Feature Third-Party Risk
The Regulators Just Proposed Scrapping the 2023 TPRM Guidance. Here's What the Replacement Says.
On September 11, 2026, the OCC, Fed, FDIC, and NCUA proposed to rescind and replace the 2023 interagency TPRM guidance. The new framework shifts from prescriptive checklists to a harm-based, risk-tailored standard. Comments due November 16.
Table of Contents
TL;DR
- On September 11, 2026, the OCC, Federal Reserve, FDIC, and NCUA proposed to rescind and replace the 2023 interagency TPRM guidance — the first wholesale rewrite since it was finalized three years ago.
- The core change: replacing the “critical activities” framework with a harm-based, risk-proportionate standard that tells institutions to calibrate oversight to the magnitude and likelihood of harm each relationship actually poses.
- The agencies explicitly admitted the 2023 guidance created de facto checklists and that institutions were applying the same rigor to low-risk vendors as to core banking providers. This proposal is the correction.
- NCUA signs on for the first time, bringing credit unions inside the interagency framework.
- Comment deadline: November 16, 2026. If your program has been suffering under the checklist model, this is the time to say so.
Three years ago, the OCC, Federal Reserve, and FDIC published a comprehensive interagency guidance on third-party risk management. Institutions built programs around it. Examiners cited it. The guidance generated a cottage industry of TPRM questionnaires, due diligence templates, and contract clause libraries.
It also generated constant frustration. The same complaint surfaced at nearly every compliance roundtable: the 2023 guidance had created de facto checklists. Banks were running the same due diligence process on their office supply vendor as on their core banking platform. Examiners were citing missing questionnaire fields on relationships that posed essentially zero systemic risk. The guidance was technically about “critical activities” — but in practice, teams were treating the checklist as mandatory for almost everything.
On September 11, 2026, the agencies blinked. The proposed interagency guidance on third-party risk management would rescind and replace the 2023 version entirely. It is not an amendment or supplement. It is a wholesale replacement — and the agencies said plainly why.
Why They’re Replacing It
The agencies’ own preamble is unusually candid. The 2023 Guidance “frequently has been interpreted in an overly broad manner and with an insufficient focus on tailoring its risk management principles.” The guidance’s detailed examples and idealized factual scenarios “effectively created de facto checklists, leading banking organizations to adopt an ‘overly-process-driven’ approach rather than exercise tailored, risk-based judgment.”
That’s the regulators acknowledging that their own guidance produced the outcome they were trying to prevent.
What TPRM examiners were finding three years into the 2023 guidance documents exactly this pattern in practice: programs that were technically complete — every field filled in, every questionnaire sent — but not actually calibrated to risk. The industry had been raising this problem formally since at least the May 2026 joint trade roundtable paper from the American Bankers Association, American Fintech Council, Coalition for Financial Ecosystem Standards, Independent Community Bankers of America, and Consumer Bankers Association.
The September 11 proposal is the regulators’ answer.
What Actually Changes: The Harm-Based Standard
The most significant conceptual shift in the proposal is the replacement of “critical activities” as the primary trigger for heightened oversight with a standard based on magnitude and likelihood of harm.
The 2023 guidance organized its requirements around whether a third-party relationship supported a “critical activity” — a term defined as activities that could cause the institution to face significant risk if the third party failed, could have significant customer impact, or required significant investment to implement. That framing pushed institutions to make a binary classification: critical or not critical. Critical triggered the full due diligence regimen; non-critical got something lighter.
The proposed guidance abandons that binary. Instead, it asks: what is the magnitude of the harm this relationship could cause, and what is the likelihood that harm actually occurs? Those two variables — magnitude and likelihood — drive every element of the risk oversight program.
Under this framework:
| Relationship Type | Proposed Treatment |
|---|---|
| High-magnitude, high-likelihood harm (core banking platforms, payment rails, critical data processors) | Comprehensive due diligence, robust contract requirements, intensive ongoing monitoring, board-level reporting |
| High-magnitude, low-likelihood harm (rarely-used contingency services with financial impact if they fail) | Risk assessment focused on likelihood and mitigants; due diligence calibrated accordingly |
| Low-magnitude harm (administrative services, professional consultants, office support) | Less detailed due diligence, reliance on public information, standard contracts, less frequent monitoring |
| Routine services with minimal impact (office physical security, certain recordkeeping services) | Proportionately lighter treatment; qualitative assessment sufficient |
The proposed guidance explicitly names lower-risk vendors: call center operators, recordkeeping services, auditors, lawyers, consultants, physical security providers. These are the relationships that have been generating the most friction under the 2023 framework’s checklist model.
The Four-Part Framework
The proposed guidance organizes risk management into four components:
1. Risk Identification and Assessment
This is where the harm standard lives. Risk assessment must account for both the magnitude of harm a relationship could cause and the likelihood it will occur. The proposal tells institutions to consider: what could go wrong, how bad would it be, and how likely is it to happen? The due diligence requirement flows from the answer, not from a pre-determined category label.
2. Risk Oversight
This component covers the full vendor lifecycle: due diligence and selection, contract negotiation, ongoing monitoring, and termination. The key change is that each of these steps gets calibrated to the risk level established in the assessment. Lower-risk relationships can use lighter due diligence, shorter contracts, and less intensive monitoring. Higher-risk relationships require the comprehensive oversight the 2023 guidance described.
The proposal preserves meaningful monitoring requirements for high-risk relationships — ongoing monitoring is not eliminated, it’s proportionated. Institutions running annual questionnaire-and-forget programs for critical vendors will still have a problem.
3. Residual Risk Acceptance
This is an underappreciated piece. The proposed guidance expects stronger documentation of residual risk acceptance — the decision to proceed with a relationship after identifying risks that haven’t been fully mitigated. The agencies are not requiring zero residual risk; they’re requiring that residual risks be understood, explicitly accepted, and that the rationale be documented.
That’s a practical constraint. In the current environment, many institutions have broad residual risk acceptance language that covers entire vendor categories. Under the proposed framework, that approach needs to be supported by an actual risk assessment showing why the residual risk is acceptable for each relationship.
4. Governance
Board and management oversight requirements remain substantive. The proposal doesn’t reduce the governance expectation — it aligns governance to the risk profile rather than to a category. Boards should still be getting reporting on high-risk relationships, third-party concentration exposure, and significant vendor events. What they shouldn’t be reviewing is a lengthy list of low-risk administrative vendors that pose no systemic exposure.
What Else Gets Rescinded
The September 11 proposal would rescind more than just the 2023 guidance. It would also replace:
- The May 15, 2002 OCC bulletin on foreign-based third-party service providers
- The July 25, 2024 joint statement on banks’ arrangements with third parties to deliver bank deposit products
- The May 3, 2024 community bank guide to third-party risk management
The July 2024 bank deposit arrangements statement is worth noting specifically. It addressed the BaaS consent orders and fintech-bank liability that have consumed compliance teams over the past two years. The new proposed guidance would absorb those issues into the broader harm-based framework rather than treating bank-fintech arrangements as a separate regulatory category.
NCUA’s Arrival
The NCUA’s co-signature on this proposal is a meaningful structural change. Credit unions have been operating under their own NCUA guidance on third-party relationships, which has not been fully interoperable with the OCC, Fed, and FDIC framework. Credit unions that partner with fintechs, or that use vendors shared with banking institutions, now face a unified standard.
Credit union compliance teams that built programs under NCUA’s existing guidance will need to map their frameworks to the new harm-based model. The core concepts are similar, but the calibration requirements are materially different from NCUA’s previous prescriptive expectations.
The Companion Core Service Providers Statement
The same day, the OCC, Federal Reserve, and FDIC issued a separate joint statement on community banks’ engagement with core service providers — the vendors that run their core banking systems and data-processing platforms.
This is not the same document as the proposed guidance revision. It addresses a specific, high-concentration risk: community banks whose entire operations depend on a small number of core technology vendors (FIS, Fiserv, Jack Henry, and their equivalents). OCC’s 2026 third-party risk guidance rewrite on core providers covers what that statement requires. The core service provider statement and the proposed TPRM guidance revision are complementary, not duplicative — the statement targets concentration in the highest-criticality category; the proposed guidance sets the overall framework that applies to all third-party relationships.
What Your Program Needs to Do Now
The proposed guidance is not final. The November 16, 2026 comment deadline matters — this is the stage where practitioners can shape the final language. If the “harm-based standard” is directionally right but needs more definition, say so. If the rescission of the July 2024 BaaS statement leaves a gap, identify it.
On the program side, here’s what to assess in parallel:
Map your current risk tiers to the harm-based model. If your tiers are built around the “critical activity” construct, evaluate whether they would survive a harm-magnitude-and-likelihood analysis. Vendors that were previously non-critical because they don’t directly support a critical activity might score higher under a harm-based lens, and vice versa.
Identify where your due diligence is over-indexed. The proposal explicitly names administrative services, professional consultants, and physical security as lower-risk categories. If your program is running the same extensive questionnaire process on lawyers and auditors as on your payment processor, the proposed guidance gives you the regulatory rationale to right-size it.
Document your residual risk acceptance rationale. For high-risk relationships, vague acceptance language will not hold up under the proposed framework. Start building specific documentation now: what risks remain, why they are acceptable, what compensating controls exist.
Prepare your comment. This is a proposed, not final, guidance. The agencies explicitly sought feedback from industry in their May 2026 roundtable. The comment process is open to everyone — not just trade associations. If there are operational aspects of the proposal that would create problems, the comment period is the time to document them.
So What?
The agencies have effectively admitted that the 2023 TPRM guidance created the problem it was meant to solve: institutions treating every vendor relationship with the same procedural rigor regardless of the actual risk it poses. The proposed replacement is a meaningful correction — a framework built around what could actually go wrong and how likely that is, rather than around a taxonomy of activity types.
For practitioners who have been running TPRM programs that feel procedurally exhausting and substantively thin, the proposed guidance offers a path to something better. The work is in the translation: turning harm-based language into a risk-tier model that holds up under examination and moving the program away from checkbox completion toward genuine risk calibration.
The comment deadline is November 16, 2026. The final guidance will follow. Your program design should probably follow the final guidance — but the scaffolding for the risk-based rebuild can start now.
Running a third-party risk program that still runs on the 2023 checklist model? The Third-Party Risk Management (TPRM) Kit includes a risk-tiering methodology, vendor lifecycle questionnaires, and an ongoing monitoring framework you can adapt to the harm-based standard the proposed guidance describes.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did the agencies propose on September 11, 2026?
What is the biggest change from the 2023 interagency guidance?
What does the proposed guidance's four-part structure cover?
Does this proposed guidance apply to credit unions for the first time?
How should institutions respond before the November 16, 2026 comment deadline?
Does the proposed guidance eliminate due diligence requirements for lower-risk vendors?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Keep reading
Related posts.
Third-Party Risk
Your Vendor Had a Breach in November. You Found Out in July. Eight Months of Invisible Risk — and Your TPRM Contract Probably Allowed It.
Paylogix, a SaaS employee benefits administrator, was breached by the Akira ransomware group in November 2025. Its insurance-carrier clients didn't get notified until July 20, 2026 — nearly eight months later. Here's what that gap reveals about the vendor breach notification requirements most TPRM programs are missing.
Sep 15, 2026
Third-Party Risk
IDScan.net Exposed 153 Million Driver's Licenses on the Dark Web. Your KYC Vendor's Breach Is Your CIP Problem.
On September 1, 2026, a dark web marketplace began advertising 153 million driver's license scans traced to IDScan.net, a KYC identity verification vendor. For any financial institution using third-party identity verification: this isn't IDScan's problem alone. Regulators hold you responsible for customer ID data wherever it flows.
Sep 14, 2026
Third-Party Risk
OCC's 2026 Third-Party Risk Guidance Rewrite: What Banks Should Change Now
The 2026 third-party risk guidance proposal rewrites vendor tiering and gives community banks leverage with core providers.
Sep 11, 2026