Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Third-Party Risk

What TPRM Examiners Are Actually Finding Three Years Into the Interagency Guidance

OCC Bulletin 2023-17 and FDIC FIL-29-2023 turned three in June. Third-party risk programs that looked solid at launch are showing cracks under examination — incomplete due diligence, weak ongoing monitoring, critical activity designations that don't hold up, and subcontractor gaps that no one mapped. Here's what's getting flagged and what to fix.

By Rebecca Leung · July 16, 2026 ·
Table of Contents

When the interagency TPRM guidance dropped in June 2023, most institutions filed it under “done.” They built a vendor inventory, added tiers, updated their due diligence questionnaire, and moved on. Examiners who reviewed programs a year later mostly agreed the new framework had been adopted.

Three years in, the picture is different. Examiners aren’t checking whether institutions adopted the guidance anymore. They’re checking whether the programs it produced actually work.

The gaps they’re finding aren’t about missing the framework. They’re about the distance between what’s documented and what’s operational — incomplete due diligence that was proportional on paper but not in practice, monitoring that generates reports nobody acts on, critical activity designations that don’t hold up when an examiner asks why a particular vendor was classified that way, and subcontractor maps that stop at the first tier.

TL;DR

  • OCC Bulletin 2023-17 / FDIC FIL-29-2023 / Federal Reserve SR 23-4 are three years old — examiners have shifted from checking adoption to checking whether programs actually function
  • The most common findings: under-resourced due diligence for critical activities, ongoing monitoring that’s annual at best, written agreements missing required elements, and subcontractor risk that was never assessed
  • The July 2024 bank-fintech joint statement added BaaS-specific examination expectations that many sponsor banks haven’t fully incorporated
  • Industry trade associations raised concerns in May 2026 about inconsistent guidance application — but inconsistency doesn’t eliminate your compliance risk

The Critical Activity Problem: Too Much or Too Little

The interagency guidance structures most of its requirements around the “critical activity” designation. Get the designation right and the rest of your TPRM program follows. Get it wrong — in either direction — and everything downstream is miscalibrated.

Under OCC Bulletin 2023-17 and FDIC FIL-29-2023, a critical activity is one that could cause a bank to face significant risk if the third party fails, could have significant customer impact, or requires significant resource investment to implement. The regulation is intentionally principle-based — it doesn’t provide a checklist.

Examiners in 2026 are finding two failure modes:

Under-designation: Institutions classified core banking technology, payment processors, and cloud infrastructure as non-critical to avoid the associated documentation burden. When examiners ask why a vendor processing 80% of the institution’s transaction volume wasn’t designated critical, the answer is often circular: “it wasn’t designated critical, so it didn’t get the critical activity review.”

Over-designation: Some institutions responded by designating nearly everything critical, creating administrative overload and diluting the depth of review for vendors that actually warrant it. A vendor list where 40% of vendors are critical is almost certainly wrong — and it creates the appearance of rigor without the substance.

The fix requires documented criticality criteria applied consistently: revenue exposure, customer impact if disrupted, data sensitivity, regulatory dependency, and concentration. If your criteria can’t produce a defensible list that an examiner could review and understand, the designation process needs work.


Due Diligence Depth: The Right Questions, Wrong Documentation

The guidance is clear that due diligence should be proportional to risk. For critical activities, that means comprehensive review of:

  • Financial condition (audited financials, going-concern indicators)
  • Information security and cybersecurity controls
  • Operational resilience and business continuity
  • Compliance and legal background
  • Subcontracting practices (who the vendor uses for critical functions)
  • Insurance coverage
  • Human capital and management depth

The common failure mode isn’t asking the wrong questions on a questionnaire. It’s accepting vendor responses without validation — taking a “yes, we have a SOC 2” answer without reviewing the actual report, or accepting a vendor’s assertion that they have a business continuity plan without asking for evidence of testing.

The Federal Reserve’s May 2024 report on third-party risk management specifically noted the gap between due diligence process and due diligence substance — institutions going through the motions of sending questionnaires but not actually building risk-informed assessments from the responses.

Examiners pull due diligence workpapers. They look at whether the bank read the SOC 2 report, noted any exceptions, and followed up. They look at whether the financial review was a one-paragraph summary or an actual analysis of vendor financial health. Work product that looks like a completed form rather than evidence of analysis will generate findings.

For institutions that haven’t built out their ongoing vendor financial monitoring process, our vendor financial health monitoring guide covers the specific indicators and monitoring cadence that examiners expect.


Ongoing Monitoring: Annual Isn’t Continuous

The interagency guidance’s language on ongoing monitoring is clear: risk management processes should adapt as the relationship evolves and as the bank’s risk profile changes. For critical activities, the guidance describes monitoring as a continuous process, not a point-in-time event.

In practice, many institutions translated this as “we’ll check in annually.” That’s a finding waiting to happen.

Examiners in 2026 are looking for evidence of monitoring activity between formal annual reviews: newsroom monitoring for vendor financial distress or breach announcements, automated review of performance metrics in vendor contracts, periodic check-ins on subcontractor changes, and escalation of any material changes to appropriate oversight functions.

The specific monitoring signals that matter most for critical vendors:

  • Credit rating changes or public financial reporting anomalies
  • Contract terminations with other clients or industry news suggesting financial stress
  • Security incidents or breach disclosures at the vendor or its subcontractors
  • Regulatory actions against the vendor
  • Key personnel changes in the vendor’s risk, security, or compliance functions
  • Material changes to the vendor’s subcontracting relationships

This doesn’t require daily manual review of every vendor. It requires a monitoring protocol that assigns specific signals to automated tracking and flags material changes for human review. The program’s output needs to be documented — examiners look for evidence that monitoring actually happened, not just a process description that says it does.


Written Agreement Completeness: Fourteen Elements, Not Eight

The interagency guidance specifies what written agreements for critical activities should contain. Examiners reviewing vendor contracts are pulling them against this list. The most common gaps are at the back half of the list — the provisions that institutions negotiate away or simply forget.

Required ElementCommonly Missing?
Scope of arrangement and activitiesRarely missing
Performance standards and metricsOften too vague
Pricing and payment termsRarely missing
Ownership and confidentiality of dataOften missing clauses on data return/deletion
Audit and access rights for bank and regulatorsFrequently narrowed by vendor negotiation
Business continuity and disaster recovery requirementsOften absent or aspirational
Indemnification and liability limitsPresent, often negotiated unfavorably
Default and termination triggersPresent but often lack detail on transition assistance
Dispute resolution proceduresOften missing
Subcontracting limitations and notification requirementsFrequently missing
Cybersecurity and data security requirementsOften vague or vendor-templated
Regulator access rightsCritical gap — vendors often resist
Compliance with applicable lawsPresent but generic
Termination and transition assistanceOften missing practical detail

The regulator access provision is the most contested. Vendors — particularly large technology providers and cloud platforms — resist giving banks contractual rights to share contracts and information with regulators, to have regulators conduct onsite reviews, or to have third-party auditors perform work on the bank’s behalf. Examiners check for this provision, and its absence is a finding for critical activity relationships.

Our vendor exit planning analysis covers how to build transition assistance requirements into vendor agreements that actually support operationalizable exits.


The BaaS and Fintech Arrangement Layer: July 2024 Joint Statement

If your institution has bank-fintech partnerships — sponsor banking, banking-as-a-service, embedded finance, or fintech program management arrangements — the July 2024 joint statement on banks’ arrangements with third parties added examination expectations that go beyond the standard interagency TPRM guidance.

The joint statement addressed a specific failure pattern the agencies observed: sponsor banks relying entirely on fintech partners’ representations about their BSA/AML compliance, consumer protection practices, and operational controls — without independent oversight capability. The statement made clear that banks cannot delegate compliance to fintech partners. Banks must have:

  • Direct oversight capability, including ability to independently assess fintech activity
  • Termination rights that are actually exercisable, with documented ability to execute them
  • Concentration risk monitoring when a significant portion of revenue comes from a small number of fintech programs
  • Board-level awareness of the bank’s fintech-related risk profile

Examiners reviewing BaaS programs in 2026 are specifically checking whether banks can demonstrate independent oversight — not just contractual rights to oversight. A contract that gives the bank audit rights isn’t meaningful if the bank has never exercised them or doesn’t have the internal capability to do so.

For institutions managing cloud provider concentration risk within their fintech partnerships, our cloud concentration risk examination guide covers what examiners are specifically looking for on sub-provider dependencies.


Subcontractor Risk: The Tier That Examiners Are Now Reaching

The May 2026 joint trade TPRM roundtable — published by the Consumer Bankers Association, American Fintech Council, Coalition for Financial Ecosystem Standards, and ICBA — identified subcontractor risk as one of the most challenging areas of guidance implementation. The roundtable, conducted under Chatham House rules, drew on input from banks, technology providers, and current and former regulatory representatives.

The core challenge: the guidance asks banks to understand their critical vendors’ subcontracting practices. But most institutions don’t have contractual rights to directly examine their vendors’ subcontractors — they can only request information through the vendor. Vendors, particularly large cloud providers and technology platforms, resist disclosing their full subcontractor footprints or accepting liability for subcontractor failures.

The practical minimum examiners expect:

  1. For each critical activity vendor, documentation of who that vendor’s critical subcontractors are
  2. Understanding of what the subcontractor does in the service delivery chain
  3. Any known risk indicators about the subcontractor
  4. Whether the bank’s contract with the vendor provides notification rights if critical subcontractors change

This is a minimum floor — it doesn’t require a full due diligence workup on every subcontractor. But examiners want to see that institutions have mapped the dependency and thought through what happens if a critical subcontractor fails.


What to Fix Before Your Next Exam

AreaCommon GapFix
Critical activity designationCriteria undocumented or inconsistently appliedBuild written criteria; document the designation decision for each vendor
Due diligence depthQuestionnaire responses accepted without validationAdd evidence review requirement: SOC 2 exceptions, audited financials analysis, BCP test results
Ongoing monitoringAnnual questionnaire onlyAdd automated news monitoring, periodic financial check-ins, escalation protocol
Written agreementsMissing elements, especially regulator accessContract review against the guidance’s 14 elements; negotiate missing provisions at renewal
Subcontractor mappingNot startedRequest critical subcontractor lists from critical activity vendors; document what you know and don’t know
BaaS oversightContractual rights only, no demonstrated exerciseSchedule and execute at least one independent review of a fintech partner’s compliance activity

So What?

Three years in, the examination expectation has shifted. Examiners aren’t checking whether you have a TPRM program anymore. They’re checking whether it actually functions as a risk management tool or whether it’s administrative theater that produces binders and vendor questionnaires that nobody uses.

The institutions that will have clean TPRM examinations in 2026 and 2027 are the ones that can show substantive due diligence work, monitoring that generated actual escalations, critical activity designations with documented rationale, and written agreements with all required provisions — not just most of them.

If you’re building out or refreshing your TPRM program and need documentation templates aligned to the interagency guidance requirements, the Third-Party Risk Management Kit includes vendor tiering criteria, due diligence workpaper templates, ongoing monitoring protocols, and a written agreement checklist mapped to the guidance’s required elements.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What does OCC Bulletin 2023-17 require for third-party due diligence?
OCC Bulletin 2023-17 (and the parallel FDIC FIL-29-2023 and Federal Reserve SR 23-4) require that due diligence be proportional to the risk and complexity of the third-party relationship and the nature of the activities involved. For critical activities — those that could materially affect the institution's operations, financials, or customers — the guidance expects comprehensive due diligence covering the vendor's financial condition, operational controls, cybersecurity program, business continuity capability, and subcontracting practices. For non-critical activities, the guidance allows proportionately lighter diligence. The most common exam finding is performing the same surface-level due diligence for all vendors regardless of criticality.
What does 'critical activity' mean under the interagency TPRM guidance?
The interagency guidance defines critical activities as those that could cause a banking organization to face significant risk if the third party fails to meet expectations, could have significant customer impact, or require significant investment in resources to implement the third-party relationship. The critical activity designation triggers the most rigorous requirements in the guidance: deeper due diligence, more comprehensive written agreement terms, ongoing monitoring with board-level reporting, and contingency planning requirements. Examiners find two failure modes: institutions that designate almost nothing as critical (avoiding the burden), and institutions that designate almost everything as critical (creating administrative overload and diluting actual risk management).
What are the most common TPRM exam findings from OCC and FDIC examiners in 2026?
Based on industry roundtable observations published in May 2026 by the Consumer Bankers Association, American Fintech Council, Coalition for Financial Ecosystem Standards, and ICBA — drawing on input from banks, fintechs, and current and former regulatory representatives — the most common TPRM exam findings include: (1) due diligence that is too shallow for the criticality of the relationship, particularly for technology vendors; (2) ongoing monitoring that amounts to an annual questionnaire rather than continuous risk intelligence; (3) written agreements missing required elements from the guidance, particularly around business continuity, subcontracting disclosure, and regulator access; (4) critical activity designations that don't withstand scrutiny; and (5) no documented subcontractor risk assessment for critical activities.
How does the July 2024 joint statement on bank-fintech arrangements add to TPRM obligations?
The July 2024 joint statement from the OCC, FDIC, and Federal Reserve addressed bank-as-a-service and bank-fintech arrangements specifically. It clarified that sponsoring banks cannot rely solely on fintech partners' representations about their compliance — banks must have independent oversight capability, including the ability to directly examine fintech activity and termination rights that are actually exercisable. Examiners reviewing BaaS arrangements in 2026 are checking whether banks have meaningful oversight of fintech partners, not just contractual rights on paper. The statement also emphasized concentration risk monitoring — where a bank's revenue is substantially dependent on one or a small number of fintech partnerships.
What is fourth-party risk and how are examiners evaluating it in 2026?
Fourth-party risk is the risk posed by your vendors' vendors — the subcontractors and technology providers that your critical third parties depend on. The interagency TPRM guidance explicitly requires banking organizations to understand their critical third parties' subcontracting practices as part of due diligence. In practice, examiners are asking whether banks can identify the critical subcontractors their core processors, cloud providers, and key fintechs depend on, and whether they have any visibility into those sub-dependencies' risk profiles. The failure mode most often cited is 'we didn't know that our core processor was dependent on [single cloud provider]' when a disruption materializes.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Third-Party Risk Management (TPRM) Kit

Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.