On September 15, 2026, the OCC, FRB, FDIC, and NCUA jointly published Proposed Third-Party Risk Management Guidance in the Federal Register. If finalized, it would rescind and replace the 2023 interagency guidance.
In this article, we’ll be reviewing who the guidance affects, what it says, how it differs from the current guidance, and what (if anything) you should do next.
The Quick Version
|
| NOTE The same day, the Federal Reserve Board separately published a Proposed Third-Party Risk Management Guide for Traditional Community Banking Organizations. That’s a different proposal and we’ll cover it in a separate article. |
The agencies released this proposed guidance jointly. If finalized, it would apply to financial institutions supervised by the:
Because the NCUA joined this publication, this guidance would apply to both banks and credit unions. The 2023 guidance only applied to banks.
One practical note worth keeping in mind: The proposal is very clear that it does not set enforceable standards, and that non-compliance with the guidance alone will not trigger supervisory action. The agencies can still act on violations of law, unsafe or unsound practices, or material risk, but the proposed guidance aims to be a set of principles, not a checklist to be graded against.
Existing TPRM guidance will be superseded. In the agencies’ words:
“The agencies plan to rescind and replace existing guidance on third-party risk management to promote consistency and innovation in the banking industry.”
Specifically, the proposal would rescind and replace:
Notably, the proposal does not mention several other pieces of currently active third-party risk management guidance, including:
The primary reason is the agencies believe the 2023 guidance “frequently has been interpreted in an overly broad manner and with an insufficient focus on tailoring its risk management principles.”
The proposal points to four specific ways the 2023 guidance fell short. In their view, it:
The agencies’ new goal is to “enable banking organizations and examiners to focus on material financial risks and violations of laws and regulations rather than ineffective and counter-productive check-the-box exercises.”
The proposed guidance is built around four components of third-party risk management. Here’s the short version of each.
Across all four components, one message comes through clearly: right-size the process. Here are a few quotes that really drive this idea home.
In short, the proposed guidance takes a practical, risk-driven view of third-party risk management, and it says so throughout the guidance.
Here are five key differences between the current and proposed third-party risk management guidance.
Current: The current TPRM guidance is nearly twice as long as the new proposal.
Proposed: The proposal calls the 2023 guidance an “extensive list of considerations” and, as a result, removed nearly all of the illustrative examples.
What This Means: The proposed version gives financial institutions far more latitude to manage third-party relationships as they see fit, as long as those relationships are managed in a safe and sound manner and don’t present material risk to the institution.
Current: Defines a third-party relationship as “any business arrangement between a banking organization and another entity, by contract or otherwise. A third-party relationship may exist despite lack of a contract or renumeration.”
Proposed: Defines it as “a business arrangement between a banking organization and an entity or individual for the provision of one or more products, services, and other activities that support the banking organization.”
A footnote adds that “third-party relationships typically involve written agreements” and that where there’s no written agreement or clear consideration behind an activity, “that activity is unlikely to constitute a third-party relationship.”
Separately, the proposal also states that institutions “may decide not to maintain extensive inventories of relationships posing limited risk.”
What This Means: The agencies appear to be intentionally limiting the scope, from essentially any relationship to those tied to a specific product or service. For the purposes of defining what is a third party, they seem to be giving weight to whether a written agreement exists and are signaling that your vendor inventory itself can scale based on risk.
Current: Primarily organized around the Third-Party Relationship Life Cycle (Planning, Due Diligence and Selection, Contract Negotiation, Ongoing Monitoring, and Termination), bookended by a small section about Risk Management and a section about Governance.
Proposed: Organized around four components: Risk Identification and Assessment, Risk Oversight, Residual Risk Acceptance, and Governance. The lifecycle now lives in the second component (Risk Oversight).
What This Means: The lifecycle still matters, but it is no longer the center of emphasis. The 2023 guidance mentioned performing a risk assessment without saying much about what this looks like. The proposal puts Risk Identification and Assessment as the foundation of the whole approach and focuses the rest of the guidance on activities to oversee, accept, and govern the risks, as appropriate.
Current: Recommends evaluating the volume and types of subcontracted activities and how much the third party relies on them. It also suggests reviewing the third party’s own third-party risk management program and building in applicable contractual requirements.
Proposed: States that “the use of subcontractors alone does not typically create an independent third-party relationship or create a presumption of direct banking organization oversight of any subcontractors.” It then adds subcontractors should factor into your risk oversight, and that you are still responsible for operating safely and soundly, regardless of whether a third party uses subcontractors or not.
What This Means: It would be a stretch to say the proposal clarifies what to actually do about subcontractors. It does confirm that oversight should be based on the risk presented, but subcontractor identification and management remains one of the more challenging parts to navigate.
Learn More: The Vendor Manager’s Guide to Subcontractor Risk Management
Current: Spends a lot of time discussing recommended contract language, with 17 lettered subsections covering everything from nature and scope, performance measures, and right to audit, to confidentiality and integrity, operational resilience, default and termination, and regulatory supervision.
Proposed: States plainly, “there are no generally applicable expected contract terms for third-party relationships” and that the presence or absence of any specific term an examiner might view as best practice “would not alone be a sufficient basis for an examiner to communicate an adverse finding.”
What This Means: Contracts still matter. But the proposal’s stance is that contract terms should be tailored to the risks a relationship presents, rather than drawn from a comprehensive list of provisions to include every time.
If this change would affect you, consider these three steps.
At Tandem, our goal is to help community financial institutions keep up with changes in regulations, guidance, and industry best practices. When new guidance comes out, we read it and make updates to the Tandem Software.
Tandem Vendor Management is our third-party risk management product. It helps you track your inventory, assess third-party risks, and manage those risks across the life cycle of each relationship.
If the guidance is adopted as proposed, several Tandem features are already built for exactly this kind of right-sized, risk-based approach. With Tandem, you can:
Choose whether to include your third parties in full or more limited oversight.
Answer significance questions to identify key risk factors and required due diligence types.
Perform a risk assessment to identify areas of heightened risk in the relationship.
Review contracts at an appropriate level with our standard or detailed review templates.
Set up notifications to review vendors on a frequency that fits the relationship.
Build custom documents to pull the right level of detail for governance and Board reporting.
See how Tandem can help you at Tandem.App/VM.
Is the 2026 TPRM guidance currently in effect?
No, it is a proposal open for public comment, as of September 2026. The 2023 interagency guidance remains in effect unless and until the final version is issued.
When are comments due on the proposed TPRM guidance?
Comments are due November 16, 2026.
When will the final TPRM guidance be published?
No date is currently set. The comment period closes November 16, 2026, and the agencies would review comments before issuing any final version. How long that takes generally depends on the volume and complexity of comments and how much the agencies decide to revise.
Does the 2026 TPRM guidance apply to credit unions?
Yes, the NCUA is one of the four issuing agencies. If finalized, the guidance would apply to federally insured credit unions, alongside banks.
Would any current TPRM guidance remain in effect?
Yes, quite a few. The current proposal only names four items to rescind, so anything it doesn’t mention (the FFIEC IT Examination Handbook, the fintech due diligence guide, the NCUA’s TPRM guidance, etc.) would stay in effect, as written, unless separately rescinded. The agencies did ask for comment on whether anything else should be rescinded.
What makes a third-party relationship “higher risk?”
It comes down to two things: how much harm the relationship could cause if it were disrupted, breached, or attacked, and how likely that harm is. Relationships that could trigger a violation of law, cause material financial harm, or significantly disrupt operations or customers are the ones most institutions treat as “higher risk.”
Is a written contract required for a third-party relationship?
Not necessarily, but it is a strong indicator. The proposal notes third-party relationships typically involve written agreements. This is a shift from the 2023 guidance, which said a relationship could exist even without a contract.