Feature Third-Party Risk
FDIC's Confidential Information Overhaul: What Banks and Their Fintech Partners Can Now Share Without Prior Approval
The FDIC's June 2026 proposed rule — the first major revision to its confidential information disclosure framework in approximately 30 years — would let banks share confidential supervisory information with fintech partners, auditors, and M&A counterparties without needing prior FDIC authorization. Comments are due August 31. Here's what changes and what your contracts need to reflect.
Table of Contents
Sometime in the mid-1990s, the FDIC wrote the rules governing how banks can share examination findings with outside parties. Those rules — codified in 12 CFR Part 309 — have governed bank information disclosure ever since. The model: if you want to share what an examiner found during a safety-and-soundness exam with anyone outside the bank, you generally need to ask the FDIC first.
That’s changing.
On June 25, 2026, the FDIC published a notice of proposed rulemaking to overhaul its confidential information disclosure framework — the first substantial revision in approximately 30 years. The proposed rule would allow insured depository institutions to share confidential supervisory information (CSI) with fintech partners, auditors, outside counsel, and M&A counterparties without FDIC pre-authorization, provided a qualifying confidentiality agreement is in place.
Comments are due August 31, 2026. For compliance teams at banks with significant fintech partnerships — and for the fintechs on the receiving end of those partnerships — the proposed rule has direct implications for what information your bank partner can share with you, and what your contracts need to say.
TL;DR
- The FDIC’s June 2026 proposed rule is the first major revision to its confidential information disclosure framework in approximately 30 years — it would shift from a prior-approval model to a qualifying-confidentiality-agreement model for routine CSI sharing.
- Banks could share CSI with affiliates, outside counsel, auditors, fintech service providers, and M&A counterparties without prior FDIC authorization — provided the sharing is for a business purpose and a qualifying confidentiality agreement is in place.
- “Qualifying service provider” explicitly includes fintech companies that provide services used in connection with financial products or services to customers — covering the overwhelming majority of BaaS fintech relationships.
- This matters for how you draft bank-fintech contracts: the confidentiality agreement provisions need to meet the FDIC’s qualifying requirements before any CSI can flow. Existing NDAs and vendor contracts almost certainly don’t include the specific provisions the proposed rule requires.
- Comments are due August 31, 2026. The proposed qualifying confidentiality agreement requirements are where this rule could change substantively before finalization.
Why the 30-Year-Old Rules Created Real Friction
The existing rules reflect a reasonable core principle: examination findings are candid, preliminary assessments of a bank’s condition — prepared by examiners who expect their observations to be held in confidence while the bank and regulators work through issues. Allowing that material to flow freely creates real risks: selective disclosure to investors, strategic misuse in litigation, and chilling effects on examiner candor.
But the prior-authorization requirement has created friction that the financial services industry has outgrown:
Audit and legal functions: A bank’s external auditors routinely need access to examination findings to assess whether management has appropriately identified and disclosed regulatory matters. Outside counsel defending the bank in regulatory proceedings needs to understand what examiners found. Both scenarios currently require prior FDIC authorization — adding administrative steps to functions that serve no competing supervisory interest.
Fintech partnerships: In a bank-fintech relationship, the fintech partner typically bears compliance responsibilities that can only be effectively overseen if the fintech has visibility into examination findings. A BaaS bank that receives an MRA for insufficient compliance monitoring of its fintech partners needs to communicate that finding to those partners as part of remediation. Under current rules, that communication technically requires FDIC pre-approval. Few banks actually go through that process.
M&A due diligence: Acquirers in bank deals need access to examination history to assess the target’s supervisory standing. Requiring FDIC pre-authorization adds timeline friction to transactions where the FDIC’s legitimate interest — ensuring the information isn’t misused — is fully served by a confidentiality agreement.
The FDIC’s proposed solution is to replace prior authorization with a notice-and-agreement model for these scenarios.
What the Proposed Rule Would Allow
Under the proposed framework, insured depository institutions could share CSI with the following categories of recipients without prior FDIC authorization, provided:
- The sharing is for a legitimate business purpose, and
- Both parties have executed a qualifying confidentiality agreement
Authorized recipient categories:
| Recipient Type | Business Purpose Basis |
|---|---|
| Affiliates | Corporate governance, shared services, consolidated oversight |
| Outside counsel | Legal defense, regulatory advice, litigation support |
| External auditors | Financial statement audit, regulatory compliance review |
| Service providers (including fintechs) | Services provided in connection with financial products or services |
| Potential merger partners | Acquisition due diligence |
The inclusion of service providers as an explicitly authorized recipient category — with the definition encompassing fintechs that provide services used in connection with financial products or services to customers — directly addresses the BaaS friction point. A bank providing banking-as-a-service to a fintech could share relevant examination findings with that fintech under the proposed framework, without an FDIC pre-authorization call.
What still requires prior FDIC authorization:
The proposed rule is not a wholesale deregulation of CSI. Sharing with parties outside the authorized categories — including investors, media, counterparties without a qualifying confidentiality agreement, or any party for purposes other than legitimate business functions — would still require prior FDIC approval (or be prohibited).
What Makes a “Qualifying Confidentiality Agreement”
This is where the practical compliance work lives. The proposed rule would authorize CSI sharing only when a qualifying confidentiality agreement is in place. To qualify, the agreement must include provisions that:
- Restrict further disclosure: The recipient cannot share CSI with unauthorized parties
- Limit use to disclosed purpose: CSI may only be used for the purpose for which it was shared
- Require legal process notification: If the recipient receives a subpoena or legal demand for CSI, it must notify the IDI promptly
- Preserve the IDI’s right to seek a protective order: The agreement must allow the bank to seek court protection against compelled disclosure
The FDIC has indicated it will provide model confidentiality agreement language with the final rule. But the framework is clear enough that compliance teams can assess their current contracts now.
The problem with existing contracts: Standard bank-fintech vendor agreements, NDAs, and service contracts generally include confidentiality provisions — but they’re written to protect both parties’ proprietary business information, not to satisfy specific regulatory requirements around CSI. The legal-process-notification and protective-order provisions are almost never in standard commercial confidentiality language. Existing contracts almost certainly need to be amended.
Practical Implications for Bank-Fintech Partnerships
For banks with significant fintech partnerships — particularly in BaaS, embedded finance, and payments — the proposed rule changes the information architecture of those relationships:
Examination findings and MRA communication: Banks that receive examination findings touching on their fintech partner programs will be able to share relevant portions of those findings with fintech partners as part of compliance remediation, without the current prior-approval friction. This doesn’t change what the bank is required to communicate — it removes an administrative barrier to communication that supervisors already expect to happen.
Compliance oversight: Fintech partners with access to examination-informed guidance can calibrate their compliance programs more effectively. If a bank’s examiner identified gaps in how the bank monitors fintech compliance, sharing that finding with the fintech is directly in service of remediation.
Contract review timeline: Banks and fintechs should start auditing their existing partnership agreements for confidentiality provisions now — before the rule is finalized — so that contract amendments can be prepared and executed promptly when the final rule takes effect. Retrofitting confidentiality language across dozens of fintech relationships after a final rule drops in late 2026 or early 2027 is an avoidable last-minute scramble.
The Broader Context: FDIC Rightsizing
The confidential information rule proposal is one of several FDIC proposals in 2026 aimed at reducing administrative friction for banks and their partners. On the same June 2026 timeline, the FDIC also proposed:
- Assessment pricing revisions: Increasing the threshold distinguishing small from large institutions for assessment purposes from $10 billion to $30 billion, and reducing initial base assessment rates by two basis points for small banks
- Resolution planning rule revisions: Easing large bank resolution planning submission requirements
The pattern reflects the current FDIC board’s alignment with the Trump administration’s May 2026 executive order directing federal financial regulators to reduce barriers to fintech-bank partnerships. For compliance professionals, the policy direction means that administrative requirements — like FDIC pre-authorization for routine CSI sharing — are likely to be phased out in favor of disclosure-and-certification frameworks.
That’s a meaningful operational change. The compliance work isn’t eliminated — it shifts from managing FDIC pre-approval calls to ensuring that contract frameworks are structured correctly and that qualifying confidentiality agreements are in place.
The M&A Dimension
Bank M&A practitioners will recognize the significance of the proposed CSI sharing authorization for merger due diligence. Under current rules, a bank acquirer seeking access to the target’s examination history must navigate FDIC pre-authorization. The administrative friction adds deal uncertainty and timeline risk.
The proposed rule’s explicit authorization for CSI sharing with potential merger partners — subject to a qualifying confidentiality agreement — directly addresses this. For community bank consolidation, where examination history is often the most important disclosure a buyer needs, removing that friction could meaningfully accelerate deal timelines.
So What? The Action Items Before August 31
For compliance and legal teams at banks and their fintech partners:
1. Audit your existing partner agreements for confidentiality provisions. Map which bank-fintech contracts include confidentiality language and assess whether those provisions would meet the qualifying requirements (legal process notification, protective order reservation, use limitation). Most won’t. Create a list of contracts that need amendment.
2. Watch the comment period for modifications to qualifying agreement requirements. The FDIC’s proposed qualifying provisions are the most operationally significant part of the rule. If you have views on whether the requirements are workable in the BaaS context — particularly around notification timing for legal demands — comment before August 31.
3. Prepare contract amendment templates now. Don’t wait for the final rule to draft qualified confidentiality language. The proposed provisions are specific enough to start drafting. Prepare a standard amendment that could be appended to existing contracts once the rule is finalized.
4. Assess what CSI your bank partners currently don’t share — and should. For fintechs in BaaS relationships, the proposed rule creates an opportunity to ask your bank partner for examination-informed compliance guidance they previously couldn’t share. Understanding examination focus areas is valuable compliance input. Start the conversation now.
For a fuller view of how FDIC examination deficiencies are showing up in TPRM programs right now, the June 2026 TPRM examination deficiency analysis covers what’s generating MRAs in third-party risk programs before any rule changes. And for the OCC’s consent order anatomy — the enforcement endpoint that makes CSI sharing relevant in the first place — the CFSB consent order breakdown shows what happens when bank-fintech compliance oversight fails. The proposed CSI rule is designed to make the information flow that prevents those outcomes easier to execute.
For fintech exit planning — an area where information-sharing gaps have generated their own examination findings — the vendor exit plan framework covers what OCC 2023-17 requires at Stage 5 of the vendor lifecycle, including what should be documented before a relationship ends.
The FDIC’s proposed rule is, fundamentally, an acknowledgment that the 30-year-old prior-approval model created administrative overhead without a corresponding supervisory benefit in routine sharing scenarios. The replacement — a confidentiality agreement framework — puts the compliance obligation where it belongs: on the parties sharing the information, not on an FDIC pre-authorization queue.
Sources:
- FDIC Board Approves Proposal to Amend Regulations Regarding the Disclosure of Information — FDIC, June 2026
- Federal Register: Disclosure of Information — FDIC, June 30, 2026
- FDIC Proposes Overhaul of Confidential Information Disclosure Rules — Consumer Financial Services Law Monitor
- Federal Deposit Insurance Corporation Proposes to Permit CSI to Be Shared in M&A Transactions — Sullivan & Cromwell, 2026
- Update from the Prudential Regulators: Rightsizing Regulation — FDIC, 2026
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is confidential supervisory information (CSI) and why has sharing it been restricted?
What does the FDIC's June 2026 proposed rule change about CSI sharing?
What makes a 'qualifying confidentiality agreement' under the proposed rule?
Does this proposed rule affect what examiners can share with fintech partners directly?
When does the FDIC comment period close and when would the rule take effect?
Does this rule change anything about M&A due diligence in bank acquisitions?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Keep reading
Related posts.
Third-Party Risk
Third-Party Risk Management Lifecycle RACI: Fix the Handoffs Between Procurement, Security, Legal, Business Owners, and Risk
A TPRM lifecycle RACI that assigns clear ownership at each stage — planning, due diligence, contracting, onboarding, monitoring, and offboarding — so findings don't fall between functions.
Jul 24, 2026
Third-Party Risk
Vendor Due Diligence Without a SOC 2: What Evidence Can Actually Substitute
A vendor due diligence checklist for evaluating security evidence when a vendor has no SOC 2 report, with a risk-based substitution matrix.
Jul 23, 2026
Third-Party Risk
Three Vendors, One Existential Risk: What the OCC's Community Bank Core Provider RFI Actually Asked
The OCC published Bulletin 2025-39 asking community banks hard questions about their relationships with Fiserv, FIS, and Jack Henry. The questions reveal exactly what examiners are now checking — and what most TPRM programs haven't addressed.
Jul 23, 2026