Strunk
  • Compliance
  • Profitabilty
    • Pricing Manager
    • ODP Manager
    • Econocheck
  • Connect
    • The Strunk Perspective
    • Contact Us
  • Login
  • DEMO
  • Menu Menu
  • Link to X
  • Link to LinkedIn

Third-Party Risk Management: New Interagency Guidance

October 7, 2026/in Banks, Compliance, Credit Unions, Financial Services, Markets, Sales, Vendor Manager/by Teresa Pezdek

Third-Party Risk Management: New Interagency Guidance

Proposed Interagency Third-Party Risk Management Guidance: What Community Financial Institutions Need to Know

On September 11, 2026, the OCC, Federal Reserve Board, FDIC, and NCUA (collectively, the agencies) issued proposed interagency guidance to revamp third-party risk management (TPRM) standards.

This proposal aims to replace the previous 2023 Guidance. It moves away from rigid, one-size-fits-all requirements and encourages community banks and credit unions to tailor risk oversight to specific risk levels.

Core Takeaways for Community Banks & Credit Unions

  • True Risk-Based Focus: Regulators emphasize that not all vendor relationships carry equal risk. Institutions can streamline oversight for lower-risk vendors (e.g., facilities management or routine software) and focus resources on material financial risks or legal compliance.
  • Non-Enforceable Supervisory Guidance: The proposal explicitly clarifies that this guidance sets no enforceable standards. Non-compliance alone will not trigger supervisory actions or adverse exam findings, protecting institutions from “check-the-box” regulatory penalties.
  • Support for Responsible Fintech Innovation: The draft removes overly restrictive language that previously discouraged partnerships with newer fintech firms or innovative vendors.
  • Explicit Acceptance of Residual Risk: Agencies acknowledge that risk cannot be eliminated entirely. Institutions are given clear leeway to accept residual risk when bargaining power or information access is limited, provided operations remain safe and sound.
  • Inclusion of Credit Unions (NCUA): Unlike the 2023 guidance, the NCUA has joined the OCC, Federal Reserve, and FDIC in issuing this proposal – establishing a unified, consistent framework across both community banks and credit unions.
  • Dedicated Community Bank Companion Guide: In tandem with the interagency draft, the Federal Reserve released a specific companion guide tailored to traditional community banks, offering practical, non-complex implementation examples.

Key Changes from the 2023 TPRM Guidance

  • Shift Away from Activity-Based Triggers: Under 2023 rules, any relationship tied to a “critical activity” triggered intensive oversight. The new proposal focuses instead on the actual magnitude and likelihood of potential harm from the specific relationship.
  • Elimination of Prescriptive Checklists: The agencies recognized that prior guidance unintentionally incentivized process-heavy compliance. The new framework cuts back on detailed, idealized scenarios that do not match real-world vendor interactions.
  • Flexible Inventory & Due Diligence Requirements: Community institutions are no longer expected to maintain extensive oversight inventories for low-risk vendors. Due diligence requirements can leverage public, industry, or third-party group resources.
  • Core Provider & Bargaining Power Leeway: Paired with a joint statement on core service providers, the proposal explicitly acknowledges that smaller institutions often face limited leverage with large tech vendors, allowing banks to document and accept residual risk without penalty

Important Deadlines & Timeline

  • Public Comment Deadline: Comments on the proposed guidance are due by November 16, 2026 (60 days following the September 15, 2026, publication in the Federal Register).
  • Current Operative Standard: Until the new version is officially finalized and published, the existing 2023 guidance remains the active, operative standard for bank examiners.
  • Expected Finalization: Finalization of this new proposal is unlikely to occur before 2027, giving institutions ample time to evaluate their internal vendor risk frameworks.

What This Means for Strunk Customers

For institutions using Strunk’s Vendor Manager, this regulatory shift brings much-needed flexibility and practicality. By reducing administrative friction on low-risk vendors, your team can redirect focus toward core systems and high-priority partners. With customizable workflows, automated contract tracking, and residual risk monitoring built right into Vendor Manager, maintaining alignment with your institution’s risk appetite has never been more seamless.

 

Share this entry
  • Share on Facebook
  • Share on X
  • Share on WhatsApp
  • Share on Pinterest
  • Share on LinkedIn
  • Share on Tumblr
  • Share on Vk
  • Share on Reddit
  • Share by Mail
https://strunkaccess.com/wp-content/uploads/2026/10/third-party-risk-management-new-interagency-guidance.jpg 854 1280 Teresa Pezdek https://strunkaccess.com/wp-content/uploads/2022/03/Strunk-Original-300x100.png Teresa Pezdek2026-10-07 10:00:152026-10-05 15:50:38Third-Party Risk Management: New Interagency Guidance

Recent Articles

  • Third-Party Risk Management: New Interagency GuidanceOctober 7, 2026 - 10:00 am
  • How do regulators evaluate fair lending risk in a community bank’s loan pricing process?September 30, 2026 - 10:00 am
  • Your Core Can’t Manage Your Overdraft ProgramSeptember 23, 2026 - 10:00 am
  • How Centralized Tracking Elevates Compliance & EfficiencySeptember 16, 2026 - 10:00 am

GRC Topics

  • Banks
  • COCC
  • Compliance
  • Credit Unions
  • Financial Services
  • FINSYNC
  • Markets
  • Overdraft Privilege
  • Perspectives
  • Policy Manager
  • Pricing Manager
  • Risk Manager
  • Sales
  • Secure Checking
  • SOC2
  • Tips
  • Uncategorized
  • Vendor Manager
  • WBA
Schedule A Demo

An independent certified public accountant has examined Strunk’s operations and found them to be in compliance with the AICPA’s Trust Service Principles. It was determined that Strunk meets the Security, Availability, Processing Integrity, Confidentiality, and Privacy criteria for SOC 2 established by the AICPA.

© Copyright - Strunk | Privacy Policy | Security Policy | Business Continuity Policy
Scroll to top Scroll to top Scroll to top