Proposed Interagency TPRM Guidance 2026: What Changes for Banks
On September 11, 2026, four US regulators proposed to replace the 2023 Interagency Guidance on Third-Party Relationships. The OCC, the Federal Reserve, the FDIC, and the NCUA want banks and credit unions to spend less time on checklists. Instead, they want institutions to focus on the third-party relationships that can actually cause harm. Comments are due November 16, 2026.
For third-party risk teams, the message is clear: proportionality is no longer a nice-to-have. However, lighter oversight for low-risk vendors only works if you can show that those vendors are still low-risk. As a result, ongoing monitoring becomes the backbone of the new approach, not an afterthought.
In this blog, we break down what the proposal says, how it differs from the 2023 guidance, and what banks can do before the comment period closes.
Key takeaways
- What: Proposed guidance from the OCC, the Fed, the FDIC, and the NCUA that would replace the 2023 interagency TPRM guidance.
- Core shift: Risk assessment moves from “critical activities” to the magnitude and likelihood of harm in each relationship.
- Low-risk vendors: Lighter due diligence, public or alternative information, and less frequent monitoring.
- Outside help: Banks can use shared assessments and outside providers, but accountability stays with the bank.
- Timing: Comments are due November 16, 2026, and the 2023 guidance stays in place until the agencies finalize the new version.
What is the proposed interagency TPRM guidance?
The proposed interagency third-party risk management guidance is a draft supervisory framework from the OCC, the Federal Reserve Board, the FDIC and the NCUA. It would rescind and replace the 2023 Interagency Guidance on Third-Party Relationships. In short, it tells banks and credit unions how examiners expect them to manage risk from vendors, service providers, fintech partners, and other third parties.
Alongside the guidance, the Fed released a companion guide for community banks. In addition, the OCC, the Fed and the FDIC issued a joint statement on core service providers.
The proposal appeared in the Federal Register on September 15, 2026. Like all supervisory guidance, it is principles-based and non-binding.
Importantly, the proposal is part of a wider pattern. Throughout 2026, US banking agencies have refocused supervision on material financial risk. For example, they revised model risk management guidance in April with the same emphasis on tailoring. Then in June, they removed references to reputational risk from interagency documents. The new TPRM proposal follows the same direction.
Why the agencies want to replace the 2023 guidance
The agencies are unusually direct about what went wrong. In their view, banks applied the 2023 guidance too broadly, so TPRM programs became heavy on process and light on judgment. They point to four problems:
- De facto checklists: Detailed examples turned into checklists that banks applied to every vendor.
- “Should” everywhere: The wording did not signal that practices should scale with risk.
- A blunt risk lens: Labeling activities as critical or not gave too little nuance.
- A chilling effect on innovation: According to the agencies, the guidance implied “an impossible goal of risk elimination, rather than risk management.”
Not everyone agrees with the fix, though. Federal Reserve Governor Michael Barr dissented. He warned that the proposals could weaken safe and sound operations, increase risk and leave gaps in supervisory coverage. Meanwhile, Governor Lisa Cook supported the proposal as a principles-based fresh look that leaves room for innovation.
For risk teams, both views point to the same conclusion. More flexibility means more room for judgment, and judgment needs evidence behind it.
2023 guidance vs. 2026 proposal at a glance
The table below summarizes the main differences between the current guidance and the proposal.
| Area | 2023 guidance | 2026 proposalProposed |
|---|---|---|
| Issuing agencies | OCC, Federal Reserve, FDIC | OCC, Federal Reserve, FDIC, NCUA |
| Status | Final and in force | Proposed; comments due November 16, 2026 |
| Risk lens | Focus on “critical activities” | Magnitude and likelihood of harm per relationship |
| Lower-risk vendors | Tailoring allowed, but often applied as a checklist | Streamlined inventories, lighter due diligence, public or alternative information, standard contracts, less frequent monitoring |
| Due diligence gaps | Document gaps and apply alternative controls | Incomplete due diligence or a short operating history does not automatically rule out a relationship |
| Contracts | Detailed list of contract considerations | No generally expected contract terms, even for higher-risk relationships |
| Examiner posture | Assessment against the guidance | Due consideration for reasonable bank judgments; departures alone would not support supervisory action |
| Community banks | Separate community bank guide (2024) | New Fed companion guide for traditional community banks under $30 billion in assets |
Source: Proposed Third-Party Risk Management Guidance, Federal Register, September 15, 2026.
What the proposal means for ongoing monitoring
Ongoing monitoring stays central in the proposal. What changes is how much of it each relationship gets. Under the proposal, banks would tailor the frequency, scope, and depth of monitoring to the risk of each third party and to their own size and capabilities.
The proposal lists practical monitoring activities, including:
- Reviewing due diligence updates and performance data
- Holding periodic visits and meetings with the third party
- Testing the bank’s own controls over third-party risk
- Reviewing public filings or supervisory examination reports for certain large service providers
- Analyzing customer complaints
Higher-risk relationships may warrant more frequent monitoring and dedicated staff. Lower-risk relationships, on the other hand, may need far less.
The low-risk paradox
Here is the catch. A risk tier is a snapshot, but third parties keep changing. A vendor you classified as low-risk in January can face a data breach, a lawsuit, a sanctions designation, or financial distress by March.
So if your bank monitors low-risk vendors less often, it needs a way to notice when one of them stops being low-risk. Otherwise, the lighter touch that the proposal allows quietly turns into a blind spot.
That is why a supported risk assessment matters so much. Legal commentators already advise banks to base any change in vendor tiers on a documented view of harm, likelihood and available mitigants. In practice, that means you need current evidence, not last year’s questionnaire.
Where external risk intelligence fits
The proposal gives banks more freedom to tailor. In return, they need proof that their tailoring is reasonable. External risk intelligence helps in three ways.
Public and alternative information for lighter due diligence
The proposal explicitly allows banks to rely on public or alternative information for lower-risk relationships. It also accepts supplemental sources, such as public information and outside expertise, when a vendor cannot share every document. With Owlin Screening, banks can check any company with an online footprint against adverse media, sanctions, PEP, SOE, and watchlist data across geographies in one step.
Monitoring the signals the proposal names
Notably, the proposal names public filings and customer complaints as monitoring inputs. Owlin already tracks 8-K and 10-K filings, and CFPB complaints alongside adverse media and sanctions, PEPs, SOEs, watchlists, and blacklists. As a result, banks can cover these inputs continuously instead of collecting them by hand once a year.
Early warning when a low-risk vendor changes
Most importantly, continuous monitoring solves the low-risk paradox. Owlin Monitoring runs 24/7 across your full vendor portfolio. The Event Detection Agent flags new risk events, while the Risk Scoring Agent surfaces the companies whose risk is rising. That way, your team can move a vendor to a higher tier as soon as the evidence changes.
Figure 1. Event-driven monitoring keeps lighter oversight for low-risk vendors defensible.
Evidence examiners can follow
The proposal also warns that relying on an outside provider creates its own risks, and accountability stays with the bank. For that reason, explainability matters. Every Owlin score, event, and summary traces back to its source. This gives your team a time-stamped, auditable record to support risk decisions, independent reviews, and exams. In addition, Owlin’s API feeds these signals into the TPRM and GRC systems you already use, so a new risk event can trigger a workflow item automatically.
What community banks should know
The package also includes a Fed companion guide for traditional community banks with less than $30 billion in assets, plus a joint statement on core service providers. In the statement, the agencies note that a few core providers serve most community banks, which weakens those banks’ negotiating power. When supervising these providers, the agencies will weigh transparency, contract features and technology, including the number and severity of security incidents. For community banks, that makes incidents and outages at their core provider a monitoring priority.
What banks can do before November 16, 2026
The proposal has not replaced the 2023 guidance yet. Still, banks can prepare now so they are ready when the final version lands.
- Re-baseline your vendor tiers. Assess each relationship on the magnitude and likelihood of harm, and document why each vendor sits in its tier.
- Find where effort is misplaced. Look for uniform annual reviews or long questionnaires sent to low-risk vendors, and redirect that time to higher-risk relationships.
- Add a trigger layer under your low-risk tier. Pair lighter oversight with continuous external monitoring, so a new risk event prompts a review.
- Review your reliance on outside assessments. Check their scope, currency, assessor qualifications, and coverage gaps, and decide what extra work you still need.
- Strengthen your documentation. Examiners would give due consideration to reasonable judgments, and reasonable judgments need evidence. Record residual risks and why you accept them.
- Map your core provider (community banks). Assess your core provider against the transparency, contract, and technology factors in the joint statement.
- Consider submitting a comment. The agencies accept comments until November 16, 2026, through Regulations.gov and the Federal Register.
Putting it all together
The 2026 proposal gives banks more flexibility, but that flexibility comes with a burden of proof. If you monitor low-risk vendors less often, you need to know the moment one of them changes. And if an examiner asks why a vendor sits in a certain tier, you need evidence that is current, sourced, and easy to follow.
That is exactly where continuous external risk monitoring earns its place. Major financial institutions across the US and Europe already use Owlin to screen and monitor their third parties, with every signal traced back to its source.
Get ready for risk-based TPRM
See how Owlin helps your bank tailor third-party oversight with confidence and keep every decision backed by evidence. Book a demo or get a free risk report for a company you care about.
Frequently asked questions
What is the proposed interagency TPRM guidance?
It is draft supervisory guidance from the OCC, the Federal Reserve Board, the FDIC, and the NCUA, issued on September 11, 2026. It would replace the 2023 Interagency Guidance on Third-Party Relationships with a more tailored, risk-based approach to managing third parties.
Does the proposal replace the 2023 guidance right away?
No. The 2023 guidance stays in effect until the agencies finalize the new guidance. Banks should keep their current programs running while they prepare.
Is the proposed guidance legally binding?
No. Like all supervisory guidance, it is principles-based and non-binding. The agencies also state that departing from the guidance or its examples would not, on its own, support supervisory action.
Does “lower risk” mean no ongoing monitoring?
No. The proposal calls for monitoring that is proportionate to risk. Lower-risk relationships may need less frequent monitoring, but banks still need to know when a vendor’s risk changes.
Can banks rely on outside risk intelligence providers?
Yes. The proposal recognizes outside assessments, consortia and vendors as support for due diligence and ongoing monitoring. However, the bank stays accountable, and it should evaluate the risks of relying on any outside provider.
How does the US proposal differ from DORA?
DORA is a binding EU regulation that has applied to financial entities and their ICT third-party providers since January 2025. The US proposal, by contrast, is non-binding supervisory guidance that covers all types of third-party relationships. Banks that operate in both regions will need to meet both sets of expectations. Read more on our DORA page.
Sources
- Federal Reserve press release: Agencies seek comment on proposed third-party risk management guidance (September 11, 2026)
- FDIC FIL-58-2026: Proposed Interagency Third-Party Risk Management Guidance
- OCC Bulletin 2026-46: Third-Party Risk Management, Proposed Guidance and Request for Comment
- Federal Register: Proposed Third-Party Risk Management Guidance (September 15, 2026)
- Federal Register: Proposed Third-Party Risk Management Guide for Traditional Community Banking Organizations
- Skadden: US Federal Banking Agencies Propose Revised Third-Party Risk Management Guidance (September 17, 2026)
- OCC Bulletin 2026-13: Model Risk Management, Revised Guidance
- Consumer Finance Insights: Agencies remove reputation risk from guidance documents (June 5, 2026)