Skip to content
RiskTemplates · The Daily Brief Sunday, September 27, 2026
Wire OFAC Just Codified Its Penalty Playbook. What 31 CFR Part 505 Means for Your Sanctions Compliance Program. SEP 26

Feature Third-Party Risk

Four Agencies Just Proposed to Kill the TPRM Checklist. Here's What 'Risk-Proportionate' Vendor Oversight Actually Means.

On September 11, 2026, the OCC, Federal Reserve, FDIC, and NCUA jointly proposed new interagency TPRM guidance to replace the 2023 framework. The core change: stop treating every vendor the same. Comments are due November 16. Here's what it means for your program.

By Rebecca Leung · September 26, 2026 ·
Table of Contents

TL;DR

  • On September 11, 2026, the OCC, Federal Reserve, FDIC, and NCUA proposed new interagency TPRM guidance to replace the 2023 framework; comments due November 16
  • The core change: stop running every vendor through the same process — oversight should be calibrated to the “magnitude and likelihood of harm” each relationship actually presents
  • The agencies admitted the 2023 guidance backfired: it drove checklist compliance, prioritized process over risk substance, and chilled engagement with fintech and innovative providers
  • Core service providers — Jack Henry, FIS, Fiserv and their peers — now face direct supervisory scrutiny as potential institution-affiliated parties
  • This is proposed guidance, not final rule — but the agencies’ direction is clear enough to act on now

Your vendor list includes a coffee machine supplier, a SaaS analytics tool you pay $200 per month for, and the core processor your entire banking operation runs through. Your TPRM program probably treats all three with some version of the same due diligence process.

That’s exactly what four banking regulators just said needs to change.

On September 11, 2026, the OCC, Federal Reserve, FDIC, and NCUA jointly proposed replacing the existing interagency third-party risk management guidance with a fundamentally different framework — one built on the principle that vendor oversight should match the risk each relationship actually presents, not apply a uniform process regardless of stakes. The proposal appeared in the Federal Register on September 15 with a comment deadline of November 16, 2026.

Why the Agencies Said the 2023 Guidance Failed

The 2023 interagency guidance — which itself replaced OCC Bulletin 2013-29, the Fed’s SR 13-19, and the FDIC’s FIL-44-2008 — was supposed to create a unified TPRM framework. It did. But according to the agencies, it created the wrong kind.

In the preamble to the September proposal, the agencies made an unusual acknowledgment: the existing guidance had produced outcomes they didn’t intend. Specifically, they said the 2023 framework had been interpreted as:

  1. Requiring a broad, process-driven approach that applies the same risk management practices across all vendor relationships regardless of actual risk
  2. Driving checklist compliance rather than substantive risk assessment
  3. Incentivizing process completeness over risk substance
  4. Chilling engagement with fintechs and innovative providers — because banks were applying enterprise due diligence to vendors that didn’t warrant it

That fourth point is worth pausing on. Banking regulators rarely admit in writing that their guidance produced industry-wide behavior they consider problematic. The explicit call-out of the “fintech chilling effect” signals where the regulatory community has landed on bank-fintech partnership oversight: the answer to third-party risk is not blanket avoidance of novel vendor relationships.

The proposed guidance is designed to course-correct.

What “Risk-Proportionate” Actually Means

The phrase “risk-proportionate” does significant work in the proposed framework, so it’s worth unpacking what the agencies say it means in practice.

Under the 2023 guidance, the organizing concept was “critical activities” — relationships that supported a banking organization’s critical activities received elevated oversight, while others got baseline treatment. But “critical activity” became a broad category, and the elevated-oversight process still applied the same template across relationships within that tier.

The proposed replacement framework directs banking organizations to calibrate oversight to “the magnitude and likelihood of harm of each relationship.” This is a different unit of analysis than “critical activity” — it asks you to assess the specific risk each vendor could cause, then design oversight proportionate to that assessment.

In practice, this means:

  • A cloud infrastructure provider hosting your core banking system gets deep due diligence, continuous monitoring, and detailed contract terms covering data security, business continuity, and exit provisions
  • An analytics SaaS tool with no access to customer PII and no operational dependencies gets a lighter assessment appropriate to the risk it presents
  • Vendors offering commodity services (facilities management, certain HR tools) may warrant minimal formal TPRM structure

The guidance doesn’t define fixed thresholds for what triggers which level of oversight. The framework is principles-based — which is both its strength and its challenge. Principles-based guidance requires judgment, and judgment requires a documented rationale.

The Core Service Provider Problem

One of the most consequential changes in the proposal is the treatment of core service providers — firms like Jack Henry & Associates, FIS, and Fiserv that provide mission-critical technology infrastructure to large numbers of banks and credit unions simultaneously.

The proposal introduces a mechanism for direct supervisory scrutiny of these providers, with the possibility of enforcement actions against them as institution-affiliated parties. Under the current framework, examiners can only reach core service providers through the banking organizations they serve. The proposed framework opens the door to examining the vendors themselves.

The practical implication for banking organizations: a vendor’s potential regulatory exposure becomes a dimension of your own vendor risk assessment. A core service provider that becomes the subject of enforcement action — even enforcement it caused rather than you — creates operational and reputational risk for the institutions that depend on it. The UK’s designation of AWS, Azure, Google Cloud, and Oracle as Critical Third Parties under the Financial Market Infrastructure Act offers a working preview of what direct regulatory oversight of technology vendors looks like in practice — and the concentration risk questions it forces banks to answer.

The joint statement on community bank engagement with core service providers specifically addresses the leverage imbalance that smaller institutions face with dominant core processors. It signals regulatory awareness that community banks often lack the contractual power to demand risk information, audit rights, or exit terms that a risk-proportionate framework technically requires from a well-functioning vendor relationship.

What the Community Bank Companion Guide Covers

For Federal Reserve-supervised institutions under $30 billion in assets, the agencies simultaneously proposed a practical guide providing non-binding examples for implementing the principles-based framework.

This addresses a real gap. The 2023 guidance was written for institutions large enough to have dedicated TPRM functions, legal teams that negotiate vendor contracts, and staff capacity to run full due diligence programs. Community banks under $1 billion often had one or two compliance staff members trying to apply enterprise guidance to a vendor population they couldn’t resource the same way.

The companion guide doesn’t lower the standard — it translates principles into examples that fit smaller institutions’ resource constraints. The key framing: what “proportionate” TPRM looks like for a $500 million community bank differs from what it looks like for a $50 billion regional bank or a systemically important institution.

What Your TPRM Program Should Do Now

The guidance is still proposed — comments are due November 16 and the final version will take time to arrive. But the agencies’ direction is clear enough to act on before the rule is finalized.

For institutions with mature TPRM programs:

Review your vendor risk tiering methodology. If “critical activity” support is your primary tiering criterion, the proposed framework gives you reason to revisit whether that criterion maps to “magnitude and likelihood of harm.” A vendor can support a critical activity without presenting meaningful harm potential; a vendor can present significant harm potential without supporting what your policy considers a critical activity.

For institutions still running one-size-fits-all processes:

The September proposal is the clearest regulatory signal yet that uniform checklist processes aren’t the standard. If your program applies the same questionnaire, contract checklist, and monitoring frequency to every vendor above a threshold, document the risk rationale — or revise the program to reflect actual risk differentiation.

For community banks under $30 billion:

The companion guide is not yet final, but its framing of proportionate oversight for resource-constrained institutions gives you a basis for calibrating your program without overbuilding. An honest assessment of which vendor relationships could cause you financial harm if they failed — versus which are operationally convenient but low-risk — is the right starting point.

The comment period matters:

The November 16 deadline is a real opportunity. The industry’s response shapes the final guidance. If your institution has specific feedback on how the risk-proportionate standard should work in practice — particularly for community banks navigating core service provider relationships where contract leverage is limited — this is the mechanism to provide it.

Current (2023 Framework)Proposed (September 2026)
“Critical activity” as primary tiering criterionMagnitude and likelihood of harm as calibration standard
Same process applied across relationships in the same tierOversight proportionate to each relationship’s specific risk
Core service providers supervised only through banking organizationDirect supervisory scrutiny; potential institution-affiliated party status
No specific community bank companion documentFed-supervised institutions under $30B: dedicated practical examples guide
Fintechs face full enterprise due diligenceRisk-proportionate standard reduces friction for low-risk fintech relationships

So What?

This is the banking agencies admitting, in writing, that their 2023 TPRM guidance produced the wrong behavior at scale. A checklist-driven vendor program that applies the same process regardless of actual risk isn’t just operationally inefficient — it’s not what regulators want.

The comment deadline is November 16. The final guidance will take time. But the direction is clear: the question your TPRM program should be able to answer is not “did we run every vendor through our process?” — it’s “does our oversight match the risk each vendor relationship actually presents?”

For practitioners managing dozens or hundreds of vendor relationships, that’s a meaningful operational shift. A purpose-built TPRM program that differentiates vendor risk by actual harm potential — rather than applying a flat checklist — is what the proposed framework rewards. The OCC/FDIC’s concurrent work on what makes a practice ‘unsafe or unsound’ amplifies the same message: risk management programs should be oriented toward actual financial harm scenarios, not documentation compliance exercises.

Build toward that standard now, and the final guidance will feel like validation. Build toward checklist completion, and the next examination cycle will ask you to explain why your oversight doesn’t match your vendor population’s actual risk profile.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did the September 2026 interagency TPRM proposal actually change?
The proposal replaces the 2023 interagency third-party risk management guidance with a framework emphasizing risk-proportionate oversight — meaning the depth of your vendor due diligence and monitoring should match the actual risk each relationship presents, not apply the same rigorous process to every vendor regardless of harm potential. The agencies explicitly acknowledged the 2023 guidance was interpreted to require a broad, checklist-driven approach that didn't distinguish between high-risk and low-risk vendor relationships. Comments are due November 16, 2026.
Who issued the proposed TPRM guidance and when?
The OCC, Federal Reserve, FDIC, and NCUA jointly proposed the guidance on September 11, 2026, with publication in the Federal Register on September 15, 2026 (document 2026-18859). The package includes three documents: the new interagency guidance itself, a practical companion guide for community banks, and a joint statement on community bank engagement with core service providers.
What is the 'institution-affiliated party' risk for core service providers?
The proposal introduces direct supervisory scrutiny of core service providers — firms like Jack Henry, FIS, and Fiserv that provide mission-critical infrastructure to large numbers of banks and credit unions simultaneously. Under the proposed framework, these vendors could face enforcement actions as institution-affiliated parties, meaning regulatory scrutiny now reaches the vendor directly, not only the banking organization that uses them.
What is the community bank companion guide and who is it for?
The Federal Reserve separately proposed a practical guide for 'traditional community banking organizations' — Federal Reserve-supervised institutions with less than $30 billion in assets. The guide is non-binding and provides practical examples for implementing risk-proportionate TPRM principles at a scale appropriate for community bank resource constraints. It's designed for institutions that may have interpreted the 2023 guidance as requiring enterprise-grade vendor programs that don't fit their staffing level.
Does this proposal change how I assess fintech and technology vendor relationships?
Potentially significantly. One of the agencies' explicit critiques of the 2023 guidance was that it had chilled engagement with fintechs and innovative providers. The proposed framework is designed to allow banking organizations to work with emerging technology vendors without applying full enterprise TPRM due diligence to relationships that don't present meaningful financial, operational, or compliance risk. Risk-proportionate oversight means low-risk vendor relationships get oversight calibrated to that lower risk.
When does the new TPRM guidance take effect?
The guidance is in proposed form as of September 26, 2026. Comments are due November 16, 2026. After the comment period, the agencies will issue final guidance that would supersede the 2023 framework. There is no announced effective date for the final guidance — it takes effect when published in final form.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Third-Party Risk Management (TPRM) Kit

Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.