THE CREDIT CURRENT RESEARCH LIBRARY
Deep-dive library
Law & regulation

Third-party oversight: what the 2026 proposal changes

How to interpret the proposed shift toward proportionate oversight, distinguish it from the core-provider statement, and build a defensible risk assessment.

September 27, 2026
Current version

Initial source-linked website research with operating analysis and limitations.

Status and scope

The Federal Reserve, FDIC, OCC and NCUA announced proposed third-party risk management guidance on September 11, 2026. The Federal Register notice published September 15 sets a November 16 comment deadline. The agencies intend to replace existing guidance when the new guidance is finalized; the proposal should not be treated as already final.

The September 11 joint announcement describes supervisory guidance as non-binding. The OCC bulletin emphasizes relationship-specific risk assessment and says the proposal does not create enforceable standards. That distinction matters: a checklist in guidance and an obligation in a statute, regulation or contract are different sources of authority.

The operating change is differentiation

The proposed text discusses tailoring oversight to the organization and the relationship, including monitoring intensity, termination and subcontractors. Risk can change over time, so the initial classification is not a permanent conclusion. A provider that once handled a minor workflow may become much more consequential after additional products depend on it.

Analysis: start with the activity and failure consequence. A vendor’s annual invoice is a poor stand-in for the damage caused by lost transaction records, erroneous credit decisions or an unavailable servicing channel. Record why the selected oversight is adequate for the dependency actually created.

A practical evidence map

The following is an analytical control design, not an agency-mandated checklist. Each item should have an owner and evidence that can be reproduced.

QuestionUseful evidenceReason it matters
What can fail?Workflow and data-flow mapReveals customer and financial consequences
Who can correct it?Escalation authority and response recordsAvoids responsibility gaps
Can the service be replaced?Tested data export and transition estimateMeasures concentration and exit risk
Is performance deteriorating?Exceptions, complaints and control resultsTests whether the original risk tier still fits

The core-provider statement is separate

OCC Bulletin 2026-47 describes an issued statement about supervision of certain core-provider services to community banks. It addresses how the agencies consider aspects of those relationships and their supervisory and enforcement authorities. It should be read alongside, not collapsed into, the broader proposed guidance.

Analysis: limited negotiating power is a reason to document compensating controls and escalation choices. It is not evidence that service dependence disappeared. A bank can distinguish a contract term it cannot obtain from an operational control it can still test.

Illustrative application: a merchant-finance platform

Assume a fictional bank uses one provider for application routing and a different provider for statements. The routing provider changes its decision payload; the servicing platform then receives an incomplete loan record. An annual vendor review could look satisfactory while this cross-provider failure remains invisible.

A useful response would trace one transaction from application through booking, funding, customer communication and correction. The bank would identify the source of truth, stop conditions and reconciliation owner. Testing that chain may provide more assurance than collecting another generic assurance report from each vendor separately.

Trade-offs and evidence that would change the view

Analysis: proportionate oversight can reduce low-value work and improve attention to consequential exposures. It can also fail if optimistic risk ratings become a reason to stop gathering evidence. Review whether resources actually moved toward higher-impact relationships and whether incident detection improved.

Revisit this article when final guidance changes the text, the comment deadline is amended, or authoritative interpretation clarifies scope. At the bank level, a new product, provider incident, acquisition, concentration increase or failed exit test can justify reassessment before the next scheduled review.

Sources