Third-Party Risk Management in Banking: A More Practical Approach to Vendor Oversight

Third-Party Risk Management in Banking: A More Practical Approach to Vendor Oversight

On September 11, 2026, the Office of the Comptroller of the Currency (OCC), Federal Reserve Board, Federal Deposit Insurance Corporation (FDIC), and National Credit Union Administration (NCUA) jointly proposed updated interagency guidance that would revise and replace existing third-party risk management guidance for banks and credit unions. Published in the Federal Register on September 15, 2026, the proposal emphasizes calibrating vendor oversight to the specific risks presented by individual relationships rather than applying standardized compliance procedures across all third-party relationships.

From Checklist Compliance to Relationship-Specific Risk Management

While the 2023 interagency guidance contemplated a risk-based approach, the regulatory agencies acknowledge that institutions have frequently interpreted and implemented those expectations too broadly. The proposed guidance seeks to refocus attention on risks specific to each third-party relationship, encouraging institutions to allocate oversight resources in proportion to the magnitude and likelihood of potential harm.

The appropriate level of oversight would depend on the institution’s size, complexity, and risk profile, as well as the nature of the services provided—a distinction of particular significance for community banks and credit unions that frequently outsource essential services performed in-house by larger institutions.

Effective third-party risk management would emphasize identifying material risks, implementing proportionate oversight, making informed decisions regarding residual risk, and maintaining appropriate governance practices.

What Does This Mean for Commercial Lenders? 

Commercial lending operations rely heavily on diverse third-party relationships, including loan origination platforms, appraisal management companies, title agencies, environmental consultants, loan servicers, and technology vendors. Under the proposed framework, the appropriate depth of oversight would be driven by the actual risks presented by each relationship, rather than merely by the fact that an outside provider is utilized.

Consider, for example, a third-party servicer managing a financial institution’s commercial loan portfolio. Such a relationship may present significant operational, financial, cybersecurity, and regulatory compliance risks, as a disruption could impair payment processing, tax escrow administration, borrower communications, or access to critical loan records.

By contrast, a vendor providing discrete, transaction-specific services may present a more limited operational risk profile, warranting correspondingly streamlined oversight.

Implications for Vendor Contracts and Core Service Providers

Vendor agreements routinely address indemnification, insurance, confidentiality, performance standards, audit rights, and termination. The proposed guidance expressly recognizes that no single set of contractual provisions is universally required—even for higher-risk relationships—and suggests that examiners should evaluate an institution’s third-party risk management practices based on the totality of the circumstances rather than the presence or absence of any particular contractual term.

An institution may reasonably proceed where it cannot negotiate all desired contractual terms, provided it reasonably understands the resulting risks and determines that the residual risk is consistent with its risk appetite and tolerances.

This flexibility is particularly relevant for community banks and credit unions negotiating with major core service providers whose standard contracts may offer limited opportunities for customization. Institutions may focus negotiations on the protections most important to mitigating material risks while appropriately documenting their acceptance of risks that cannot reasonably be eliminated.

Separately, the OCC, Federal Reserve, and FDIC issued an interagency statement addressing supervision of core service providers to community banks. Unlike the proposed guidance, this statement has already been issued and addresses factors the agencies will consider when making supervisory and enforcement decisions involving these providers.

Together, these developments acknowledge the commercial realities faced by community banks and credit unions that depend on a limited number of essential third-party service providers, while preserving the institutions’ responsibility to identify and manage the risks associated with those relationships.

What Should Financial Institutions Do Now?

Although the proposed guidance has not been finalized (the public comment period closes November 16, 2026), financial institutions should consider evaluating whether their existing vendor management practices appropriately reflect the risks presented by individual third-party relationships.

Institutions may wish to revisit how they classify vendor relationships, whether due diligence and ongoing monitoring procedures are appropriately tailored, and whether contract review practices distinguish between provisions necessary to mitigate material risks and those that may be less consequential in a particular relationship. Institutions should also consider whether their policies provide a practical framework for evaluating and documenting residual risk when desired contractual protections or diligence materials cannot reasonably be obtained.

Critically, the proposed guidance would not displace applicable laws or relieve institutions of responsibility for unsafe or unsound practices. The agencies distinguish between noncompliance with supervisory guidance, standing alone, and violations of law or material risks stemming from insufficient third-party risk management.

The proposal does not eliminate the need for meaningful third-party oversight. Rather, it emphasizes that effective risk management depends on identifying and addressing the risks that matter most—not simply completing standardized compliance procedures.

If you have questions about the proposed interagency guidance or its potential impact on your institution’s third-party risk management practices, please contact Pat Gill at jpg@shapirosher.com or any other member of Shapiro Sher’s Banking and Financial Services Group.