Third-Party Risk Management: New Interagency Guidance
Third-Party Risk Management: New Interagency Guidance
Proposed Interagency Third-Party Risk Management Guidance: What Community Financial Institutions Need to Know
On September 11, 2026, the OCC, Federal Reserve Board, FDIC, and NCUA (collectively, the agencies) issued proposed interagency guidance to revamp third-party risk management (TPRM) standards.
This proposal aims to replace the previous 2023 Guidance. It moves away from rigid, one-size-fits-all requirements and encourages community banks and credit unions to tailor risk oversight to specific risk levels.
Core Takeaways for Community Banks & Credit Unions
- True Risk-Based Focus: Regulators emphasize that not all vendor relationships carry equal risk. Institutions can streamline oversight for lower-risk vendors (e.g., facilities management or routine software) and focus resources on material financial risks or legal compliance.
- Non-Enforceable Supervisory Guidance: The proposal explicitly clarifies that this guidance sets no enforceable standards. Non-compliance alone will not trigger supervisory actions or adverse exam findings, protecting institutions from “check-the-box” regulatory penalties.
- Support for Responsible Fintech Innovation: The draft removes overly restrictive language that previously discouraged partnerships with newer fintech firms or innovative vendors.
- Explicit Acceptance of Residual Risk: Agencies acknowledge that risk cannot be eliminated entirely. Institutions are given clear leeway to accept residual risk when bargaining power or information access is limited, provided operations remain safe and sound.
- Inclusion of Credit Unions (NCUA): Unlike the 2023 guidance, the NCUA has joined the OCC, Federal Reserve, and FDIC in issuing this proposal – establishing a unified, consistent framework across both community banks and credit unions.
- Dedicated Community Bank Companion Guide: In tandem with the interagency draft, the Federal Reserve released a specific companion guide tailored to traditional community banks, offering practical, non-complex implementation examples.
Key Changes from the 2023 TPRM Guidance
- Shift Away from Activity-Based Triggers: Under 2023 rules, any relationship tied to a “critical activity” triggered intensive oversight. The new proposal focuses instead on the actual magnitude and likelihood of potential harm from the specific relationship.
- Elimination of Prescriptive Checklists: The agencies recognized that prior guidance unintentionally incentivized process-heavy compliance. The new framework cuts back on detailed, idealized scenarios that do not match real-world vendor interactions.
- Flexible Inventory & Due Diligence Requirements: Community institutions are no longer expected to maintain extensive oversight inventories for low-risk vendors. Due diligence requirements can leverage public, industry, or third-party group resources.
- Core Provider & Bargaining Power Leeway: Paired with a joint statement on core service providers, the proposal explicitly acknowledges that smaller institutions often face limited leverage with large tech vendors, allowing banks to document and accept residual risk without penalty
Important Deadlines & Timeline
- Public Comment Deadline: Comments on the proposed guidance are due by November 16, 2026 (60 days following the September 15, 2026, publication in the Federal Register).
- Current Operative Standard: Until the new version is officially finalized and published, the existing 2023 guidance remains the active, operative standard for bank examiners.
- Expected Finalization: Finalization of this new proposal is unlikely to occur before 2027, giving institutions ample time to evaluate their internal vendor risk frameworks.
What This Means for Strunk Customers
For institutions using Strunk’s Vendor Manager, this regulatory shift brings much-needed flexibility and practicality. By reducing administrative friction on low-risk vendors, your team can redirect focus toward core systems and high-priority partners. With customizable workflows, automated contract tracking, and residual risk monitoring built right into Vendor Manager, maintaining alignment with your institution’s risk appetite has never been more seamless.



