Information Security & Compliance Blog - Tandem

New Proposed Third-Party Risk Management (TPRM) Guidance | September 2026 Update - Tandem

Written by Alyssa Pugh | Oct 7, 2026, 3:13:24 PM

On September 15, 2026, the OCC, FRB, FDIC, and NCUA jointly published Proposed Third-Party Risk Management Guidance in the Federal Register. If finalized, it would rescind and replace the 2023 interagency guidance.

In this article, we’ll be reviewing who the guidance affects, what it says, how it differs from the current guidance, and what (if anything) you should do next.

The Quick Version

  • The federal banking agencies proposed new TPRM guidance. This guidance would rescind and replace the 2023 interagency guidance and its related community bank resources. 

  • The theme of the proposed guidance is right-sizing. Manage each third-party relationship in proportion to the risk it actually presents. Higher-risk relationships need more oversight, while lower-risk relationships may require a lighter touch.

  • The guidance is proposed. The 2023 guidance stays in effect until a final version is issued.

  • Comments are due November 16, 2026. No immediate action is required, but this signals where regulatory supervision may be heading. 

In This Article

NOTE 
The same day, the Federal Reserve Board separately published a Proposed Third-Party Risk Management Guide for Traditional Community Banking Organizations. That’s a different proposal and we’ll cover it in a separate article.

Who would be impacted by the TPRM guidance? 

The agencies released this proposed guidance jointly. If finalized, it would apply to financial institutions supervised by the: 

  • Office of the Comptroller of the Currency (OCC)
  • Federal Reserve Board (FRB)
  • Federal Deposit Insurance Corporation (FDIC)
  • National Credit Union Administration (NCUA)

Because the NCUA joined this publication, this guidance would apply to both banks and credit unions. The 2023 guidance only applied to banks. 

One practical note worth keeping in mind: The proposal is very clear that it does not set enforceable standards, and that non-compliance with the guidance alone will not trigger supervisory action. The agencies can still act on violations of law, unsafe or unsound practices, or material risk, but the proposed guidance aims to be a set of principles, not a checklist to be graded against.

What will happen to existing TPRM guidance?

Existing TPRM guidance will be superseded. In the agencies’ words:

 “The agencies plan to rescind and replace existing guidance on third-party risk management to promote consistency and innovation in the banking industry.” 

Specifically, the proposal would rescind and replace:

Notably, the proposal does not mention several other pieces of currently active third-party risk management guidance, including: 

The agencies did ask for comment on whether any other guidance or resources should also be rescinded, so the initial list could grow.
 

Why is the TPRM guidance being updated?

The primary reason is the agencies believe the 2023 guidance “frequently has been interpreted in an overly broad manner and with an insufficient focus on tailoring its risk management principles.”

The proposal points to four specific ways the 2023 guidance fell short. In their view, it:

  • Was unclear about which considerations apply to which third parties.
  • Focused on categorization (like “critical activities”) rather than a relationship’s actual risk.
  • Read as prescriptive, because words like “should” didn’t signal that risk management is meant to be tailored.
  • Discouraged arrangements with newer, innovative third parties by implying they carry elevated risk.

The agencies’ new goal is to “enable banking organizations and examiners to focus on material financial risks and violations of laws and regulations rather than ineffective and counter-productive check-the-box exercises.”

What does the proposed TPRM guidance say?

The proposed guidance is built around four components of third-party risk management. Here’s the short version of each.

  1. Risk Identification and Assessment. Maintain an inventory, identify the most relevant risks, and weigh both the likelihood and potential impact those risks could have on the institution or its customers or members.
  2. Risk Oversight. Tailor oversight activities based on risk. This is where the familiar lifecycle lives: due diligence and selection, contract negotiation, ongoing monitoring, and termination.
  3. Residual Risk Acceptance. Decide what level of remaining risk is acceptable. Some residual risk is unavoidable, mitigating it may cost more than it’s worth, or you simply may not be able to reduce it further.
  4. Governance. Put a supporting structure in place: clear roles and responsibilities, a defined risk appetite and tolerances, prioritization based on assessed risk, reporting to senior management and the Board, documentation, and periodic independent reviews.

Across all four components, one message comes through clearly: right-size the process. Here are a few quotes that really drive this idea home. 

  • Each third-party relationship is unique and should be managed accordingly.
    “Not all third-party relationships present the same level of risk, and a similar relationship at different banking organizations may present different risks. Accordingly, there is no one-size-fits-all approach to effective risk management.”
  • Regulators will take your “reasonable decisions” into account.
    “The agencies will give due consideration to a banking organization's reasonable decisions in matters of third-party risk management supervision.”
  • Spend your limited time on the risks that matter most.
    “Risk management practices that do not prioritize and tailor according to risk could increase the magnitude and likelihood of harm arising from higher-risk relationships due to inappropriate levels of attention and oversight.”
  • Lighter due diligence can be enough in the right circumstances.
    “Depending on the circumstances, this relatively less-detailed level of due diligence may be sufficient for the banking organization to determine that the third party is likely able to perform the services being contracted for (including, for example, that the third party has sufficient staffing and capabilities) and that further due diligence may not provide appreciable benefits to the banking organization.”
  • Monitoring should fit your needs and capabilities, too.
    “Banking organizations can tailor monitoring to their needs, abilities, risk determinations, and negotiating power, all of which can vary between larger or more complex banking organizations and community banks or among third-party relationships.”

In short, the proposed guidance takes a practical, risk-driven view of third-party risk management, and it says so throughout the guidance. 

What’s different between the current and proposed TPRM guidance?

Here are five key differences between the current and proposed third-party risk management guidance. 

1. The proposed guidance is streamlined.

Current: The current TPRM guidance is nearly twice as long as the new proposal.

Proposed: The proposal calls the 2023 guidance an “extensive list of considerations” and, as a result, removed nearly all of the illustrative examples.

What This Means: The proposed version gives financial institutions far more latitude to manage third-party relationships as they see fit, as long as those relationships are managed in a safe and sound manner and don’t present material risk to the institution.

2. The proposed guidance redefines third-party relationships.

Current: Defines a third-party relationship as “any business arrangement between a banking organization and another entity, by contract or otherwise. A third-party relationship may exist despite lack of a contract or renumeration.”

Proposed: Defines it as “a business arrangement between a banking organization and an entity or individual for the provision of one or more products, services, and other activities that support the banking organization.”

A footnote adds that “third-party relationships typically involve written agreements” and that where there’s no written agreement or clear consideration behind an activity, “that activity is unlikely to constitute a third-party relationship.”

Separately, the proposal also states that institutions “may decide not to maintain extensive inventories of relationships posing limited risk.”

What This Means: The agencies appear to be intentionally limiting the scope, from essentially any relationship to those tied to a specific product or service. For the purposes of defining what is a third party, they seem to be giving weight to whether a written agreement exists and are signaling that your vendor inventory itself can scale based on risk.

3. The proposed guidance reorients around risk management.

Current: Primarily organized around the Third-Party Relationship Life Cycle (Planning, Due Diligence and Selection, Contract Negotiation, Ongoing Monitoring, and Termination), bookended by a small section about Risk Management and a section about Governance.

Proposed: Organized around four components: Risk Identification and Assessment, Risk Oversight, Residual Risk Acceptance, and Governance. The lifecycle now lives in the second component (Risk Oversight).

What This Means: The lifecycle still matters, but it is no longer the center of emphasis. The 2023 guidance mentioned performing a risk assessment without saying much about what this looks like. The proposal puts Risk Identification and Assessment as the foundation of the whole approach and focuses the rest of the guidance on activities to oversee, accept, and govern the risks, as appropriate.

4. The proposed guidance offers a new take on subcontractors.

Current: Recommends evaluating the volume and types of subcontracted activities and how much the third party relies on them. It also suggests reviewing the third party’s own third-party risk management program and building in applicable contractual requirements.

Proposed: States that “the use of subcontractors alone does not typically create an independent third-party relationship or create a presumption of direct banking organization oversight of any subcontractors.” It then adds subcontractors should factor into your risk oversight, and that you are still responsible for operating safely and soundly, regardless of whether a third party uses subcontractors or not.

What This Means: It would be a stretch to say the proposal clarifies what to actually do about subcontractors. It does confirm that oversight should be based on the risk presented, but subcontractor identification and management remains one of the more challenging parts to navigate.

Learn More: The Vendor Manager’s Guide to Subcontractor Risk Management

5. The proposed guidance removes the contract negotiation clauses.

Current: Spends a lot of time discussing recommended contract language, with 17 lettered subsections covering everything from nature and scope, performance measures, and right to audit, to confidentiality and integrity, operational resilience, default and termination, and regulatory supervision.

Proposed: States plainly, “there are no generally applicable expected contract terms for third-party relationships” and that the presence or absence of any specific term an examiner might view as best practice “would not alone be a sufficient basis for an examiner to communicate an adverse finding.”

What This Means: Contracts still matter. But the proposal’s stance is that contract terms should be tailored to the risks a relationship presents, rather than drawn from a comprehensive list of provisions to include every time.

What can you do to prepare?

If this change would affect you, consider these three steps.

  1. Get familiar with the guidance. Reading this article is a good start, but reading the full proposal would be better.
  2. Consider commenting before November 16, 2026. The agencies want to hear from you. Is the guidance about right? Too much? Too little? As a practitioner, your perspective is valuable. If you’re not sure where to start, the proposal also asks several specific questions the agencies are hoping to have answered.
  3. Coordinate with your associations. Your bank or credit union associations are likely reviewing the proposal and may be planning to comment. Sharing your thoughts with them helps them advocate more effectively on your behalf.
  4. Review your vendor management program. Despite how the 2023 guidance has been interpreted and applied, its core ideas still ring true. Make sure your current third-party risk management activities are focused on the risk each relationship actually presents, not just compliance exercises.

How will Tandem be responding?

At Tandem, our goal is to help community financial institutions keep up with changes in regulations, guidance, and industry best practices. When new guidance comes out, we read it and make updates to the Tandem Software.

Tandem Vendor Management is our third-party risk management product. It helps you track your inventory, assess third-party risks, and manage those risks across the life cycle of each relationship.

If the guidance is adopted as proposed, several Tandem features are already built for exactly this kind of right-sized, risk-based approach. With Tandem, you can:

  • Choose whether to include your third parties in full or more limited oversight.

  • Answer significance questions to identify key risk factors and required due diligence types.

  • Perform a risk assessment to identify areas of heightened risk in the relationship.

  • Review contracts at an appropriate level with our standard or detailed review templates.

  • Set up notifications to review vendors on a frequency that fits the relationship.

  • Build custom documents to pull the right level of detail for governance and Board reporting.

See how Tandem can help you at Tandem.App/VM.

Frequently Asked Questions (FAQs)

Is the 2026 TPRM guidance currently in effect?
No, it is a proposal open for public comment, as of September 2026. The 2023 interagency guidance remains in effect unless and until the final version is issued.

When are comments due on the proposed TPRM guidance?
Comments are due November 16, 2026.

When will the final TPRM guidance be published?
No date is currently set. The comment period closes November 16, 2026, and the agencies would review comments before issuing any final version. How long that takes generally depends on the volume and complexity of comments and how much the agencies decide to revise.

Does the 2026 TPRM guidance apply to credit unions?
Yes, the NCUA is one of the four issuing agencies. If finalized, the guidance would apply to federally insured credit unions, alongside banks.

Would any current TPRM guidance remain in effect?
Yes, quite a few. The current proposal only names four items to rescind, so anything it doesn’t mention (the FFIEC IT Examination Handbook, the fintech due diligence guide, the NCUA’s TPRM guidance, etc.) would stay in effect, as written, unless separately rescinded. The agencies did ask for comment on whether anything else should be rescinded.

What makes a third-party relationship “higher risk?”
It comes down to two things: how much harm the relationship could cause if it were disrupted, breached, or attacked, and how likely that harm is. Relationships that could trigger a violation of law, cause material financial harm, or significantly disrupt operations or customers are the ones most institutions treat as “higher risk.”

Is a written contract required for a third-party relationship?
Not necessarily, but it is a strong indicator. The proposal notes third-party relationships typically involve written agreements. This is a shift from the 2023 guidance, which said a relationship could exist even without a contract.