
Four U.S. financial regulators have proposed new third-party risk guidelines that would let banks and credit unions tailor oversight to each outside relationship while replacing existing guidance.
Summary
- Four federal regulators have opened the proposed guidelines to public comment.
- The nonbinding framework would replace third-party risk guidance issued in 2023 and 2024.
- Community banks with less than $30 billion in assets would receive a separate practical guide.
- Federal Reserve Governor Michael Barr dissented, warning of supervisory gaps and added financial risk.
Proposed bank guidelines favor risk-based oversight
The Federal Reserve, Federal Deposit Insurance Corporation, National Credit Union Administration, and Office of the Comptroller of the Currency announced the proposal on Sep. 11, saying financial institutions should match their controls to the risks posed by each third-party relationship.
Under the proposal, banks and credit unions would consider both the possible harm from an outside provider and the likelihood of the harm occurring. Institutions could use less detailed checks, standard contracts, or less frequent monitoring when a relationship carries limited risk.
The framework would also let a financial institution accept some residual risk after considering its risk appetite, tolerance, and ability to operate safely. According to the agencies, the principles would not impose enforceable requirements, and a bank would not face supervisory action solely for failing to follow the guidance.
Comments will remain open for 60 days after the proposal appears in the Federal Register. Once finalized, the agencies plan to withdraw the current third-party risk framework and replace it with the revised version.
Federal Reserve staff said existing guidance has sometimes been applied too broadly, encouraged process-heavy reviews, and failed to give enough weight to differences among vendors. Staff also said banks have read the current framework as discouraging work with newer service providers.
As technology has become more central to banking, institutions have outsourced more functions to vendors that can lower costs or improve efficiency. Outside providers may handle payment processing, cybersecurity, online banking, fraud detection, card programs, and anti-money laundering systems, leaving banks responsible for risks tied to services they do not operate themselves.
Community banks would receive a separate guide
Alongside the main proposal, the Federal Reserve has requested comments on a companion guide for traditional community banking organizations under its supervision. The central bank defines eligible institutions as locally focused banks with less than $30 billion in assets.
The proposed guide covers four main areas: operational resilience, information security, legal compliance, and financial resilience. It also explains how banks could assess eight common vendor groups, including core service providers, payment processors, digital banking companies, cybersecurity firms, and financial-crime platforms.
For each category, the document sets out issues that smaller banks may consider during due diligence, contract negotiations, monitoring, and a possible move to another provider. Federal Reserve staff said smaller institutions had asked for more practical information than the high-level principles in the existing framework provided.
Complex bank-fintech arrangements would not fall under the community bank guide. The Federal Reserve memo identifies such arrangements as cases in which one or more fintech companies market, distribute, or provide access to a bank’s products.
A separate statement on core providers addresses vendors that supply systems needed for transaction processing, account management, payments, compliance, customer relations, and online banking. The Fed, FDIC, and OCC said a small number of large companies control much of this market, limiting the negotiating power of community banks.
According to the statement, banks have reported difficulty obtaining due diligence records, negotiating suitable contract terms, and monitoring vendors. Regulators said they may consider a provider’s transparency, contract practices and technology investment when deciding the scope and frequency of examinations.
The agencies may also examine whether providers disclose security incidents on time, supply audit and security records, maintain aging technology, and allow clients to connect services from other companies. Opaque pricing, retroactive billing, and undefined fees for leaving a platform may also influence supervisory decisions.
Barr warns the proposal could leave oversight gaps
Federal Reserve Governor Michael Barr opposed the two proposals, arguing that their wording could weaken oversight rather than help institutions manage vendor risks.
Barr objected to a proposed “material financial risk” standard for supervisory action. According to his dissenting statement, the threshold could make banks less likely to correct problems before they become material to the institution.
The governor also questioned language saying regulators would give due consideration to a bank’s reasonable decisions. Barr said institutions could interpret the passage as requiring supervisors to defer to a bank’s judgment instead of making an independent assessment.
Consumer compliance presents another concern, according to Barr. He said the proposals could result in existing guidance being removed without a clear replacement for consumer-protection issues, or force banks to follow two sets of standards.
Barr also noted that the community bank guide excludes institutions with complex business models and vendor relationships, including some bank-fintech partnerships. In his view, banks using such structures may have an especially strong need for detailed third-party risk instructions.
“I dissent,” Barr said.
Federal Reserve Governor Lisa Cook supported reviewing the current framework but requested feedback on whether the final version should say more about cybersecurity, record management, consumer protection and the division of anti-money laundering duties in bank-fintech partnerships.
Cook also backed the separate guide for traditional community banks, describing it as a resource for institutions dealing with complex and critical vendor relationships. She asked community banks to comment on any extra resources they may need when evaluating technology companies and core providers.
Crypto service providers could fall within bank reviews
Although the proposal does not create rules written only for digital assets, its scope can cover technology companies that provide crypto custody, stablecoin, payment, or blockchain services to regulated banks. The agencies’ framework requires institutions to evaluate third parties according to the service and risk involved, regardless of the technology used.
The proposal follows earlier U.S. regulatory action that gave banks more room to conduct permitted digital-asset business. In April 2025, crypto.news reported that the Federal Reserve had removed prior-notification expectations for certain crypto and dollar-token activities.
Federal regulators later issued a July 2025 statement explaining how existing risk-management principles apply when banks safeguard crypto assets. The OCC’s related bulletin said banks should assess outside service providers before offering custody, while noting that the statement created no new supervisory expectations.
The new all-bank proposal permits institutions to use shared due diligence through consortia, standard contracts, certification bodies, and outside consultants. Federal Reserve staff presented such methods as possible ways for banks to gain expertise or reduce repeated work when evaluating service providers.
Consumer compliance issues are not directly covered by the proposed framework, according to the Fed memo, though third-party relationships may still create duties under existing consumer laws. The traditional community bank guide likewise states that consumer compliance falls outside its scope.

Leave feedback about this