The OCC, Fed, FDIC, and NCUA proposed new interagency guidance on third-party risk management in September, replacing the 2023 guidance that banks said was overly broad and checklist-driven. The new guidance emphasizes risk identification and assessment, allowing banks to tailor oversight to the actual risk posed by each relationship. It drops the “critical activities” concept and the prescriptive contract-term checklist, leaving it to each bank to determine which relationships warrant more scrutiny. The Fed also proposed a companion guide for community banks under $30 billion in assets, organized around four risk areas and eight common vendor categories. Comments are due November 16, 2026.
What you should do: Do not mistake a permissive attitude for a lack of scrutiny. Any third-party relationship must be underpinned by rigorous due diligence, clear contractual agreements, and ongoing monitoring. The responsibility for compliance and risk management ultimately rests with the bank.
Sources:
https://www.occ.gov/news-issuances/bulletins/2026/bulletin-2026-46.html