Skip to content
Connecting live market data
Full board

Banking

Four Agencies Want to Replace the 2023 Third-Party Risk Rules. The Proposal Says It Sets No Enforceable Standards.

The replacement is principles-based and organised around four components. It would also rescind three supplemental documents issued in 2024. Comments close November 16, and one Federal Reserve governor dissented.

Wallcrest Banking DeskPublished 18 Sept 2026, 05:20 UTCUpdated 18 Sept 2026, 05:20 UTC3 min read
Four Agencies Want to Replace the 2023 Third-Party Risk Rules. The Proposal Says It Sets No Enforceable Standards. — Wallcrest Media cover image
Photo: Photo by introspectivedsgn / Pexels · Pexels License — free to use, no attribution legally required (credited above as good practice).

The short answer

  • The OCC, Federal Reserve, FDIC and NCUA have proposed guidance that would replace the 2023 Interagency Guidance on Third-Party Relationships: Risk Management.
  • The proposal states it sets forth no enforceable standards or prescriptive requirements, and that deviation from it alone would not trigger supervisory action.
  • It is organised around four components: risk identification and assessment, risk oversight, residual risk acceptance, and governance.
  • Comments are due November 16, 2026. Federal Reserve Governor Michael Barr dissented from the proposal.

On September 11 the four federal banking agencies - the Office of the Comptroller of the Currency, the Federal Reserve Board, the Federal Deposit Insurance Corporation and the National Credit Union Administration - proposed new guidance on how banks and credit unions should manage the risks of the outside firms they depend on. It was published in the Federal Register on September 15. Comments are due November 16, 2026.

What it would replace

The proposal would rescind the 2023 Interagency Guidance on Third-Party Relationships: Risk Management, which has been the governing framework for bank relationships with vendors, service providers and fintech partners. It would also rescind the supplemental material the agencies issued in 2024 to explain it - OCC Bulletin 2024-20, the Board's SR Letter 24-5, and FDIC FIL-45-2024 - along with related resources.

The dockets are OCC-2026-0793, Board OP-1881, FDIC 3064-ZA58 and NCUA-2026-1684.

The agencies' criticism of their own 2023 guidance

The proposal sets out what the agencies now think went wrong with the framework they wrote three years ago. Four complaints recur.

  • The examples in the 2023 guidance were read as de facto checklists, which discouraged institutions from exercising tailored judgement.
  • The repeated use of "should" failed to convey that practices were meant to be scaled to an institution's own risk profile.
  • The organising concept of "critical activities" was too blunt compared with assessing the magnitude and likelihood of potential harm.
  • The guidance carried a bias toward eliminating risk rather than managing it, which discouraged relationships with newer and smaller providers.

The four components

In place of that structure the proposal sets out four components: risk identification and assessment; risk oversight, which covers due diligence, contracting, ongoing monitoring and termination; residual risk acceptance; and governance. The emphasis throughout is on scaling oversight to the size and complexity of the institution and to the risk actually present in a given relationship.

The document also says plainly that it "sets forth no enforceable standards or prescriptive requirements," and that an institution departing from it would not for that reason alone face supervisory action. That sentence is the proposal's central claim about its own status, and it is the sentence the comment period is most likely to be about.

The dissent

Federal Reserve Governor Michael Barr voted against. In his dissent he said the proposals would "reduce safe and sound operations, increase financial and other risk, create undue confusion, and leave gaps in supervisory coverage." He objected in particular to language directing examiners to give due consideration to an institution's own risk judgements, arguing it could be read as requiring deference rather than independent supervisory assessment.

A separate proposal for community banks

The Federal Reserve simultaneously proposed its own third-party risk management guide for the traditional community banking organisations it supervises, published in the Federal Register the same day as a companion to the interagency document. Alongside both, the four agencies issued a joint statement on how community banks deal with core service providers, which Wallcrest covers separately.

Sources

Spotted an error? Tell our corrections desk.

How this article was produced

Responsible desk:
Banking & Payments
Published:
18 Sept 2026, 05:20 UTC
Last updated:
18 Sept 2026, 05:20 UTC
Verification:
Figures and quotations checked against primary sources under our fact-checking policy and editorial standards.
Independence:
No advertiser or affiliate partner had any involvement in this article — see editorial independence and how we make money.

This article is general financial information and journalism, not personalised financial, investment, tax or legal advice.

Share

third-party riskbank supervisionOCCFDICNCUAFederal Reserveguidance