Federal Regulators Unveil Overhauled Third-Party Risk Guidance to Ease Burdens on Community Banks and Credit Unions

By PYMNTS
Published September 11, 2026


Main Facts

In a coordinated regulatory push aimed at modernizing oversight and easing compliance pressures, four major U.S. financial regulatory agencies have jointly issued proposed guidance designed to help banks and credit unions better manage the risks associated with third-party relationships.

Announced on Friday, September 11, 2026, the initiative involves the Federal Deposit Insurance Corporation (FDIC), the Federal Reserve Board, the National Credit Union Administration (NCUA), and the Office of the Comptroller of the Currency (OCC).

The proposed framework represents a fundamental shift away from overly broad, one-size-fits-all compliance mandates. Instead, it encourages financial institutions to tailor their third-party risk management (TPRM) practices to the distinct, individual risks posed by specific vendors, fintech partners, and service providers. Once finalized, the non-binding guidance will officially replace existing federal bank regulatory frameworks governing third-party relationships.

Simultaneously, the regulatory bodies are taking targeted aim at the challenges community banks face when negotiating with essential technology vendors. The FDIC, Federal Reserve, and OCC issued a separate joint statement addressing community bank engagement with core service providers (CSPs). This statement clarifies how regulators will evaluate supervisory and enforcement decisions concerning these critical vendors. To complement these efforts, the Federal Reserve also released a specialized, proposed third-party risk management guide tailored explicitly for the community banking organizations under its direct supervision.

The public and industry stakeholders have a 60-day window to submit formal comments on the proposed guidance following its upcoming publication in the Federal Register.


Chronology of Regulatory Action

The journey toward this comprehensive overhaul of third-party risk management has evolved over several years, shaped heavily by the rapid acceleration of bank-fintech partnerships and the increasing digitization of financial services.

  • Early Digital Expansion Era: As community banks and credit unions increasingly turned to third-party technology providers to offer digital wallets, mobile banking applications, and cloud-based infrastructure, existing regulatory frameworks struggled to keep pace. Regulators previously relied on generalized advisory letters that left institutions scrambling to apply enterprise-level risk frameworks to smaller operational contracts.
  • The Interagency Guidance of 2023: Recognizing mounting systemic exposure, the Federal Reserve, FDIC, and OCC issued a landmark joint guidance on third-party risk management in early 2023. While intended to establish a unified standard, smaller financial institutions quickly reported that the expansive requirements created disproportionate operational and financial compliance burdens.
  • Growing Pains for Community Lenders (2024–2025): Throughout 2024 and 2025, trade groups and community banking advocates persistently lobbied federal regulators. They argued that smaller institutions lacked the bargaining power to demand compliance concessions from dominant core service providers, yet were being held strictly accountable by examiners for vendor shortcomings.
  • September 11, 2026 — The Joint Announcement: Reponding to these industry-wide pain points, the FDIC, Federal Reserve, NCUA, and OCC simultaneously released a multi-pronged regulatory package. This package introduced the updated cross-agency guidance, a specific joint statement on core service providers, and a localized Fed companion guide designed to directly alleviate community bank compliance strains.

Supporting Data & Industry Context

The necessity for streamlined third-party risk management is rooted in the operational realities of modern American banking. According to industry data, more than 98% of U.S. community banks and credit unions rely on a handful of dominant core service providers to manage their day-to-day ledger systems, transaction processing, and customer databases.

  • The Core Provider Concentration: A mere three or four major technology companies control the vast majority of the core processing market for community financial institutions. This high market concentration often leaves community banks as "price-takers" with limited leverage to negotiate contract terms, audit rights, or service-level agreements.
  • Compliance Cost Disparities: Studies tracking regulatory expenditures indicate that compliance costs consume a significantly higher percentage of operating revenue for institutions with under $10 billion in assets compared to multinational mega-banks. Third-party vendor management has routinely ranked among the top three operational expenses for compliance departments.
  • The Shift Toward Responsible Innovation: Regulators crafted the 2026 guidance with an eye toward fostering competitive tech adoption. By reducing ambiguous compliance expectations, policymakers hope to clear a path for community lenders to partner safely with agile fintech startups—expanding credit access, modernizing user interfaces, and driving regional economic growth without running afoul of overly rigid safety-and-soundness examinations.

Official Responses and Perspectives

The release of the proposed guidance prompted widespread commentary from regulatory leaders, institutional heads, and banking trade associations, highlighting the delicate balance between systemic risk mitigation and regulatory relief.

The Office of the Comptroller of the Currency (OCC)

Comptroller of the Currency Jonathan V. Gould emphasized that the new framework is fundamentally about unburdening local lenders so they can focus on their core economic mission.

"We are giving these vital institutions more freedom to do what they do best—serve their customers, support local businesses, strengthen their communities and drive economic growth across America," Gould stated in the OCC’s official press release.

Gould highlighted that the proposed adjustments are specifically designed to provide greater clarity regarding supervisory and enforcement expectations surrounding core service providers, replacing ambiguous, overly broad standards with concrete, risk-based evaluations.

Interagency Assessment of Core Service Providers

In their joint statement, the Federal Reserve, FDIC, and OCC acknowledged the inherent structural imbalances in the banking technology marketplace. The agencies noted:

"These relationships are essential to the safe and sound operations of community banking organizations, yet certain core provider business practices and market dynamics may pose obstacles to a CBO’s ability to efficiently and effectively identify, assess and address the attendant risks."

By explicitly defining the criteria for supervisory and enforcement decisions regarding these core vendors, the agencies signaled a willingness to hold major technology suppliers more accountable while protecting the banks that rely upon them from unfair regulatory penalties.

Industry and Trade Association Reactions

Early feedback from national banking associations has been cautiously optimistic. Representatives from community banking coalitions praised the move away from rigid, one-size-fits-all enforcement. Many noted that allowing institutions to scale their risk management protocols directly to the materiality and nature of each third-party vendor will save thousands of compliance hours annually.

However, risk management consultants have also stressed that financial institutions must not view the guidance as a relaxation of safety standards. Instead, institutions are being urged to use the 60-day comment period to provide detailed feedback on how the agencies can further clarify the boundaries between bank responsibility and vendor accountability.


Implications for Financial Institutions

The unveiling of the revised third-party risk management framework carries profound implications for the banking and credit union sectors, reshaping how institutions evaluate, onboard, and oversee external partners.

1. Tailored Risk Appraisals

Under the proposed framework, risk management programs will no longer be judged by their sheer volume of paperwork, but by their precision. Financial institutions are expected to scale their due diligence, contract negotiation, and ongoing monitoring based on the criticality of the service provided. A vendor handling non-sensitive marketing data will face a vastly different oversight protocol than a third-party core processor managing core ledger systems or customer Personally Identifiable Information (PII).

2. Redefined Vendor Negotiations

With federal regulators formally acknowledging the market obstacles posed by dominant core service providers, community banks and credit unions may find themselves on firmer footing during contract renewals. While the guidance does not grant banks unilateral legal leverage over tech giants, the explicit regulatory scrutiny on core provider business practices provides compliance officers with stronger justification when pushing back against restrictive vendor clauses or opaque audit restrictions.

3. Accelerated Fintech Collaboration

By actively encouraging "responsible innovation," the regulatory agencies are signaling that community lenders should not fear partnering with emerging technology firms due to the looming threat of punitive examinations. This regulatory clarity is expected to spur a wave of local digital partnerships, enabling regional banks to deploy advanced fraud detection, automated lending platforms, and enhanced mobile banking tools that rival those of large national institutions.

4. Action Items During the Comment Period

With the Federal Register publication initiating a 60-day public comment window, compliance executives, risk officers, and legal counsel within banks and credit unions have a critical opportunity to shape the final rule. Industry participants are actively preparing submissions to ensure that the final guidance provides maximum operational flexibility without inadvertently creating new regulatory grey areas.

As the financial services ecosystem continues to digitalize at a rapid pace, this coordinated federal intervention marks a pivotal milestone in balancing robust systemic oversight with the operational survival and growth of community-focused financial institutions.