Feature Third-Party Risk
Four Agencies Just Proposed to Kill the TPRM Checklist. Here's What 'Risk-Proportionate' Vendor Oversight Actually Means.
On September 11, 2026, the OCC, Federal Reserve, FDIC, and NCUA jointly proposed new interagency TPRM guidance to replace the 2023 framework. The core change: stop treating every vendor the same. Comments are due November 16. Here's what it means for your program.
Table of Contents
TL;DR
- On September 11, 2026, the OCC, Federal Reserve, FDIC, and NCUA proposed new interagency TPRM guidance to replace the 2023 framework; comments due November 16
- The core change: stop running every vendor through the same process — oversight should be calibrated to the “magnitude and likelihood of harm” each relationship actually presents
- The agencies admitted the 2023 guidance backfired: it drove checklist compliance, prioritized process over risk substance, and chilled engagement with fintech and innovative providers
- Core service providers — Jack Henry, FIS, Fiserv and their peers — now face direct supervisory scrutiny as potential institution-affiliated parties
- This is proposed guidance, not final rule — but the agencies’ direction is clear enough to act on now
Your vendor list includes a coffee machine supplier, a SaaS analytics tool you pay $200 per month for, and the core processor your entire banking operation runs through. Your TPRM program probably treats all three with some version of the same due diligence process.
That’s exactly what four banking regulators just said needs to change.
On September 11, 2026, the OCC, Federal Reserve, FDIC, and NCUA jointly proposed replacing the existing interagency third-party risk management guidance with a fundamentally different framework — one built on the principle that vendor oversight should match the risk each relationship actually presents, not apply a uniform process regardless of stakes. The proposal appeared in the Federal Register on September 15 with a comment deadline of November 16, 2026.
Why the Agencies Said the 2023 Guidance Failed
The 2023 interagency guidance — which itself replaced OCC Bulletin 2013-29, the Fed’s SR 13-19, and the FDIC’s FIL-44-2008 — was supposed to create a unified TPRM framework. It did. But according to the agencies, it created the wrong kind.
In the preamble to the September proposal, the agencies made an unusual acknowledgment: the existing guidance had produced outcomes they didn’t intend. Specifically, they said the 2023 framework had been interpreted as:
- Requiring a broad, process-driven approach that applies the same risk management practices across all vendor relationships regardless of actual risk
- Driving checklist compliance rather than substantive risk assessment
- Incentivizing process completeness over risk substance
- Chilling engagement with fintechs and innovative providers — because banks were applying enterprise due diligence to vendors that didn’t warrant it
That fourth point is worth pausing on. Banking regulators rarely admit in writing that their guidance produced industry-wide behavior they consider problematic. The explicit call-out of the “fintech chilling effect” signals where the regulatory community has landed on bank-fintech partnership oversight: the answer to third-party risk is not blanket avoidance of novel vendor relationships.
The proposed guidance is designed to course-correct.
What “Risk-Proportionate” Actually Means
The phrase “risk-proportionate” does significant work in the proposed framework, so it’s worth unpacking what the agencies say it means in practice.
Under the 2023 guidance, the organizing concept was “critical activities” — relationships that supported a banking organization’s critical activities received elevated oversight, while others got baseline treatment. But “critical activity” became a broad category, and the elevated-oversight process still applied the same template across relationships within that tier.
The proposed replacement framework directs banking organizations to calibrate oversight to “the magnitude and likelihood of harm of each relationship.” This is a different unit of analysis than “critical activity” — it asks you to assess the specific risk each vendor could cause, then design oversight proportionate to that assessment.
In practice, this means:
- A cloud infrastructure provider hosting your core banking system gets deep due diligence, continuous monitoring, and detailed contract terms covering data security, business continuity, and exit provisions
- An analytics SaaS tool with no access to customer PII and no operational dependencies gets a lighter assessment appropriate to the risk it presents
- Vendors offering commodity services (facilities management, certain HR tools) may warrant minimal formal TPRM structure
The guidance doesn’t define fixed thresholds for what triggers which level of oversight. The framework is principles-based — which is both its strength and its challenge. Principles-based guidance requires judgment, and judgment requires a documented rationale.
The Core Service Provider Problem
One of the most consequential changes in the proposal is the treatment of core service providers — firms like Jack Henry & Associates, FIS, and Fiserv that provide mission-critical technology infrastructure to large numbers of banks and credit unions simultaneously.
The proposal introduces a mechanism for direct supervisory scrutiny of these providers, with the possibility of enforcement actions against them as institution-affiliated parties. Under the current framework, examiners can only reach core service providers through the banking organizations they serve. The proposed framework opens the door to examining the vendors themselves.
The practical implication for banking organizations: a vendor’s potential regulatory exposure becomes a dimension of your own vendor risk assessment. A core service provider that becomes the subject of enforcement action — even enforcement it caused rather than you — creates operational and reputational risk for the institutions that depend on it. The UK’s designation of AWS, Azure, Google Cloud, and Oracle as Critical Third Parties under the Financial Market Infrastructure Act offers a working preview of what direct regulatory oversight of technology vendors looks like in practice — and the concentration risk questions it forces banks to answer.
The joint statement on community bank engagement with core service providers specifically addresses the leverage imbalance that smaller institutions face with dominant core processors. It signals regulatory awareness that community banks often lack the contractual power to demand risk information, audit rights, or exit terms that a risk-proportionate framework technically requires from a well-functioning vendor relationship.
What the Community Bank Companion Guide Covers
For Federal Reserve-supervised institutions under $30 billion in assets, the agencies simultaneously proposed a practical guide providing non-binding examples for implementing the principles-based framework.
This addresses a real gap. The 2023 guidance was written for institutions large enough to have dedicated TPRM functions, legal teams that negotiate vendor contracts, and staff capacity to run full due diligence programs. Community banks under $1 billion often had one or two compliance staff members trying to apply enterprise guidance to a vendor population they couldn’t resource the same way.
The companion guide doesn’t lower the standard — it translates principles into examples that fit smaller institutions’ resource constraints. The key framing: what “proportionate” TPRM looks like for a $500 million community bank differs from what it looks like for a $50 billion regional bank or a systemically important institution.
What Your TPRM Program Should Do Now
The guidance is still proposed — comments are due November 16 and the final version will take time to arrive. But the agencies’ direction is clear enough to act on before the rule is finalized.
For institutions with mature TPRM programs:
Review your vendor risk tiering methodology. If “critical activity” support is your primary tiering criterion, the proposed framework gives you reason to revisit whether that criterion maps to “magnitude and likelihood of harm.” A vendor can support a critical activity without presenting meaningful harm potential; a vendor can present significant harm potential without supporting what your policy considers a critical activity.
For institutions still running one-size-fits-all processes:
The September proposal is the clearest regulatory signal yet that uniform checklist processes aren’t the standard. If your program applies the same questionnaire, contract checklist, and monitoring frequency to every vendor above a threshold, document the risk rationale — or revise the program to reflect actual risk differentiation.
For community banks under $30 billion:
The companion guide is not yet final, but its framing of proportionate oversight for resource-constrained institutions gives you a basis for calibrating your program without overbuilding. An honest assessment of which vendor relationships could cause you financial harm if they failed — versus which are operationally convenient but low-risk — is the right starting point.
The comment period matters:
The November 16 deadline is a real opportunity. The industry’s response shapes the final guidance. If your institution has specific feedback on how the risk-proportionate standard should work in practice — particularly for community banks navigating core service provider relationships where contract leverage is limited — this is the mechanism to provide it.
| Current (2023 Framework) | Proposed (September 2026) |
|---|---|
| “Critical activity” as primary tiering criterion | Magnitude and likelihood of harm as calibration standard |
| Same process applied across relationships in the same tier | Oversight proportionate to each relationship’s specific risk |
| Core service providers supervised only through banking organization | Direct supervisory scrutiny; potential institution-affiliated party status |
| No specific community bank companion document | Fed-supervised institutions under $30B: dedicated practical examples guide |
| Fintechs face full enterprise due diligence | Risk-proportionate standard reduces friction for low-risk fintech relationships |
So What?
This is the banking agencies admitting, in writing, that their 2023 TPRM guidance produced the wrong behavior at scale. A checklist-driven vendor program that applies the same process regardless of actual risk isn’t just operationally inefficient — it’s not what regulators want.
The comment deadline is November 16. The final guidance will take time. But the direction is clear: the question your TPRM program should be able to answer is not “did we run every vendor through our process?” — it’s “does our oversight match the risk each vendor relationship actually presents?”
For practitioners managing dozens or hundreds of vendor relationships, that’s a meaningful operational shift. A purpose-built TPRM program that differentiates vendor risk by actual harm potential — rather than applying a flat checklist — is what the proposed framework rewards. The OCC/FDIC’s concurrent work on what makes a practice ‘unsafe or unsound’ amplifies the same message: risk management programs should be oriented toward actual financial harm scenarios, not documentation compliance exercises.
Build toward that standard now, and the final guidance will feel like validation. Build toward checklist completion, and the next examination cycle will ask you to explain why your oversight doesn’t match your vendor population’s actual risk profile.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did the September 2026 interagency TPRM proposal actually change?
Who issued the proposed TPRM guidance and when?
What is the 'institution-affiliated party' risk for core service providers?
What is the community bank companion guide and who is it for?
Does this proposal change how I assess fintech and technology vendor relationships?
When does the new TPRM guidance take effect?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Keep reading
Related posts.
Third-Party Risk
The Regulators Just Proposed Scrapping the 2023 TPRM Guidance. Here's What the Replacement Says.
On September 11, 2026, the OCC, Fed, FDIC, and NCUA proposed to rescind and replace the 2023 interagency TPRM guidance. The new framework shifts from prescriptive checklists to a harm-based, risk-tailored standard. Comments due November 16.
Sep 18, 2026
Third-Party Risk
Your Vendor Had a Breach in November. You Found Out in July. Eight Months of Invisible Risk — and Your TPRM Contract Probably Allowed It.
Paylogix, a SaaS employee benefits administrator, was breached by the Akira ransomware group in November 2025. Its insurance-carrier clients didn't get notified until July 20, 2026 — nearly eight months later. Here's what that gap reveals about the vendor breach notification requirements most TPRM programs are missing.
Sep 15, 2026
Third-Party Risk
IDScan.net Exposed 153 Million Driver's Licenses on the Dark Web. Your KYC Vendor's Breach Is Your CIP Problem.
On September 1, 2026, a dark web marketplace began advertising 153 million driver's license scans traced to IDScan.net, a KYC identity verification vendor. For any financial institution using third-party identity verification: this isn't IDScan's problem alone. Regulators hold you responsible for customer ID data wherever it flows.
Sep 14, 2026