What the Third-Party Risk Package Deletes: The Bank-Fintech Statement, and the Examiner's Soft Landing
How the 2026 interagency third-party risk package rewrites the 2023 guidance (88 FR 37920), plus the operative Fed/FDIC/OCC Joint Statement on core providers.
By Lex
The press coverage of September 11 settled on two words: risk-based. Four agencies proposed replacing the 2023 interagency third-party risk guidance with something shorter and more deferential, the Comptroller talked about cutting regulatory friction, and the trade press filed it under deregulation. That reading is not wrong. It is aimed at the wrong document.
Three things landed that morning, and only two of them are proposals. The interagency guidance (FR Doc. 2026-18859, published September 15, comments due November 16, 2026) is out for comment. The Federal Reserve's companion guide for "traditional community banking organizations" (FR Doc. 2026-18852, Docket OP-1880) is out for comment. The Joint Statement on Community Banks' Engagement with Core Service Providers — signed by the Federal Reserve Board, the FDIC, and the OCC, dated September 11, 2026 — was issued. Not proposed. It is operative now. The part of this package that loosens supervision of banks is a draft; the part that reaches vendors is already live. Institutions reading the press release for relief have the sequencing backwards.
How we got here
The 2023 Interagency Guidance on Third-Party Relationships (88 FR 37920, June 9, 2023) organized vendor oversight around whether a third party supported "critical activities." The agencies now say, in their own words, that this failed: the 2023 guidance "frequently has been interpreted in an overly broad manner and with an insufficient focus on tailoring," was "interpreted as establishing prescriptive requirements," and "unintentionally incentivized overly-process-driven approaches that fail to prioritize higher-risk relationships."
That is an unusually direct concession, and it has a specific author. Governor Bowman declined to support the 2023 guidance, objecting that it "applies the same expectations to all banks, regardless of their size and complexity" and that the promised community bank resources came with "no timeline for development." Bowman is now Vice Chair for Supervision. Read the September 11 package as the delivery of that dissent — the tailored community bank tool she said should have been developed concurrently, arriving three years late, with the underlying guidance rewritten to match her critique.
The replacement rests on a two-part test. A higher-risk relationship is one that, if disrupted or breached, "could cause the banking organization to incur an actual non-trivial violation of law or regulation, pose material harm to the financial condition of the banking organization, or result in a significant disruption" — and where "there is a material likelihood" of that occurring. Magnitude times probability, replacing activity classification. Core processing relationships are "likely to be assessed by most banking organizations as higher risk." The landscaper is not.
The deletions
Footnote 2 is where the consequence lives. The proposal cites Executive Order 14405, "Integrating Financial Technology Innovation into Regulatory Frameworks," 91 FR 30475 (May 19, 2026), and declares itself a deregulatory action under Executive Order 14192 — but the operative move is deletion. Final guidance would replace the 2023 guidance and what the agencies label the "Supplemental TPRM Resources": OCC Bulletin 2002-16 on foreign-based third-party service providers (May 15, 2002); the community bank guide of May 3, 2024 (OCC Bulletin 2024-11, Board SR Letter 24-2/CA Letter 24-1, FDIC FIL-19-2024); and the Joint Statement on Banks' Arrangements with Third Parties to Deliver Bank Deposit Products and Services of July 25, 2024 (OCC Bulletin 2024-20, Board SR Letter 24-5, FDIC FIL-45-2024).
That last one is the post-Synapse document. It is the closest thing the sponsor-bank cohort has to a rulebook — the issuance that set expectations on ledger reconciliation, end-user recordkeeping, and deposit-product arrangements where a fintech, not the bank, faces the customer. Under this proposal it goes away, and nothing in either new document replaces it. The Fed's community bank guide says so expressly: it "is not intended for community banking organizations with more complex business models or third-party relationship profiles, such as complex bank-fintech partnerships (e.g., where a bank makes products or services available through an arrangement with one or more fintech companies and the fintech company, rather than the bank, markets, distributes, or otherwise provides access to the products or services)." The guide also puts consumer compliance out of scope, and limits itself to institutions under $30 billion in assets serving local communities.
So the BaaS cohort loses its guidance and is told, in the same package, that the new operational guide is not for them. Barr made precisely this point in dissent: "Experience suggests that many banks with complex business models are especially in need of guidance that better addresses their particular third-party risk management issues, which is not addressed in these proposals." He warned that rescission could leave "a big gap in risk, or banks could end up needing to comply with two sets of guidance." Footnote 5 then invites comment on "whether any additional guidance documents, interpretive letters, or other resources relevant to third-party risk management should also be rescinded" — an open nomination window the industry will use.
The awkward part is that examiner expectations do not decay on the same schedule as issuances. Field staff have been working the July 2024 statement for two years. Rescinding the citation does not unlearn the exam question; it removes the bank's ability to argue from a shared text, and being outside both regimes is worse than being inside either one. Chime's purchase of Stride Bank's parent, covered in our September 13 week-in-review (lexregpulse.com/brief/2026-09-13), starts to look less like integration strategy and more like a read of where sponsor-model supervision is heading.
Your risk assessment is now the operative document
The proposal contains three separate carve-outs limiting what an examiner may criticize. Deviation from the guidance "or any examples herein, including where an examiner believes that deviation or inconsistency is contrary to best practices, will not alone be a basis for supervisory action." On contracts: "There are no generally applicable expected contract terms for third-party relationships—even for higher-risk relationships," and the presence or absence of a term an examiner thinks is best practice "would not alone be a sufficient basis for an examiner to communicate an adverse finding." And on assessment itself: "examiners will give due consideration to a banking organization's reasonable judgment regarding the banking organization's risk assessments."
Read together, these do not reduce the institution's exposure. They relocate it. If the examiner cannot criticize the vendor file, the contract terms, or the monitoring cadence in isolation, the only remaining target is the reasoning that produced them — the risk assessment methodology. An institution that writes a thin, conclusory assessment has discarded the one instrument the agencies just promised to defer to. The thick vendor binder was the old compliance artifact; the defensible methodology is the new one, and most programs have the ratio inverted.
Barr flagged the deference language too, worrying it "may be misinterpreted to mean agencies will give deference to the bank's views on third-party risk management, rather than making an independent judgment." His broader objection is that the "material financial risk" standard makes it "less likely that banks will correct problems before they become material risks to the firm." To be fair, that is the strongest argument against the package, and it is partially right — the two-part test does raise the trigger. But it changes nothing about 12 U.S.C. 1818, and the guidance expressly preserves action for "violations of laws or regulations, unsafe or unsound practices, or other material risks." What actually disappears is the examiner's soft landing. Guidance-based criticism was the low-severity channel: an MRA citing a process gap, remediated without legal findings. Remove it and marginal concerns migrate toward violation-of-law and unsafe-or-unsound theories. Expect fewer third-party findings and harder ones — the same asymmetry we identified after the August 27 supervisory-standards rule (lexregpulse.com/brief/2026-09-15), where the bar for criticizing the institution rose while the standard applied to individuals did not.
Two smaller items deserve counsel's attention. On subcontractors: "The use of subcontractors alone does not typically create an independent third-party relationship or create a presumption of direct banking organization oversight of any subcontractors" — a real retreat on fourth-party risk. And footnote 9 floats limiting the guidance to third parties "subject to a written agreement," pushing informal arrangements out of the framework.
The vendor-facing half, which is already in force
The three-agency joint statement calls core providers "CBOs' most material, complex, and highest-risk third-party relationships" and concedes the market structure: "a significant percentage of the core provider market is represented by just a few large providers, which limits CBOs' negotiating power." It then lists factors the agencies will weigh in supervisory allocation decisions — including "whether to add a core provider to the agencies' service provider examination program" — under three headings: Transparency, Contract Features, and Technology.
The Contract Features list is the one to print out. It names opaque pricing structures; opaque billing including "extensive 'back billing' windows"; "unsupported or contractually undefined core deconversion fees," singled out where the provider breached the contract, missed its service levels, or "may have caused the CBO to violate any laws or regulations"; and "excessive limitations on the ability of unaffiliated service providers to integrate with the core platform." Under Transparency, contract provisions restricting a bank's ability to benchmark the provider against competitors are a listed factor. Under Technology: security-incident frequency and severity, end-of-life asset management, and absence of demonstrated resilience.
Note the design. The agencies told banks they will not be criticized for missing contract terms, and told core providers that their contract terms determine their supervisory profile. That is not inconsistency; it is a deliberate transfer of the contract fight out of the examination and into the vendor's renewal cycle. Every institution walking into a core negotiation now holds a federal document naming the provisions examiners consider obstacles to sound risk management.
Then the statement goes further than anything in the 2023 framework. The agencies state they "may have a reasonable basis to determine that certain core providers qualify as 'institution-affiliated parties'" under 12 U.S.C. 1813(u), specifically 1813(u)(3), as persons "who participate[] in the conduct of the affairs of an insured depository institution," and that "[b]ecause core providers are integral to carrying out the business of banking and the functions of CBOs, they may be held liable for the practices or violations of a CBO as an institution-affiliated party." Enforcement authorities cited are 12 U.S.C. 1818 and 1867; examination authority rests on 12 U.S.C. 1464(d)(7)(D) and 1867(c)(1). NCUA signed the four-agency guidance but is absent here — the machinery in this statement runs on Bank Service Company Act and FDI Act authorities the Federal Reserve, FDIC, and OCC hold.
What to watch
Comments close November 16, 2026. Three questions will decide the final shape. First, whether anything replaces the July 2024 deposit-products statement; Barr's dissent is the template for that comment letter, and sponsor banks who stay silent will deserve the outcome. Second, whether the written-agreement scoping limitation in footnote 9 is adopted. Third, the consumer compliance gap — the guidance addresses it only in footnote 8, acknowledging considerations "that may be relevant to, but that are not directly addressed in, this proposed guidance," while the Fed's guide excludes the subject outright. If the 2023 guidance is rescinded, the allocation of UDAP and Regulation E responsibility in vendor arrangements loses its interagency anchor.
On enforcement, the test is empirical: whether an agency actually names a core processor as an institution-affiliated party, and which providers appear in the service provider examination program over the next two exam cycles. Until then, the IAP paragraph is leverage rather than precedent. Leverage is not nothing — core provider contracts will move on back-billing, deconversion, and integration rights well before any action is brought, because the rational vendor response is to fix the paper first.
Bottom line
This package does not reduce third-party risk exposure; it moves it. Supervision narrows around the institution's process and widens around the institution's vendors, and the artifact that determines whether a bank is defended is no longer the vendor file but the risk assessment methodology that justifies it. Do three things before the comment window closes: rewrite the assessment methodology so it can survive being deferred to, mark the core contract against the joint statement's three factor lists ahead of the next renewal, and — if you run a sponsor-bank program — keep the July 2024 controls in place and file a comment letter, because you are the one cohort this package leaves without a document to cite.
Sources
- Proposed Third-Party Risk Management Guidance, FR Doc. 2026-18859 (OCC, Federal Reserve Board, FDIC, NCUA), Docket ID OCC-2026-0793 / OP-1881 / ZRIN 3064-ZA58 / NCUA-2026-1684: https://public-inspection.federalregister.gov/2026-18859.pdf and https://www.federalregister.gov/public-inspection/2026-18859/proposed-third-party-risk-management-guidance
- Proposed Third-Party Risk Management Guide for Traditional Community Banking Organizations, FR Doc. 2026-18852 (Federal Reserve Board), Docket OP-1880: https://public-inspection.federalregister.gov/2026-18852.pdf and https://www.federalregister.gov/public-inspection/2026-18852/proposed-third-party-risk-management-guide-for-traditional-community-banking-organizations
- Joint Statement on Community Banks' Engagement with Core Service Providers (Federal Reserve Board, FDIC, OCC), September 11, 2026: https://www.federalreserve.gov/newsevents/pressreleases/files/bcreg20260911a3.pdf
- Joint press release, "Agencies seek comment on proposed third-party risk management guidance and issue statement on community bank engagement with core service providers," September 11, 2026: https://www.federalreserve.gov/newsevents/pressreleases/bcreg20260911a.htm
- Statement on Third-Party Risk Management Guidance and Guide for Traditional Community Banks by Governor Michael S. Barr, September 11, 2026: https://www.federalreserve.gov/newsevents/pressreleases/barr-statement-20260911a.htm
- Statement on Third Party Risk Management Guidance by Governor Michelle W. Bowman, June 6, 2023: https://www.federalreserve.gov/newsevents/pressreleases/bowman-statement-20230606.htm
- LexRegPulse briefs: lexregpulse.com/brief/2026-09-12, lexregpulse.com/brief/2026-09-13, lexregpulse.com/brief/2026-09-15