Why it matters
- Four federal regulators proposed principles-based, non-binding guidance for banks and credit unions managing third-party relationships, with comments due 60 days after Federal Register publication.
- The proposal would replace existing third-party guidance if finalised, alongside a separate statement on community banks' core service providers and a Fed companion guide.
- Clear examination standards and transparent responsibility for cloud and fintech dependencies would improve resilience without turning supervisory guidance into a shadow law.
The United States' main bank regulators have opened a consequential question about who really runs the financial system. The Federal Reserve, FDIC, National Credit Union Administration and Office of the Comptroller of the Currency asked for comments Friday on proposed guidance for managing third-party relationships, including the outside providers on which banks increasingly rely.
The agencies describe the proposal as principles-based and non-binding. They say it would help banks and credit unions tailor oversight to the risk of each relationship, and that a final version would replace existing third-party guidance. The agencies also issued a statement about community banks' engagement with core service providers, while the Fed proposed a companion guide for the community banks it supervises. Comments are due 60 days after publication in the Federal Register.
The policy problem is real. A bank may own the customer relationship while a cloud company, software vendor or fintech partner carries the data, payments or operational process that makes the relationship work. A failure at one provider can therefore become a concentration event across many institutions. But supervision becomes brittle when non-binding guidance quietly functions as law, with firms learning the real standard only during an examination.
The agencies should publish a risk taxonomy, model examination questions and anonymised examples of the evidence that would trigger escalation. They should also identify which duties belong to the bank, which can be tested through a provider and which require a regulator-to-provider channel. That would let smaller banks buy useful technology without pretending that a checklist can substitute for resilience, and it would give vendors a clear incentive to document recovery, subcontracting and data controls.
The goal should be fewer surprises, not more paperwork. Regulators are right to update a framework built for a financial system that now runs through a dense vendor network. They should make the framework transparent enough that banks can comply before a failure, rather than discover after one that voluntary guidance had become an invisible rule.
Sources
- Federal Reserve Board, Agencies seek comment on proposed third-party risk management guidance and issue statement on community bank engagement with core service providers, September 11, 2026
- Office of the Comptroller of the Currency, Agencies Seek Comment on Proposed Third-Party Risk Management Guidance, September 11, 2026
- Bloomberg, Fed, FDIC, OCC Unveil Bank Third-Party Risk Management Proposal, September 11, 2026
