THIRD PARTYCURRENT
Banking Supervision · Official proposed-guidance analysis

Bank agencies propose replacing third-party risk guidance

Four federal banking agencies requested comment on non-binding, principles-based third-party risk management guidance on September 11, 2026. The proposal would replace existing interagency guidance only if finalized, while a separate statement and Federal Reserve community-bank guide create distinct records that institutions should not collapse into one current requirement.

Third Party Current editorial graphic. Source material: Federal banking agencies proposed third-party risk management guidance; analysis and presentation by Third Party Current.

Keep the proposal separate from current guidance

The direct answer is that banking organizations should open a proposed-guidance change record, not overwrite their current control library. The joint release says the agencies requested comment on new third-party risk management guidance and characterizes it as non-binding and principles-based. It also says the agencies plan to rescind existing guidance when the proposal is finalized. Until that later action occurs, the proposal, the existing guidance, and any institution-specific obligations remain different authority states.

A defensible register should retain the four issuing agencies, September 11 release date, proposal status, affected bank and credit-union audience, official source, Federal Register publication status, comment-period rule, anticipated replacement action, and unresolved final text. The release says comments are due 60 days after Federal Register publication; it does not provide a calendar deadline on the page. Teams should calculate and record that deadline only from the published notice rather than infer it from the press-release date.

Separate three agency records

The release identifies three related but distinct records: proposed interagency guidance, a joint statement on community banks' engagement with core service providers, and a proposed Federal Reserve guide for Federal Reserve-supervised traditional community banks. They differ in issuer, status, intended audience, and operating purpose. A single project labeled “new TPRM rule” would obscure whether a requirement, supervisory consideration, or practical companion guide is actually being evaluated.

Route each record to the functions it may affect. Enterprise third-party governance may compare lifecycle language and risk tailoring; community-bank leaders may examine the core-provider statement; Federal Reserve-supervised traditional community banks may review the companion proposal. Legal, compliance, risk, procurement, technology, business, and board owners should record applicability independently. Neither inclusion in the release nor thematic overlap establishes that every record applies to every institution.

Map proposed principles to decisions, not feature labels

The agencies say the proposal is intended to align and tailor practices to risks of individual third-party relationships. That wording makes the relationship and its operating consequence the useful review object. Teams should map each proposed principle to a specific decision such as inventory scope, risk tier, diligence depth, contract condition, monitoring trigger, issue escalation, contingency action, or termination record. A platform feature called assessment, monitoring, or resilience is not evidence that the institution's proposed control outcome is configured or operating.

Preserve the legal third party, product or service, contract, business service, data access, integration, facility, geography, downstream dependency, accountable owner, risk basis, evidence, exception, and effective period. This also prevents an institution from assuming that one treatment fits every relationship with the same company. The proposal's principles-based framing does not remove the need for a reproducible decision record or establish what an examiner will conclude about a particular fact pattern.

Test transition logic before finalization

A useful readiness exercise should select one core service provider and one less critical third party, then trace the current guidance citation behind each inventory, tiering, diligence, contract, monitoring, and contingency control. Reviewers can map the proposed language without changing the live authority state, identify controls whose rationale may need revision, preserve comments submitted and agency responses, and define who may authorize a future transition after final text and effective status are verified.

The official release establishes the joint request for comment, the proposal's described approach, the planned replacement only upon finalization, and the existence of the two community-bank records. It does not establish final wording, a Federal Register publication date or fixed comment deadline on the page, applicability to one institution, examiner treatment, implementation timing, or conformity of any program or product. Those questions remain with the controlling record and accountable supervisory, legal, risk, procurement, technology, and business owners.

What we will watch next

Third Party Current will watch for later primary-source evidence that changes the maintained company, capability, or standards record. The next useful evidence may include implementation documentation, release details, regulator findings, corrected methods, product packaging, customer-observable workflow, or a subsequent company statement. Until then, the dated source and its stated boundary remain attached to this analysis.

Primary source: Federal banking agencies proposed third-party risk management guidance · Official joint federal banking-agency release.

Source boundary: Independent analysis of the Federal Reserve-hosted joint agency release dated September 11, 2026 and reviewed September 12, 2026. The Federal Reserve, FDIC, NCUA, and OCC did not review or sponsor this article. The linked proposal notices and statement were not treated as one instrument, and no institution, examination, third party, control, platform, comment, or outcome was assessed. This is not supervisory, banking, compliance, procurement, risk, or legal advice.

Editorial record: Published September 12, 2026; last reviewed September 12, 2026. Corrections policy.