Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Third-Party Risk

FDIC's Confidential Information Overhaul: What Banks and Their Fintech Partners Can Now Share Without Prior Approval

The FDIC's June 2026 proposed rule — the first major revision to its confidential information disclosure framework in approximately 30 years — would let banks share confidential supervisory information with fintech partners, auditors, and M&A counterparties without needing prior FDIC authorization. Comments are due August 31. Here's what changes and what your contracts need to reflect.

By Rebecca Leung · July 12, 2026 ·
Table of Contents

Sometime in the mid-1990s, the FDIC wrote the rules governing how banks can share examination findings with outside parties. Those rules — codified in 12 CFR Part 309 — have governed bank information disclosure ever since. The model: if you want to share what an examiner found during a safety-and-soundness exam with anyone outside the bank, you generally need to ask the FDIC first.

That’s changing.

On June 25, 2026, the FDIC published a notice of proposed rulemaking to overhaul its confidential information disclosure framework — the first substantial revision in approximately 30 years. The proposed rule would allow insured depository institutions to share confidential supervisory information (CSI) with fintech partners, auditors, outside counsel, and M&A counterparties without FDIC pre-authorization, provided a qualifying confidentiality agreement is in place.

Comments are due August 31, 2026. For compliance teams at banks with significant fintech partnerships — and for the fintechs on the receiving end of those partnerships — the proposed rule has direct implications for what information your bank partner can share with you, and what your contracts need to say.

TL;DR

  • The FDIC’s June 2026 proposed rule is the first major revision to its confidential information disclosure framework in approximately 30 years — it would shift from a prior-approval model to a qualifying-confidentiality-agreement model for routine CSI sharing.
  • Banks could share CSI with affiliates, outside counsel, auditors, fintech service providers, and M&A counterparties without prior FDIC authorization — provided the sharing is for a business purpose and a qualifying confidentiality agreement is in place.
  • “Qualifying service provider” explicitly includes fintech companies that provide services used in connection with financial products or services to customers — covering the overwhelming majority of BaaS fintech relationships.
  • This matters for how you draft bank-fintech contracts: the confidentiality agreement provisions need to meet the FDIC’s qualifying requirements before any CSI can flow. Existing NDAs and vendor contracts almost certainly don’t include the specific provisions the proposed rule requires.
  • Comments are due August 31, 2026. The proposed qualifying confidentiality agreement requirements are where this rule could change substantively before finalization.

Why the 30-Year-Old Rules Created Real Friction

The existing rules reflect a reasonable core principle: examination findings are candid, preliminary assessments of a bank’s condition — prepared by examiners who expect their observations to be held in confidence while the bank and regulators work through issues. Allowing that material to flow freely creates real risks: selective disclosure to investors, strategic misuse in litigation, and chilling effects on examiner candor.

But the prior-authorization requirement has created friction that the financial services industry has outgrown:

Audit and legal functions: A bank’s external auditors routinely need access to examination findings to assess whether management has appropriately identified and disclosed regulatory matters. Outside counsel defending the bank in regulatory proceedings needs to understand what examiners found. Both scenarios currently require prior FDIC authorization — adding administrative steps to functions that serve no competing supervisory interest.

Fintech partnerships: In a bank-fintech relationship, the fintech partner typically bears compliance responsibilities that can only be effectively overseen if the fintech has visibility into examination findings. A BaaS bank that receives an MRA for insufficient compliance monitoring of its fintech partners needs to communicate that finding to those partners as part of remediation. Under current rules, that communication technically requires FDIC pre-approval. Few banks actually go through that process.

M&A due diligence: Acquirers in bank deals need access to examination history to assess the target’s supervisory standing. Requiring FDIC pre-authorization adds timeline friction to transactions where the FDIC’s legitimate interest — ensuring the information isn’t misused — is fully served by a confidentiality agreement.

The FDIC’s proposed solution is to replace prior authorization with a notice-and-agreement model for these scenarios.


What the Proposed Rule Would Allow

Under the proposed framework, insured depository institutions could share CSI with the following categories of recipients without prior FDIC authorization, provided:

  1. The sharing is for a legitimate business purpose, and
  2. Both parties have executed a qualifying confidentiality agreement

Authorized recipient categories:

Recipient TypeBusiness Purpose Basis
AffiliatesCorporate governance, shared services, consolidated oversight
Outside counselLegal defense, regulatory advice, litigation support
External auditorsFinancial statement audit, regulatory compliance review
Service providers (including fintechs)Services provided in connection with financial products or services
Potential merger partnersAcquisition due diligence

The inclusion of service providers as an explicitly authorized recipient category — with the definition encompassing fintechs that provide services used in connection with financial products or services to customers — directly addresses the BaaS friction point. A bank providing banking-as-a-service to a fintech could share relevant examination findings with that fintech under the proposed framework, without an FDIC pre-authorization call.

What still requires prior FDIC authorization:

The proposed rule is not a wholesale deregulation of CSI. Sharing with parties outside the authorized categories — including investors, media, counterparties without a qualifying confidentiality agreement, or any party for purposes other than legitimate business functions — would still require prior FDIC approval (or be prohibited).


What Makes a “Qualifying Confidentiality Agreement”

This is where the practical compliance work lives. The proposed rule would authorize CSI sharing only when a qualifying confidentiality agreement is in place. To qualify, the agreement must include provisions that:

  • Restrict further disclosure: The recipient cannot share CSI with unauthorized parties
  • Limit use to disclosed purpose: CSI may only be used for the purpose for which it was shared
  • Require legal process notification: If the recipient receives a subpoena or legal demand for CSI, it must notify the IDI promptly
  • Preserve the IDI’s right to seek a protective order: The agreement must allow the bank to seek court protection against compelled disclosure

The FDIC has indicated it will provide model confidentiality agreement language with the final rule. But the framework is clear enough that compliance teams can assess their current contracts now.

The problem with existing contracts: Standard bank-fintech vendor agreements, NDAs, and service contracts generally include confidentiality provisions — but they’re written to protect both parties’ proprietary business information, not to satisfy specific regulatory requirements around CSI. The legal-process-notification and protective-order provisions are almost never in standard commercial confidentiality language. Existing contracts almost certainly need to be amended.


Practical Implications for Bank-Fintech Partnerships

For banks with significant fintech partnerships — particularly in BaaS, embedded finance, and payments — the proposed rule changes the information architecture of those relationships:

Examination findings and MRA communication: Banks that receive examination findings touching on their fintech partner programs will be able to share relevant portions of those findings with fintech partners as part of compliance remediation, without the current prior-approval friction. This doesn’t change what the bank is required to communicate — it removes an administrative barrier to communication that supervisors already expect to happen.

Compliance oversight: Fintech partners with access to examination-informed guidance can calibrate their compliance programs more effectively. If a bank’s examiner identified gaps in how the bank monitors fintech compliance, sharing that finding with the fintech is directly in service of remediation.

Contract review timeline: Banks and fintechs should start auditing their existing partnership agreements for confidentiality provisions now — before the rule is finalized — so that contract amendments can be prepared and executed promptly when the final rule takes effect. Retrofitting confidentiality language across dozens of fintech relationships after a final rule drops in late 2026 or early 2027 is an avoidable last-minute scramble.


The Broader Context: FDIC Rightsizing

The confidential information rule proposal is one of several FDIC proposals in 2026 aimed at reducing administrative friction for banks and their partners. On the same June 2026 timeline, the FDIC also proposed:

  • Assessment pricing revisions: Increasing the threshold distinguishing small from large institutions for assessment purposes from $10 billion to $30 billion, and reducing initial base assessment rates by two basis points for small banks
  • Resolution planning rule revisions: Easing large bank resolution planning submission requirements

The pattern reflects the current FDIC board’s alignment with the Trump administration’s May 2026 executive order directing federal financial regulators to reduce barriers to fintech-bank partnerships. For compliance professionals, the policy direction means that administrative requirements — like FDIC pre-authorization for routine CSI sharing — are likely to be phased out in favor of disclosure-and-certification frameworks.

That’s a meaningful operational change. The compliance work isn’t eliminated — it shifts from managing FDIC pre-approval calls to ensuring that contract frameworks are structured correctly and that qualifying confidentiality agreements are in place.


The M&A Dimension

Bank M&A practitioners will recognize the significance of the proposed CSI sharing authorization for merger due diligence. Under current rules, a bank acquirer seeking access to the target’s examination history must navigate FDIC pre-authorization. The administrative friction adds deal uncertainty and timeline risk.

The proposed rule’s explicit authorization for CSI sharing with potential merger partners — subject to a qualifying confidentiality agreement — directly addresses this. For community bank consolidation, where examination history is often the most important disclosure a buyer needs, removing that friction could meaningfully accelerate deal timelines.


So What? The Action Items Before August 31

For compliance and legal teams at banks and their fintech partners:

1. Audit your existing partner agreements for confidentiality provisions. Map which bank-fintech contracts include confidentiality language and assess whether those provisions would meet the qualifying requirements (legal process notification, protective order reservation, use limitation). Most won’t. Create a list of contracts that need amendment.

2. Watch the comment period for modifications to qualifying agreement requirements. The FDIC’s proposed qualifying provisions are the most operationally significant part of the rule. If you have views on whether the requirements are workable in the BaaS context — particularly around notification timing for legal demands — comment before August 31.

3. Prepare contract amendment templates now. Don’t wait for the final rule to draft qualified confidentiality language. The proposed provisions are specific enough to start drafting. Prepare a standard amendment that could be appended to existing contracts once the rule is finalized.

4. Assess what CSI your bank partners currently don’t share — and should. For fintechs in BaaS relationships, the proposed rule creates an opportunity to ask your bank partner for examination-informed compliance guidance they previously couldn’t share. Understanding examination focus areas is valuable compliance input. Start the conversation now.

For a fuller view of how FDIC examination deficiencies are showing up in TPRM programs right now, the June 2026 TPRM examination deficiency analysis covers what’s generating MRAs in third-party risk programs before any rule changes. And for the OCC’s consent order anatomy — the enforcement endpoint that makes CSI sharing relevant in the first place — the CFSB consent order breakdown shows what happens when bank-fintech compliance oversight fails. The proposed CSI rule is designed to make the information flow that prevents those outcomes easier to execute.

For fintech exit planning — an area where information-sharing gaps have generated their own examination findings — the vendor exit plan framework covers what OCC 2023-17 requires at Stage 5 of the vendor lifecycle, including what should be documented before a relationship ends.

The FDIC’s proposed rule is, fundamentally, an acknowledgment that the 30-year-old prior-approval model created administrative overhead without a corresponding supervisory benefit in routine sharing scenarios. The replacement — a confidentiality agreement framework — puts the compliance obligation where it belongs: on the parties sharing the information, not on an FDIC pre-authorization queue.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is confidential supervisory information (CSI) and why has sharing it been restricted?
Confidential supervisory information includes examination reports, supervisory correspondence, memoranda, and other materials produced by FDIC examiners during the examination process. Under the current FDIC rules (12 CFR Part 309), sharing CSI with third parties — including fintech partners, auditors, and outside counsel — generally requires prior FDIC authorization. The restriction exists because CSI reflects examiner findings that are candid, preliminary, and often unresolved — sharing them without supervision risks misuse, selective disclosure, and chilling the examination dialogue. The problem is that the prior-approval requirement has created operational friction for legitimate business purposes: due diligence, legal defense, audit oversight, and fintech partnership management.
What does the FDIC's June 2026 proposed rule change about CSI sharing?
The proposed rule would permit insured depository institutions to share CSI with affiliates, outside counsel, auditors, service providers (including fintechs), and potential merger partners without first obtaining FDIC authorization — provided the sharing is for a legitimate business purpose and both parties have entered into a qualifying confidentiality agreement. This is a fundamental shift from the existing prior-approval model to a notice-and-confidentiality-agreement model for most routine sharing scenarios.
What makes a 'qualifying confidentiality agreement' under the proposed rule?
The proposed rule would specify that qualifying confidentiality agreements must restrict the recipient from further disclosure of CSI to unauthorized parties, require the recipient to use CSI only for the purpose for which it was disclosed, require the recipient to notify the IDI promptly if it receives a subpoena or legal demand for CSI, and provide that the IDI retains the right to seek a protective order. The FDIC has indicated it will provide model agreement language. Banks will need to update their standard vendor contracts, NDA templates, and partner agreements to include the qualifying provisions before sharing.
Does this proposed rule affect what examiners can share with fintech partners directly?
No. The proposed rule addresses what insured depository institutions can share with third parties. Examiners do not share CSI directly with third parties, including fintechs — that's still prohibited. What the rule changes is a bank's ability to share examination findings, supervisory correspondence, and related materials with its fintech partners for legitimate business purposes (compliance oversight, audit functions, due diligence) without needing to call the FDIC first.
When does the FDIC comment period close and when would the rule take effect?
The proposed rule was published in the Federal Register on June 30, 2026. Comments are due August 31, 2026. A final rule would likely follow in late 2026 or early 2027, after the FDIC reviews and addresses comments. The rule would not take effect until finalized. Banks and fintechs should monitor the comment period for any substantive changes to the qualifying confidentiality agreement requirements, as those will determine what contract language needs to be added before sharing begins.
Does this rule change anything about M&A due diligence in bank acquisitions?
Yes. The proposed rule would explicitly authorize banks to share CSI with potential merger partners as part of M&A due diligence, provided a qualifying confidentiality agreement is in place. Currently, sharing CSI with an acquirer during due diligence requires prior FDIC approval, which creates timeline friction in deals. The proposed change is part of the FDIC's broader regulatory rightsizing agenda under the current administration — reducing administrative overhead for transactions where the FDIC's supervisory interest is served by the confidentiality agreement rather than pre-authorization.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Third-Party Risk Management (TPRM) Kit

Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.