What the New Interagency TPRM Proposal Means for Your Vendor Program

By Christopher Salone, on October 7th, 2026

On September 11, 2026, the NCUA, FDIC, Federal Reserve, and OCC jointly proposed new third-party risk management guidance, and it would rescind and replace the 2023 Interagency Guidance on Third-Party Relationships, along with its supplemental resources (the 2024 community bank TPRM guide, the 2024 joint statement on bank deposit product arrangements, and the OCC’s 2002 foreign-based service provider bulletin). It was published in the Federal Register on September 15, and comments are due November 16, 2026.

In their own words, the 2023 guidance was being read too broadly and with too little focus on tailoring. Its long lists of considerations and examples were hard to apply across different kinds of relationships, and it unintentionally pushed institutions toward process-driven, check-the-box programs instead of risk-focused ones. The agencies also said it was being read as discouraging relationships with newer, more innovative third parties.

What New Interagency TPRM Proposal Aims to Accomplish

It’s principles-based and organized around four components: risk identification and assessment; risk oversight (due diligence and selection, contract negotiation, ongoing monitoring, termination, and cross-cutting topics); residual risk acceptance; and governance. The central theme is proportionality: align the depth of your oversight with the reasonably assessed risk of each individual relationship, tailored to your institution’s size, complexity, and risk profile.

The bulletin states plainly that the guidance will not set enforceable standards or prescriptive requirements, and that non-compliance won’t result in supervisory action. That said, don’t mistake non-binding for unimportant, examiners still evaluate third-party risk under existing regulation (Part 748 and GLBA for credit unions, Part 500 for NY-regulated institutions), and this guidance shapes how they think about adequacy.

What This Means for Your Exams

The practical shift is from “did you complete the review?” to “why is this level of oversight proportionate to this vendor?” If you’ve been running every vendor through the same diligence packet, this is your opening to right-size, but only if the rationale is written down. Under a tailored model, the documented reasoning behind your risk tiering becomes the artifact examiners test. A thin or undocumented justification for treating a vendor as low-risk is a much bigger exposure than it was under a one-size-fits-all program.

This matters because third-party risk is already the most commonly cited IT issue. Recent exams have hit institutions for vendor management policies that don’t address cloud providers or fourth-party/subcontractor exposure, and for incomplete annual due diligence on high-risk and GLBA-rated vendors.

What Institutions Should Do Now

  • Read your vendor policy against the four components. If it still reads like it was written around a core processor contract, with no cloud provider categories, no subcontractor language, it needs work regardless of what the final guidance says.
  • Document the why behind every risk tier. Inherent risk rating, residual risk after controls, and a written conclusion on each review.
  • Map your fourth parties for critical vendors. Concentration and subcontractor exposure remain examiner favorites.
  • Formalize residual risk acceptance. The proposal calls it out as its own component; make sure someone with authority is signing off, and that it reaches the board.
  • Don’t rewrite everything yet. This is a proposal, not final guidance. Fix the gaps you already know you have and hold structural rewrites until the final version lands.

If you have any questions, we are here to help. Please do not hesitate to reach out to discuss your specific situation.

This material has been prepared for general, informational purposes only and is not intended to provide, and should not be relied on for, tax, legal or accounting advice. Should you require any such advice, please contact us directly. The information contained herein does not create, and your review or use of the information does not constitute, an accountant-client relationship.

Share on LinkedIn
Share on Facebook
Share on X

Written By

Related Industries

Insights

Related Articles