On September 11, 2026, the OCC, Federal Reserve, FDIC, and NCUA proposed rescinding the vendor guidance every US bank has operated under since June 2023. Comments close November 16, 2026. Nothing is final, and the guidance would not be binding in any case: the OCC’s companion bulletin states plainly that non-compliance with the guidance will not result in supervisory action.

Read it anyway. If your company sells anything to banks, credit unions, or regulated enterprises, this proposal is the clearest signal in three years of what your customers’ security reviews will look like: who gets waved through, who gets the deep file, and which answers stop working.

What the agencies say went wrong

The document is the Proposed Third-Party Risk Management Guidance, Federal Register 91 FR 58536, published September 15. It would rescind and replace the June 2023 Interagency Guidance on Third-Party Relationships: Risk Management, the text that shaped every bank vendor questionnaire and annual review cycle since. The agencies’ diagnosis is unusually blunt for supervisory prose, and it reads like the list of complaints fintech vendors have been making since the day it landed.

The 2023 guidance, they write, has been “interpreted in an overly broad manner and with an insufficient focus on tailoring its risk management principles.” Its detailed examples “unintentionally incentivized overly-process-driven approaches,” so banks reported “applying heightened risk management practices to a wide range of third-party relationships without regard to the magnitude and likelihood of the risks actually posed by each relationship.” It was read as implying “an impossible goal of risk elimination, rather than risk management.” And it “has been read to discourage arrangements with newer and innovative third parties.”

The flip side shows up in the fix itself. The proposal encourages responsible innovation in part by “removing broad-based and overly prescriptive language from the 2023 Guidance that may unduly impede fintechs from entering partnerships with banking organizations.” In other words, the agencies are saying the paperwork was choking exactly the partnerships the banking system is supposed to be able to absorb.

This is not about your bank customer. It is about you, the person filling out the form.

The proposed replacement tells banks and examiners to focus on “material financial risks and violations of laws and regulations rather than ineffective and counter-productive check-the-box exercises.” That sentence is the whole story for vendors. The undifferentiated review, the one that treats a core ledger integration and a parking-gate vendor identically, is now the named-and-shamed pattern, straight from the regulators’ pen rather than a vendor’s complaint.

The four components

Section B is the part worth memorizing in full. In the agencies’ words, the guidance “presents four components that banking organizations may consider when managing third-party risk: (1) identifying and assessing applicable risks; (2) overseeing risks proportionate to their significance; (3) making informed decisions about residual risks and risk acceptance; and (4) establishing appropriate governance practices.”

Unpacked:

  1. Identify and assess risks by magnitude and likelihood. The assessment question changes from “does the vendor have a policy?” to “what is the worst realistic event here, and how likely is it?”
  2. Oversee risks proportionate to their significance. Depth and frequency of oversight scale with what the relationship actually touches.
  3. Make informed residual-risk decisions. The bank accepts some risk on purpose, understands what remains after mitigation, and can explain the acceptance.
  4. Establish appropriate governance. Structure follows the bank’s size, complexity, and risk profile. The agencies add that “there is no one right way” to structure these practices.

Notice the “may consider.” This is a proposal, open for comment until November 16, 2026, and even final it stays principles-based guidance, not a rule. The 2023 guidance remains in effect until the agencies finalize a replacement. But the direction is unmistakable, and bank TPRM teams do not typically wait for final print to begin reorganizing.

What it says about contracts, certifications, and your SOC 2

The most operationally interesting language in the proposal is about contracts. The text is direct about it: “There are no generally applicable expected contract terms for third-party relationships,” even for higher-risk ones. A contractual term an examiner personally dislikes would not, by itself, support an adverse finding. And a bank with weak negotiating power “may be unable to negotiate all of its desired contractual provisions” and can still proceed, as long as it understands the residual risk and that risk sits within its appetite.

Then the sentence that belongs above every vendor-review desk:

“The agencies do not expect banking organizations to eliminate third-party risk.”

Some residual risk is unavoidable, the text says. Managing a mitigated risk well can beat designing a vendor out of existence.

On certifications and shared diligence, the proposal formally blesses what many practitioners already do: participating in a co-venture or consortium on due diligence, using standard-setting and certification organizations, and relying on assessments performed by auditors, consultants, or law firms. The caution is one clause long. Certifications and assessment results are “adequate for a banking organization’s due diligence needs, depending on facts and circumstances.” Skadden’s client alert translates the practical point: a certification does not itself transfer the bank’s accountability or establish a safe harbor.

For vendors, that cuts both ways. Your SOC 2 still matters, probably more than before: it becomes the evidence behind a proportionate judgment rather than a stamp that ends a conversation. What stops working is the assumption that a clean report, any clean report, answers whatever the bank was actually worried about.

If you sell into banks and credit unions

Expect re-tiering to start before this is final. Banks that take the proposal seriously will sort vendor inventories by magnitude and likelihood, and your file lands somewhere in that sort.

At the low end, files get slimmer. The proposal’s own examples of administratively simple relationships: operators of call centers or recordkeeping services, auditors, lawyers, consultants, physical security providers. If your product touches a bank in one narrow way, your next review is a short, well-written file, not a two-week questionnaire cycle. Keep the short answers pre-written, because banks will need them quickly and cheaply.

At the high end, questions get harder, not softer. Proportionate reviews concentrate on the questions that map to real risk: what breaks if you are down, where your data sits, who your subprocessors are, how you recover, how quickly your customer learns about an incident. The preparation that shortens these conversations is evidence mapping. Write the magnitude answer in plain prose, then point to the artifact: the SOC 2 report, the disaster-recovery test results, the penetration-test summary, the subprocessor list, the incident-history disclosure. A bank reviewing a tier-one relationship wants the evidence next to the claim, not instead of it.

Transparency stops being a cost center. The companion statement on core providers, covered below, tells banks that supervisors will weigh provider transparency, contract features, and technology when deciding how much scrutiny the bank itself deserves. Read from the vendor chair: your willingness to disclose subcontractors and recovery posture is becoming part of your customer’s supervisory story, and stonewalling now has a supervisory footprint. We have written before about how a single vendor question can stall a deal; that dynamic gets sharper as banks tie diligence depth to examination posture.

This does not mean rolling over: answer everything relevant with evidence, and push back on genuinely irrelevant questions with substance rather than silence. “Here is the evidence that answers the risk question behind your item 47, and here is why the request as written does not map to one,” beats both the blanket refusal and the 40-tab spreadsheet.

One context note, because fintech readers will look for it: nothing in this proposal mentions AI. None of the regulatory claims above touch it. The overlap is situational: many fintech AI vendors sit exactly where the agencies say friction was misplaced, in the “newer and innovative third parties” bucket that the 2023 guidance discouraged banks from touching quickly. If that is your position, the same evidence discipline applies. The global counterpart of this discussion, where supervisors worry about shared dependencies rather than paperwork volume, is the FSB’s frontier-AI third-party warning, and the vendor-side logic there converges with this proposal from the other direction.

If you buy, or depend

The second audience is TPRM managers inside mid-market banks, plus fintech executives whose own vendor stacks lean on the same bank-era providers everyone else uses. For you, the rewrite is permission to right-size.

Segment the inventory. The FR text gives the low-complexity categories in plain sight. Streamlined vendor inventories for limited-risk relationships are one of the tailoring devices Skadden highlights, and lower-risk relationships can warrant less detailed diligence and less frequent monitoring. A register that treats the auditors and the core processor with the same annual review ritual is what the agencies described as process without proportionality.

Retire the uniform annual review where risk does not justify it. Skadden’s alert poses the question institutions should be asking: whether “uniform annual reviews or extensive questionnaires across most vendors” direct resources to the most significant exposures. Note the framing carefully: that is a practitioner pattern regulators now invite banks to re-examine, not a measured statistic about the market. Do not quote it as one.

Document the risk you accept. The third component, informed residual-risk decisions, sounds soft until you see what it produces: an acceptance memo naming the risk, its magnitude and likelihood, the mitigants applied, who signed, and when it gets re-reviewed. Skadden’s advice is that explanations for risk acceptance should be strengthened. In practice, the signature and review date are the two fields most programs skip, and the first two an examiner asks for. The memo is what distinguishes “we made an informed decision” from “nobody looked.”

Two cautions keep this honest. Certifications do not transfer accountability; the bank reviewing your vendors still owns the outcome. And the bank’s own duty survives untouched: “A banking organization’s use of third parties does not diminish its responsibility to meet these requirements to the same extent as if the activities were performed by the banking organization internally.” Right-sizing reallocates attention. It does not shrink accountability.

The two companion documents, and why vendors should read both

Three documents shipped the same day, and they are easy to blur into one. They are not the same instrument.

First, the interagency proposal itself, from all four agencies, covering banks, credit unions, and their third parties. That is the document this article mostly discusses.

Second, a Federal Reserve-only companion, the Proposed Third-Party Risk Management Guide for Traditional Community Banking Organizations, also published September 15 in the Federal Register. It covers banking organizations with less than $30 billion in assets that focus on serving their local communities, and it explicitly excludes institutions with more complex third-party profiles. It is a companion proposal, not part of the interagency document.

Third, a Joint Statement on Community Banks’ Engagement with Core Service Providers from the OCC, FDIC, and FRB. Not a proposal. A statement of the factors the agencies expect to weigh when they decide how much supervisory attention to point at core providers and the banks that depend on them. The premise: core providers are community banks’ most material relationships, the market is concentrated, and banks often have limited leverage. The warning: providers that “unreasonably limit [community banks’] ability to conduct due diligence and ongoing monitoring or to negotiate contract terms” create greater risks for their bank customers and attract correspondingly more supervisory attention. The factors named for deciding how closely to look: transparency, contract features, and technology.

Why should a fintech vendor read a community-bank core-provider statement? Because it is the clearest statement on record of how providers’ conduct feeds their customers’ supervisory posture, and that logic does not stop at community banks. If your customer’s examiner starts weighing what your customer can see about you, your transparency choices have become your customer’s regulatory environment. Vendors who make diligence easy are choosing the cheaper supervisory path for their own customers. That is a sales argument, not a compliance one, and it is now written down by three agencies.

What does not change

The accountability sentence stands. A bank remains responsible for vendor-driven activity as if it were performed in-house, and nothing proposed weakens that.

The proposal is not final. The comment window closes November 16, 2026, the 2023 guidance governs until a replacement is finalized, and the agencies have published no timeline beyond that window. Even after finalization, this is guidance: no supervisory action for non-compliance, per the OCC bulletin, though the usual carve-outs remain, and the FR text is explicit that the agencies may still act on violations of law, unsafe or unsound practices, or material risks from insufficient third-party risk management. The direction of encouragement changes. The obligation to run a sound program does not.

What to do this quarter

If you sell into banks and credit unions:

  1. Pull your last three bank security reviews. Sort every question into three buckets: a real risk question, generic boilerplate, and everything else. This takes an afternoon and shows you where your evidence file is thin before it costs you a deal.
  2. Build the evidence map for your bank-critical relationships: one paragraph answering the magnitude and likelihood question directly, then pointers to the artifacts (SOC 2, DR test results, pen-test summary, subprocessor list, incident history). This is the spine of the proportionate file your customers’ rebuilt programs will ask for.
  3. Close the two transparency gaps customers are most likely to notice first: subprocessor change notice and incident notification timelines.
  4. Pre-write the short file for low-risk categories so a minor questionnaire never eats an engineering week again.

If you run TPRM inside a mid-market bank:

  1. Segment the vendor inventory against the FR text’s own categories, and pilot streamlined treatment on one limited-risk tier this quarter rather than waiting for a final rule.
  2. Draft the residual-risk acceptance memo format before you need it, with the signature and review-date fields everyone forgets.
  3. If you depend on core providers, read the joint statement from the provider side. Your ability to see into your core provider, benchmark its contract, and exit it on reasonable terms is now part of your own supervisory picture.

The agencies wrote the quiet part down: banks are not expected to eliminate third-party risk, and there is no one right way to run the program. What replaces the paperwork is evidence, proportionate to the relationship. Building that evidence file, and the judgment behind it, is most of what a fractional CISO does for a fintech selling into banks. If you want a second pair of eyes on your vendor evidence pack before the next bank review lands, or help right-sizing a program on either side of the table, start with the fintech security practice, or the broader fractional CISO engagement. For a direct ask, the contact page is the fastest route.