Overhauled Third-Party Risk Management Guidance: What Banks and Their Vendors Need to Do Now"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">On September 11, 2026, the FDIC, Federal Reserve Board, OCC, and NCUA jointly proposed a package of three <a href=\"https:\/\/www.federalreserve.gov\/newsevents\/pressreleases\/bcreg20260911a.htm\">documents that would reshape third-party risk management<\/a> (&#8220;TPRM&#8221;) oversight for banks and credit unions: (1) new interagency guidance replacing the 2023 TPRM framework, (2) a practical companion guide for community banks, and (3) a joint statement putting core service providers on notice. Comments are due <strong>November 16, 2026<\/strong> \u2014 here is what your institution needs to know.\u00a0<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span style=\"text-decoration: underline\">What Went Wrong With the 2023 Guidance<\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The agencies acknowledge the 2023 framework failed on four fronts: it was interpreted too broadly, drove checklist compliance instead of risk-proportionate oversight, incentivized process over substance, and chilled engagement with fintechs and innovative providers. The bottom line for institutions: disproportionate compliance spending on low-risk relationships and lock-in with legacy vendors.\u00a0<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span style=\"text-decoration: underline\">How the New All-Bank Framework Changes Day-to-Day TPRM<\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The proposed guidance would replace the 2023 Guidance and 2024 community bank resources.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Three shifts matter most for compliance teams:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Risk-Based Prioritization.<\/strong> TPRM practices should be calibrated to the magnitude and likelihood of harm of each relationship \u2014 not merely whether it supports a &#8220;critical activity.&#8221; Lower-risk relationships may warrant less detailed due diligence, standard-form contracts, or less frequent monitoring.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Principles, Not Prescriptions.<\/strong> The guidance is expressly non-binding; non-compliance alone will not trigger supervisory criticism. The framework is organized into four components:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Risk Identification and Assessment<\/strong> \u2014 identifying third-party relationships, cataloguing associated risks, and assessing their severity.<\/li>\n\n\n\n<li><strong>Risk Oversight<\/strong> \u2014 covering due diligence, contract negotiation, ongoing monitoring, termination planning, and cross-cutting topics such as subcontractor oversight, operational resilience, and insurance\/indemnification.<\/li>\n\n\n\n<li><strong>Residual Risk Acceptance<\/strong> \u2014 recognizing that institutions may reasonably accept some amount of residual risk based on their risk appetite.<\/li>\n\n\n\n<li><strong>Governance<\/strong> \u2014 establishing appropriate board and management oversight structures.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Encouraging Innovation.<\/strong> The guidance recognizes co-ventures, consortia for joint due diligence, standard-setting organizations, and third-party consultants as legitimate TPRM strategies \u2014 a clear signal that engaging with fintechs and newer providers should not be treated as inherently higher risk.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span style=\"text-decoration: underline\">New Playbook for Community Banks Under $30 Billion<\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The Federal Reserve separately proposed a <em>Third-Party Risk Management Guide for Traditional Community Banking Organizations<\/em> (&#8220;TCBOs&#8221;) \u2014 institutions under $30 billion focused on serving local communities. Banks with complex bank-fintech partnership models are excluded. The guide gives TCBOs an operational roadmap organized in two parts:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Overarching Risk Management Topics.<\/strong> Four cross-cutting themes applicable to most TCBO third-party relationships:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Operational Resilience<\/strong> \u2014 assessing how a vendor&#8217;s disruptions could impair the institution&#8217;s operations, including through review of SOC reports, penetration testing, and business continuity testing.<\/li>\n\n\n\n<li><strong>System and Information Security<\/strong> \u2014 managing vulnerabilities created when vendors access sensitive banking systems.<\/li>\n\n\n\n<li><strong>Compliance with Rules and Regulations<\/strong> \u2014 ensuring third parties performing regulated functions maintain compliance, including with payment network rules.<\/li>\n\n\n\n<li><strong>Financial Resilience<\/strong> \u2014 evaluating a vendor&#8217;s financial stability, particularly when it is privately held or a newer market entrant.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Vendor-by-Vendor Considerations.<\/strong> The guide identifies eight categories of third parties most commonly used by TCBOs and provides risk-specific guidance for each:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Core Providers<\/li>\n\n\n\n<li>IT Infrastructure Providers<\/li>\n\n\n\n<li>Cybersecurity Providers<\/li>\n\n\n\n<li>Payment Processing and Digital Banking Providers<\/li>\n\n\n\n<li>Loan Management System Providers<\/li>\n\n\n\n<li>Card Issuing and Processing Providers<\/li>\n\n\n\n<li>BSA\/AML and Financial Crime Platform Providers<\/li>\n\n\n\n<li>Fraud Prevention and Detection Providers<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For core providers, the guide addresses core conversion considerations \u2014 costs, integration challenges, and middleware alternatives \u2014 in significant detail.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Board is seeking comment on the $30 billion asset threshold, whether to add &#8220;deposit placement networks&#8221; as a vendor category, and whether the guide&#8217;s detail level risks creating <em>de facto<\/em> supervisory standards.\u00a0<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span style=\"text-decoration: underline\">Core Service Providers Face Direct Supervisory Scrutiny<\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The <em>Joint Statement on Community Banks&#8217; Engagement with Core Service Providers<\/em> (Federal Reserve, FDIC, and OCC) marks a significant escalation. The agencies will now factor three criteria into examination frequency and scope decisions for core providers:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Transparency<\/strong> \u2014 whether a core provider furnishes timely due diligence information, complies with service level agreements, promptly discloses security incidents, and avoids complex billing practices that are difficult for banks to reconcile.<\/li>\n\n\n\n<li><strong>Contract Features<\/strong> \u2014 whether contract terms make it unreasonably difficult for community banks to exit relationships or engage supplemental providers. Examples of problematic terms include opaque pricing, excessive &#8220;back billing&#8221; windows, unsupported deconversion fees, and limitations on third-party integrations with the core platform.<\/li>\n\n\n\n<li><strong>Technology<\/strong> \u2014 whether the core provider invests in maintaining up-to-date systems, including the frequency and severity of security incidents, management of end-of-life assets, and demonstrated operational resilience.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Notably, the agencies state that certain core providers may qualify as &#8220;institution-affiliated parties&#8221; under the Federal Deposit Insurance Act, given the degree to which they participate in the conduct of a bank&#8217;s affairs. This determination could expose core providers to enforcement actions \u2014 a significant escalation in regulatory posture.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Comments on all three proposals are due <strong>November 16, 2026<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><span style=\"text-decoration: underline\">DM Tips<\/span><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>For banking organizations:<\/strong> Begin assessing how the shift from checklist-based compliance to risk-based prioritization would affect your existing TPRM program. Community banks in particular should view the TCBO Guide and core provider statement as new leverage in vendor negotiations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>For core service providers:<\/strong> The agencies are now tying examination frequency and scope to provider-level transparency, contract fairness, and technology investment. The institution-affiliated party discussion adds enforcement teeth to what was previously a supervisory expectations framework.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On September 11, 2026, the FDIC, Federal Reserve Board, OCC, and NCUA jointly proposed a package of three documents that would reshape third-party risk management (&#8220;TPRM&#8221;) oversight for banks and credit unions: (1) new interagency guidance replacing the 2023 TPRM framework, (2) a practical companion guide for community banks, and (3) a joint statement putting &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/blogs.duanemorris.com\/bankinglaw\/2026\/09\/17\/overhauled-third-party-risk-management-guidance-what-banks-and-their-vendors-need-to-do-now\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Overhauled Third-Party Risk Management Guidance: What Banks and Their Vendors Need to Do Now&#8221;<\/span><\/a><\/p>\n","protected":false},"author":693,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"ppma_author":[502],"class_list":["post-584","post","type-post","status-publish","format-standard","hentry","category-general"],"authors":[{"term_id":502,"user_id":693,"is_guest":0,"slug":"jsilvia","display_name":"Joseph E. Silvia","avatar_url":"https:\/\/blogs.duanemorris.com\/bankinglaw\/wp-content\/uploads\/sites\/14\/2024\/09\/silviajoseph-100x100.jpg","author_category":"","last_name":"Silvia","first_name":"Joseph E.","job_title":"","user_url":"https:\/\/www.duanemorris.com\/attorneys\/josephsilvia.html","description":"<a href=\"https:\/\/www.duanemorris.com\/attorneys\/josephsilvia.html\">Read Joseph's bio.<\/a>"}],"_links":{"self":[{"href":"https:\/\/blogs.duanemorris.com\/bankinglaw\/wp-json\/wp\/v2\/posts\/584","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.duanemorris.com\/bankinglaw\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.duanemorris.com\/bankinglaw\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/bankinglaw\/wp-json\/wp\/v2\/users\/693"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/bankinglaw\/wp-json\/wp\/v2\/comments?post=584"}],"version-history":[{"count":1,"href":"https:\/\/blogs.duanemorris.com\/bankinglaw\/wp-json\/wp\/v2\/posts\/584\/revisions"}],"predecessor-version":[{"id":585,"href":"https:\/\/blogs.duanemorris.com\/bankinglaw\/wp-json\/wp\/v2\/posts\/584\/revisions\/585"}],"wp:attachment":[{"href":"https:\/\/blogs.duanemorris.com\/bankinglaw\/wp-json\/wp\/v2\/media?parent=584"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/bankinglaw\/wp-json\/wp\/v2\/categories?post=584"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/bankinglaw\/wp-json\/wp\/v2\/tags?post=584"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/bankinglaw\/wp-json\/wp\/v2\/ppma_author?post=584"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}