Skip to content
RiskTemplates · The Daily Brief Saturday, September 19, 2026
Wire SEC's $64 Million Croft & Frost Offering Fraud Case: The Warning Email Compliance Teams Cannot Ignore SEP 14

Feature Third-Party Risk

The Regulators Just Proposed Scrapping the 2023 TPRM Guidance. Here's What the Replacement Says.

On September 11, 2026, the OCC, Fed, FDIC, and NCUA proposed to rescind and replace the 2023 interagency TPRM guidance. The new framework shifts from prescriptive checklists to a harm-based, risk-tailored standard. Comments due November 16.

By Rebecca Leung · September 18, 2026 ·
Table of Contents

TL;DR

  • On September 11, 2026, the OCC, Federal Reserve, FDIC, and NCUA proposed to rescind and replace the 2023 interagency TPRM guidance — the first wholesale rewrite since it was finalized three years ago.
  • The core change: replacing the “critical activities” framework with a harm-based, risk-proportionate standard that tells institutions to calibrate oversight to the magnitude and likelihood of harm each relationship actually poses.
  • The agencies explicitly admitted the 2023 guidance created de facto checklists and that institutions were applying the same rigor to low-risk vendors as to core banking providers. This proposal is the correction.
  • NCUA signs on for the first time, bringing credit unions inside the interagency framework.
  • Comment deadline: November 16, 2026. If your program has been suffering under the checklist model, this is the time to say so.

Three years ago, the OCC, Federal Reserve, and FDIC published a comprehensive interagency guidance on third-party risk management. Institutions built programs around it. Examiners cited it. The guidance generated a cottage industry of TPRM questionnaires, due diligence templates, and contract clause libraries.

It also generated constant frustration. The same complaint surfaced at nearly every compliance roundtable: the 2023 guidance had created de facto checklists. Banks were running the same due diligence process on their office supply vendor as on their core banking platform. Examiners were citing missing questionnaire fields on relationships that posed essentially zero systemic risk. The guidance was technically about “critical activities” — but in practice, teams were treating the checklist as mandatory for almost everything.

On September 11, 2026, the agencies blinked. The proposed interagency guidance on third-party risk management would rescind and replace the 2023 version entirely. It is not an amendment or supplement. It is a wholesale replacement — and the agencies said plainly why.

Why They’re Replacing It

The agencies’ own preamble is unusually candid. The 2023 Guidance “frequently has been interpreted in an overly broad manner and with an insufficient focus on tailoring its risk management principles.” The guidance’s detailed examples and idealized factual scenarios “effectively created de facto checklists, leading banking organizations to adopt an ‘overly-process-driven’ approach rather than exercise tailored, risk-based judgment.”

That’s the regulators acknowledging that their own guidance produced the outcome they were trying to prevent.

What TPRM examiners were finding three years into the 2023 guidance documents exactly this pattern in practice: programs that were technically complete — every field filled in, every questionnaire sent — but not actually calibrated to risk. The industry had been raising this problem formally since at least the May 2026 joint trade roundtable paper from the American Bankers Association, American Fintech Council, Coalition for Financial Ecosystem Standards, Independent Community Bankers of America, and Consumer Bankers Association.

The September 11 proposal is the regulators’ answer.

What Actually Changes: The Harm-Based Standard

The most significant conceptual shift in the proposal is the replacement of “critical activities” as the primary trigger for heightened oversight with a standard based on magnitude and likelihood of harm.

The 2023 guidance organized its requirements around whether a third-party relationship supported a “critical activity” — a term defined as activities that could cause the institution to face significant risk if the third party failed, could have significant customer impact, or required significant investment to implement. That framing pushed institutions to make a binary classification: critical or not critical. Critical triggered the full due diligence regimen; non-critical got something lighter.

The proposed guidance abandons that binary. Instead, it asks: what is the magnitude of the harm this relationship could cause, and what is the likelihood that harm actually occurs? Those two variables — magnitude and likelihood — drive every element of the risk oversight program.

Under this framework:

Relationship TypeProposed Treatment
High-magnitude, high-likelihood harm (core banking platforms, payment rails, critical data processors)Comprehensive due diligence, robust contract requirements, intensive ongoing monitoring, board-level reporting
High-magnitude, low-likelihood harm (rarely-used contingency services with financial impact if they fail)Risk assessment focused on likelihood and mitigants; due diligence calibrated accordingly
Low-magnitude harm (administrative services, professional consultants, office support)Less detailed due diligence, reliance on public information, standard contracts, less frequent monitoring
Routine services with minimal impact (office physical security, certain recordkeeping services)Proportionately lighter treatment; qualitative assessment sufficient

The proposed guidance explicitly names lower-risk vendors: call center operators, recordkeeping services, auditors, lawyers, consultants, physical security providers. These are the relationships that have been generating the most friction under the 2023 framework’s checklist model.

The Four-Part Framework

The proposed guidance organizes risk management into four components:

1. Risk Identification and Assessment

This is where the harm standard lives. Risk assessment must account for both the magnitude of harm a relationship could cause and the likelihood it will occur. The proposal tells institutions to consider: what could go wrong, how bad would it be, and how likely is it to happen? The due diligence requirement flows from the answer, not from a pre-determined category label.

2. Risk Oversight

This component covers the full vendor lifecycle: due diligence and selection, contract negotiation, ongoing monitoring, and termination. The key change is that each of these steps gets calibrated to the risk level established in the assessment. Lower-risk relationships can use lighter due diligence, shorter contracts, and less intensive monitoring. Higher-risk relationships require the comprehensive oversight the 2023 guidance described.

The proposal preserves meaningful monitoring requirements for high-risk relationships — ongoing monitoring is not eliminated, it’s proportionated. Institutions running annual questionnaire-and-forget programs for critical vendors will still have a problem.

3. Residual Risk Acceptance

This is an underappreciated piece. The proposed guidance expects stronger documentation of residual risk acceptance — the decision to proceed with a relationship after identifying risks that haven’t been fully mitigated. The agencies are not requiring zero residual risk; they’re requiring that residual risks be understood, explicitly accepted, and that the rationale be documented.

That’s a practical constraint. In the current environment, many institutions have broad residual risk acceptance language that covers entire vendor categories. Under the proposed framework, that approach needs to be supported by an actual risk assessment showing why the residual risk is acceptable for each relationship.

4. Governance

Board and management oversight requirements remain substantive. The proposal doesn’t reduce the governance expectation — it aligns governance to the risk profile rather than to a category. Boards should still be getting reporting on high-risk relationships, third-party concentration exposure, and significant vendor events. What they shouldn’t be reviewing is a lengthy list of low-risk administrative vendors that pose no systemic exposure.

What Else Gets Rescinded

The September 11 proposal would rescind more than just the 2023 guidance. It would also replace:

The July 2024 bank deposit arrangements statement is worth noting specifically. It addressed the BaaS consent orders and fintech-bank liability that have consumed compliance teams over the past two years. The new proposed guidance would absorb those issues into the broader harm-based framework rather than treating bank-fintech arrangements as a separate regulatory category.

NCUA’s Arrival

The NCUA’s co-signature on this proposal is a meaningful structural change. Credit unions have been operating under their own NCUA guidance on third-party relationships, which has not been fully interoperable with the OCC, Fed, and FDIC framework. Credit unions that partner with fintechs, or that use vendors shared with banking institutions, now face a unified standard.

Credit union compliance teams that built programs under NCUA’s existing guidance will need to map their frameworks to the new harm-based model. The core concepts are similar, but the calibration requirements are materially different from NCUA’s previous prescriptive expectations.

The Companion Core Service Providers Statement

The same day, the OCC, Federal Reserve, and FDIC issued a separate joint statement on community banks’ engagement with core service providers — the vendors that run their core banking systems and data-processing platforms.

This is not the same document as the proposed guidance revision. It addresses a specific, high-concentration risk: community banks whose entire operations depend on a small number of core technology vendors (FIS, Fiserv, Jack Henry, and their equivalents). OCC’s 2026 third-party risk guidance rewrite on core providers covers what that statement requires. The core service provider statement and the proposed TPRM guidance revision are complementary, not duplicative — the statement targets concentration in the highest-criticality category; the proposed guidance sets the overall framework that applies to all third-party relationships.

What Your Program Needs to Do Now

The proposed guidance is not final. The November 16, 2026 comment deadline matters — this is the stage where practitioners can shape the final language. If the “harm-based standard” is directionally right but needs more definition, say so. If the rescission of the July 2024 BaaS statement leaves a gap, identify it.

On the program side, here’s what to assess in parallel:

Map your current risk tiers to the harm-based model. If your tiers are built around the “critical activity” construct, evaluate whether they would survive a harm-magnitude-and-likelihood analysis. Vendors that were previously non-critical because they don’t directly support a critical activity might score higher under a harm-based lens, and vice versa.

Identify where your due diligence is over-indexed. The proposal explicitly names administrative services, professional consultants, and physical security as lower-risk categories. If your program is running the same extensive questionnaire process on lawyers and auditors as on your payment processor, the proposed guidance gives you the regulatory rationale to right-size it.

Document your residual risk acceptance rationale. For high-risk relationships, vague acceptance language will not hold up under the proposed framework. Start building specific documentation now: what risks remain, why they are acceptable, what compensating controls exist.

Prepare your comment. This is a proposed, not final, guidance. The agencies explicitly sought feedback from industry in their May 2026 roundtable. The comment process is open to everyone — not just trade associations. If there are operational aspects of the proposal that would create problems, the comment period is the time to document them.

So What?

The agencies have effectively admitted that the 2023 TPRM guidance created the problem it was meant to solve: institutions treating every vendor relationship with the same procedural rigor regardless of the actual risk it poses. The proposed replacement is a meaningful correction — a framework built around what could actually go wrong and how likely that is, rather than around a taxonomy of activity types.

For practitioners who have been running TPRM programs that feel procedurally exhausting and substantively thin, the proposed guidance offers a path to something better. The work is in the translation: turning harm-based language into a risk-tier model that holds up under examination and moving the program away from checkbox completion toward genuine risk calibration.

The comment deadline is November 16, 2026. The final guidance will follow. Your program design should probably follow the final guidance — but the scaffolding for the risk-based rebuild can start now.


Running a third-party risk program that still runs on the 2023 checklist model? The Third-Party Risk Management (TPRM) Kit includes a risk-tiering methodology, vendor lifecycle questionnaires, and an ongoing monitoring framework you can adapt to the harm-based standard the proposed guidance describes.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did the agencies propose on September 11, 2026?
The OCC, Federal Reserve, FDIC, and NCUA proposed to rescind and replace the interagency guidance on third-party risk management published on June 9, 2023. They also proposed to rescind the 2024 community bank guide and the July 2024 joint statement on bank-fintech deposit arrangements. A companion joint statement on community banks and core service providers was issued the same day. Comments on the proposed guidance are due November 16, 2026.
What is the biggest change from the 2023 interagency guidance?
The fundamental shift is from 'critical activities' as the trigger for heightened oversight to a 'magnitude and likelihood of harm' standard. The agencies acknowledged the 2023 guidance created de facto checklists and that institutions were applying the same due diligence to low-risk vendors as to core banking providers. The proposed framework tells institutions to calibrate due diligence to the actual risk each relationship poses — not to a categorical activity label.
What does the proposed guidance's four-part structure cover?
The proposed guidance covers four components: (1) risk identification and assessment, focusing on magnitude and likelihood of harm; (2) risk oversight, covering due diligence and selection, contract negotiation, ongoing monitoring, and termination; (3) residual risk acceptance, with stronger documentation expectations; and (4) governance, including the board and management roles.
Does this proposed guidance apply to credit unions for the first time?
Yes. The NCUA signed onto this proposal, bringing credit unions inside the interagency TPRM framework for the first time. The four agencies — OCC, Fed, FDIC, and NCUA — all co-signed the September 11, 2026 proposal.
How should institutions respond before the November 16, 2026 comment deadline?
Institutions should submit comments on any aspects of the proposed framework that would be difficult to operationalize — including how they currently define risk tiers, where the 'de facto checklist' problem was most acute, and what guidance on harm-based calibration would be most useful. The comment period is the chance to shape how the final guidance gets written.
Does the proposed guidance eliminate due diligence requirements for lower-risk vendors?
No, it calibrates them. The proposal explicitly says lower-risk relationships could warrant less detailed due diligence, reliance on public or alternative information, and less frequent monitoring. But it doesn't eliminate the due diligence requirement — institutions still need to assess risk and document the rationale for their approach.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Third-Party Risk Management (TPRM) Kit

Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.