Federal banking regulators have launched a joint proposal to update risk management frameworks for financial institutions working with outside vendors.
Key points
- The Federal Reserve, FDIC, NCUA, and OCC jointly requested comment on proposed third-party risk management guidance.
- The guidance utilizes a principles-based approach and is non-binding, aiming to promote consistency and prudent innovation.
- Comments are due 60 days following publication in the Federal Register.
- Separately, agencies issued a statement regarding community bank engagement with core service providers.
US financial regulators have launched a joint initiative to reshape how banking institutions oversee outside vendors, seeking public feedback on updated risk management frameworks. The Federal Deposit Insurance Corporation, the Federal Reserve Board, the National Credit Union Administration, and the Office of the Comptroller of the Currency announced the proposal on September 11, 2026, aimed at helping institutions better align oversight practices with individual vendor risks.
Overhauling Vendor Oversight Frameworks
The proposed framework draws from supervisory experiences and lessons gathered during routine examinations of financial institutions. According to the regulatory agencies, the updated approach applies a principles-based methodology intended to help banks and credit unions tailor their internal controls.
Once finalized, the federal regulators intend to rescind older, existing guidance on third-party relationships and replace it entirely with the new standards. The goal is to establish a consistent regulatory baseline across the banking industry while supporting prudent technological and operational innovation.
Community Banks and Core Service Providers
Alongside the broader guidance, the agencies released a joint statement focusing on community banks and their engagement with core service providers. This document outlines the specific factors regulators will weigh when making supervisory and enforcement determinations regarding these essential technology and service partners.
Additionally, the Federal Reserve Board issued a separate request for comment on a companion guide designed specifically for Federal Reserve-supervised community banking organizations. Public comments for the main proposed guidance will remain open for 60 days following its official publication in the Federal Register.
What this means for investors
For investors keeping an eye on the banking sector, changes to vendor risk management frameworks can influence compliance costs and operational strategies at financial institutions. As banks increasingly rely on technology vendors and external service providers for core operations, regulatory expectations around oversight continue to tighten. Clearer supervisory guidelines help institutions manage potential disruptions, cybersecurity vulnerabilities, and operational failures.
While the proposed guidance is non-binding, finalized rules typically set the benchmark for supervisory examinations. Investors should monitor how financial institutions adapt their compliance programs and whether smaller community banks face distinct operational hurdles as these regulatory standards take shape.
Frequently asked questions
Which regulatory agencies are involved in the proposal? The joint initiative involves the Federal Reserve Board, the Federal Deposit Insurance Corporation, the National Credit Union Administration, and the Office of the Comptroller of the Currency.
How long is the public comment period? Comments on the proposed third-party risk management guidance are due 60 days after its publication in the Federal Register.
This article is for information only and is not investment advice. Do your own research or consult a licensed adviser before investing.
Based on information published by U.S. Federal Reserve Board. Source: U.S. Federal Reserve Board. Spotted an error? corrections@moneypuran.com


