On September 11, 2026, the Office of the Comptroller of the Currency, the Federal Reserve Board, the Federal Deposit Insurance Corporation, and the National Credit Union Administration jointly requested comment on proposed guidance for managing risks tied to third-party relationships. The action matters because it would revise and replace existing guidance, signaling a coordinated effort across federal banking regulators to update supervisory expectations as financial institutions increasingly rely on outside vendors, core service providers, and other third parties. The proposal is explicitly designed to help banking organizations better align and tailor their risk management practices to the reasonably assessed risk levels of each relationship, rather than applying a uniform standard to all arrangements.
The proposed guidance draws on the agencies' supervisory experience and lessons learned through examinations of banking organizations' third-party risk management practices. It would apply to community banks when finalized, according to the OCC bulletin, and the agencies issued a related statement on community bank engagement with core service providers. Comments are due 60 days from publication of the proposed guidance in the Federal Register. The bulletin identifies a contact for questions: Graham Bannon, Counsel in the OCC Chief Counsel's Office, at (202) 649-5490. The document was issued under the signature of Adam J. Cohen, Senior Deputy Comptroller and Chief Counsel.
The source is a primary regulatory bulletin published by the OCC on its official website, dated September 11, 2026, and labeled OCC Bulletin 2026-46. It is addressed to chief executive officers of all national banks, federal savings associations, and federal branches and agencies, as well as department and division heads, examining personnel, and other interested parties. The bulletin notes that the term "banking organizations" includes OCC-supervised banks, and that "banks" refers collectively to national banks, federal savings associations, and federal branches and agencies of foreign banking organizations. The dossier contains no additional corroborating sources, so the analysis is bounded by this single primary document.
For market participants, the proposal carries implications for compliance burdens and vendor oversight expectations across the banking sector. Because the guidance would apply to community banks when final, smaller institutions may need to review their third-party risk management frameworks even if they have fewer resources than larger banks. The emphasis on tailoring practices to the risk level of each relationship suggests regulators are seeking to avoid a one-size-fits-all approach, potentially reducing unnecessary compliance costs for lower-risk arrangements while maintaining scrutiny on critical service providers. The accompanying statement on community bank engagement with core service providers indicates particular regulatory attention to dependencies on essential technology vendors.
The available evidence leaves several questions open. The bulletin does not include the full text of the proposed guidance, the specific definitions of risk levels, or detailed examples of what tailored practices would look like in practice. It also does not state whether the proposal would impose new reporting requirements or how it would interact with existing interagency guidance. The 60-day comment window begins upon Federal Register publication, but the bulletin does not specify that publication date. Market observers should watch for the Federal Register version, the full proposed guidance text, and any agency statements clarifying how the final rule would affect community banks and core service provider relationships.