Feature Third-Party Risk
Your TPRM Program Classifies Vendor Risk. It Doesn't Measure Vendor Concentration. Here's What Examiners Are Starting to Ask For.
The September 2026 interagency TPRM proposal and the joint statement on core providers both point toward concentration risk analysis — but most TPRM programs only assess individual vendor risk, not portfolio-level concentration. Here's the analysis gap and what to build.
Table of Contents
TL;DR
- The September 2026 interagency TPRM guidance proposal and the joint statement on core providers both point toward concentration risk as a gap in current programs — but most TPRM frameworks only evaluate vendors individually, not the portfolio as a whole
- The difference between vendor risk assessment and vendor concentration analysis: one tells you how bad it would be if Vendor X failed; the other tells you how many critical systems fail simultaneously if Vendor X fails
- The joint statement on core providers explicitly flagged deconversion fees and integration lock-in as contract provisions that create and entrench concentration risk — examiners are starting to ask banks how locked in they are
- Building a concentration analysis requires four components: portfolio concentration map, single-point-of-failure inventory, exit timeline analysis, and platform concentration assessment (whether separately contracted vendors share underlying infrastructure)
Your third-party risk program has a vendor list, a risk tier for each vendor, and a due diligence process calibrated to each tier. That’s the baseline the agencies have required since at least 2013.
Here’s what it probably doesn’t have: any measurement of what happens when one vendor on that list has a problem — and that problem takes down five other things simultaneously.
That gap has a name. It’s vendor concentration risk. And based on the direction of the September 2026 interagency TPRM guidance proposal and the accompanying joint statement on core service providers, it’s what examiners are going to start probing in your next review cycle.
The Difference Between Vendor Risk and Vendor Concentration Risk
Vendor risk assessment answers one question: how dangerous is this vendor to our organization? You assess the vendor’s financial health, cybersecurity posture, business continuity program, and the regulatory and operational consequences if that specific relationship fails. A critical vendor gets deep due diligence; a low-risk vendor gets lighter treatment.
Vendor concentration risk answers a different question: what percentage of your total exposure is concentrated in this vendor?
A vendor can score low on individual risk while creating severe concentration risk. Consider a mid-size community bank whose core processor handles deposit accounts, loan origination, ACH processing, and debit card authorization. Each of these functions, assessed individually, might show a “critical but manageable” vendor risk. But if all four fail simultaneously in a core processor outage — which is exactly what happens in a 72-hour system disruption — the institution isn’t facing one critical vendor problem. It’s facing its entire operational infrastructure offline at once.
The standard TPRM due diligence process doesn’t surface this risk because it’s not designed to. Due diligence asks: can this vendor continue operating? Concentration analysis asks: if this vendor stops operating, what percentage of our critical functions stop with it?
What the September 2026 Guidance Signals
The September 11, 2026 interagency TPRM guidance proposal introduced a “magnitude and likelihood of harm” framework to replace the existing critical-activity-based approach. The key word is “magnitude.” It’s doing work that vendor tier classifications don’t do.
Magnitude-based assessment has to account for the scale of impact — not just whether a vendor’s failure would be bad, but how much of your operations it would take offline and for how long. A vendor that supports one business line presents a different magnitude than a vendor that supports five business lines on the same platform.
The guidance explicitly supports lighter oversight for lower-risk vendors, which means you need to have done the portfolio-level analysis to know which vendors are actually lower-risk. A vendor handling commodity services with no access to customer data and no operational dependencies is genuinely low-risk. A vendor handling commodity services that runs on the same cloud infrastructure as your critical payment systems is not.
The accompanying joint statement on community banks’ engagement with core service providers — issued the same day — makes the concentration implication explicit. The three agencies called out specific contract provisions they will consider in supervisory decisions: deconversion fees, back-billing windows, and restrictions on third-party integrations.
Why those three? Because each one is a mechanism that entrenches concentration. A deconversion fee that costs a community bank $1.5 million to switch core processors doesn’t just make switching expensive. It makes meaningful oversight difficult. You can’t credibly tell your core processor that you’ll take your business elsewhere if you can’t actually afford to leave.
The OCC’s Bulletin 2026-47 and the interagency joint statement put core providers on notice that the agencies may treat them as institution-affiliated parties subject to direct enforcement. But the institution’s side of the conversation requires a concentration analysis — you have to know how locked in you are before you can have an informed conversation about whether you need to be.
The Four Concentration Gaps Most Programs Are Missing
1. Portfolio Concentration Map
Do you know, for each vendor, which business functions depend on it? Most vendor inventories list vendors and their contract terms. They don’t produce the inverse view: for each critical business function, which vendors support it, and what is the overlap?
The overlap is where concentration appears. If your payment processing, customer authentication, and mobile banking platform all run through vendors that contract separately but operate on AWS us-east-1, then a single AWS regional disruption creates a concentration event — even though no individual vendor assessment would have flagged it.
Building the portfolio concentration map requires connecting the vendor inventory to the business impact analysis — a step that TPRM and BCP programs often treat as separate workstreams.
2. Single-Point-of-Failure Inventory
A single-point-of-failure (SPOF) in a vendor portfolio is a vendor whose loss would cause a critical business function to fail completely, with no available fallback.
Current TPRM frameworks typically assess whether a vendor has its own business continuity program. That’s a vendor-level assessment. The SPOF inventory is a portfolio-level assessment: even if the vendor has a solid BCP, does your institution have an alternative path to deliver this function if the vendor is unavailable for 72 hours? For a week?
Community banks frequently have SPOF exposure in their core processor relationship — there is no 72-hour fallback for deposit account processing when the core processor goes down. The question the joint statement is implicitly asking: have you acknowledged and documented this SPOF exposure, and what is your plan?
3. Exit Timeline and Cost Analysis
The joint statement’s focus on deconversion fees reflects a gap that most TPRM programs don’t address: the exit feasibility analysis. Vendor due diligence assesses whether you should stay with a vendor. Exit analysis asks whether you could realistically leave.
For every critical vendor, the analysis should include:
- Contract exit provisions: What are the termination rights, notice periods, and wind-down obligations?
- Deconversion or transition costs: What would it cost in fees, internal resources, and downtime to exit this relationship?
- Transition timeline: Realistically, how long does it take to migrate this function to an alternative provider? (For core processors, this is typically 18-36 months for community banks.)
- Alternative provider availability: Are there credible alternatives, and have you had preliminary conversations with them?
The point isn’t that you should exit every concentrated vendor relationship. The point is that if you’ve never done this analysis, you don’t actually know whether your oversight is credible. A vendor that would cost you $2 million and 24 months to exit is a vendor you have significant leverage problems with.
4. Platform Concentration Analysis
Platform concentration is the hardest to identify because it doesn’t appear on vendor contracts. It requires asking whether vendors you treat as separate relationships actually share underlying infrastructure.
Common platform concentration scenarios:
- Multiple “independent” SaaS vendors all running on AWS or Azure, creating correlated failure risk in a cloud outage
- Payment network concentration: ACH, wire, and card processing all ultimately clearing through the same underlying payment network
- Custodian and back-office software vendors owned by the same parent company
- API aggregators that route through a small number of core banking data providers
Cloud concentration risk in financial institution BCPs has been documented extensively — the CrowdStrike outage and subsequent AWS incidents showed that hyperscaler concentration creates simultaneous failure across dozens of seemingly independent vendor relationships. Platform concentration analysis extends this logic to your specific vendor portfolio.
The Examiner Conversation
The most common TPRM examiner ask before the September 2026 guidance: “Show me your vendor inventory and your due diligence documentation for critical vendors.”
The emerging ask, consistent with the guidance’s direction: “What percentage of your critical systems run through your largest vendor? Have you mapped your single-point-of-failure exposures? What does your exit analysis say about core processor transition?”
The difference is the level of analysis. The first question can be answered with a vendor list and a file of due diligence questionnaires. The second requires a portfolio-level view that most current programs haven’t built.
Institutions that can show the examiner a concentration map — here are our critical vendors, here are the business functions each supports, here is our SPOF inventory, here is our exit analysis for the top five by concentration — are in a materially better position than institutions whose TPRM program is vendor-by-vendor due diligence documentation.
This isn’t about having perfect concentration management. It’s about demonstrating that the program is asking the right questions.
So What? Building the Concentration Analysis
Step 1: Produce the portfolio concentration map. Take your vendor inventory and, for each vendor, document which critical business functions it supports. Then produce the inverse: for each critical business function, list all vendors that support it. The functions that have only one vendor supporting them are your SPOF candidates.
Step 2: Run a SPOF test for your five most concentrated vendors. For each of your five largest vendors by function count, document what happens operationally in a 72-hour outage. No workarounds, no “we’d call the vendor.” What actually stops working, and what are your manual fallbacks?
Step 3: Complete an exit analysis for your core processor. Get the deconversion fee from your current contract. Get an informal estimate of the transition timeline from a competing core provider. Document the analysis. If the deconversion fee or transition timeline is prohibitive, document that too — and present it to the board as a concentration risk acknowledgment.
Step 4: Add concentration metrics to your vendor risk reporting. Your quarterly vendor risk report should include at minimum: number of critical functions with single-vendor dependencies, percentage of critical functions supported by your top three vendors, and current contract exit exposure for core vendors. These are the metrics that tell your board whether concentration risk is increasing, stable, or decreasing — the same way loan concentration limits work in credit risk management.
The comment period on the interagency TPRM guidance proposal closes November 16, 2026. Whether you engage in the rulemaking or not, the direction the agencies are moving is clear. Risk-proportionate oversight requires knowing what your portfolio looks like — not just what individual vendors look like.
A complete TPRM Kit that includes vendor inventory templates, due diligence questionnaires, and risk rating frameworks is the starting point. But the portfolio concentration analysis has to be built on top of that infrastructure — and it’s the layer that the September 2026 guidance is asking about. Sources for building the concentration framework include the OCC Bulletin 2026-47 supervisory factors, the FDIC joint statement on core service providers, and the Mayer Brown analysis of the September 2026 interagency proposals.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is vendor concentration risk and how is it different from third-party risk assessment?
Does the September 2026 interagency TPRM proposal require concentration analysis?
What specific questions are examiners asking about vendor concentration?
How does the joint statement on core providers connect to concentration risk?
What should a vendor concentration analysis include?
What concentration risk thresholds should financial institutions use?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Keep reading
Related posts.
Third-Party Risk
Four Agencies Just Proposed to Kill the TPRM Checklist. Here's What 'Risk-Proportionate' Vendor Oversight Actually Means.
On September 11, 2026, the OCC, Federal Reserve, FDIC, and NCUA jointly proposed new interagency TPRM guidance to replace the 2023 framework. The core change: stop treating every vendor the same. Comments are due November 16. Here's what it means for your program.
Sep 26, 2026
Third-Party Risk
The Regulators Just Proposed Scrapping the 2023 TPRM Guidance. Here's What the Replacement Says.
On September 11, 2026, the OCC, Fed, FDIC, and NCUA proposed to rescind and replace the 2023 interagency TPRM guidance. The new framework shifts from prescriptive checklists to a harm-based, risk-tailored standard. Comments due November 16.
Sep 18, 2026
Third-Party Risk
Your Vendor Had a Breach in November. You Found Out in July. Eight Months of Invisible Risk — and Your TPRM Contract Probably Allowed It.
Paylogix, a SaaS employee benefits administrator, was breached by the Akira ransomware group in November 2025. Its insurance-carrier clients didn't get notified until July 20, 2026 — nearly eight months later. Here's what that gap reveals about the vendor breach notification requirements most TPRM programs are missing.
Sep 15, 2026