Federal Regulators Propose New Approach to Third-Party Risk Management
Never miss a thing.
Sign up to receive our insights newsletter.

Federal banking regulators on September 11, 2026, proposed a revised approach to third-party risk management that would give financial institutions greater flexibility to tailor their oversight to the risks presented by individual relationships.
The Federal Deposit Insurance Corporation (FDIC), Federal Reserve, Office of the Comptroller of the Currency and National Credit Union Administration issued proposed interagency guidance that would replace the agencies’ 2023 guidance on third-party relationships. The agencies also issued a joint statement addressing community banks’ engagement with service providers that support essential banking operations. The proposal emphasizes a risk-based approach, recognizing that third-party relationships vary widely in their importance, complexity and potential impact and should not necessarily be subject to the same level of due diligence and oversight.
If finalized, the guidance could give financial institutions more latitude to focus resources on third-party relationships that pose the greatest financial, operational, compliance or customer risks.
A More Tailored, Risk-based Approach
A central theme of the proposed guidance is that third-party risk management should be tailored to an institution’s size, complexity and risk profile. Rather than applying the same level of oversight to every vendor or service provider, institutions would be expected to scale their risk management activities to the nature and significance of each relationship.
That could mean directing more targeted attention to third parties that present significant financial, operational, compliance or customer risks, while using less extensive oversight for lower-risk relationships. The proposal also recognizes that effective third-party risk management does not require institutions to eliminate all risk. Instead, institutions should understand the risks presented by third-party relationships, establish appropriate controls and determine whether any remaining risk is acceptable.
What the Proposal Could Mean in Practice
The proposed guidance would retain familiar elements of third-party risk management, including risk assessment, due diligence, contract negotiation, ongoing monitoring and planning for termination of a relationship. The proposal would allow institutions to scale the scope and frequency of those activities to the level of risk associated with the third-party relationship.
For example, institutions may be able to use streamlined due diligence or publicly available information when evaluating some lower-risk third parties. Relationships involving critical operations or greater potential risk may warrant more extensive due diligence, ongoing monitoring and management oversight.
The proposal also continues to emphasize governance. Institutions should establish clear responsibilities for third-party risk management, provide appropriate board and management oversight and periodically conduct independent reviews to determine whether their programs and controls are working as intended.
Using Independent Sources to Support Oversight
The proposed guidance also recognizes that institutions may use information from a variety of independent sources when assessing and monitoring third-party relationships. These may include third-party assessments, certifications, audits, consultants and industry organizations.
For financial institutions, the ability to use these sources could help make due diligence and ongoing monitoring more efficient, particularly when information is reliable and appropriate for the risks associated with the relationship. Independent assessments, including SOC reports and other risk-based reviews, may provide useful information about areas such as controls, cybersecurity, operational resilience and compliance.
What Financial Institutions Can Do Now
Although the guidance remains a proposal, financial institutions can begin considering how well their current third-party risk management programs align with the principles it outlines.
That review could include whether vendor risk classifications reflect actual business and regulatory risk, due diligence and monitoring are appropriately scaled to the risk of individual relationships and management has sufficient visibility into critical third parties. Institutions may also want to re-evaluate their governance processes to support informed decisions about accepting residual risk. That review could include whether independent assurance activities provide useful information about third-party controls and performance.
Weaver’s financial services and risk advisory professionals monitor the proposed guidance and its implications for third-party risk management programs. Contact us to discuss how the guidance could affect your organization’s approach to third-party risk assessment, oversight and governance.
©2026
