Fed and Bank Regulators Propose New Rules on Bank Vendor Risk
Four federal banking regulators want to rewrite the rulebook on how banks and credit unions manage their outside vendors, the kind of companies that run core computer systems, process payments, and power many of the apps people use to check their balances. On September 11, 2026, the Federal Deposit Insurance Corporation, the Federal Reserve Board, the National Credit Union Administration, and the Office of the Comptroller of the Currency jointly asked for public comment on proposed guidance covering these third-party relationships.
What the agencies are proposing
The proposed guidance is meant to help banks and credit unions manage risks tied to the outside companies they depend on. According to the agencies, it reflects supervisory experience and lessons learned from examining how financial institutions have handled third-party risk management in the past. The stated goal is to help banks and credit unions align and tailor their oversight practices to the actual risk level of each vendor relationship, rather than applying a one-size-fits-all approach.
The agencies describe the approach as principles-based, and they note that, like all supervisory guidance, it is non-binding. If finalized, the federal bank regulatory agencies plan to rescind their existing third-party risk management guidance and replace it with this new version, with the stated purpose of promoting consistency and what the release calls prudent innovation across the banking industry.
A separate guide for community banks
The Federal Reserve Board also separately requested comment on a proposed third-party risk management guide written specifically for Federal Reserve-supervised community banks. This document is intended to serve as a companion to the broader proposed guidance, giving smaller institutions a more tailored reference as they build or update their vendor oversight practices.
Community banks often rely heavily on a small number of outside “core service providers” that run the technology behind checking accounts, loan processing, and online banking. Because these banks typically have fewer in-house technology staff than large national banks, how they manage those vendor relationships can directly affect the reliability of everyday banking services for their customers.
A joint statement on core service providers
Separately from the proposed guidance, the agencies issued a joint statement on community banks’ engagement with core service providers. This statement lays out certain factors the agencies say they will weigh when making supervisory and enforcement decisions related to these core providers. It does not create new binding rules on its own, but it signals what examiners will be looking at when they assess how well a community bank understands and manages its dependence on outside technology vendors.
Why this matters for bank customers
Most people never see the vendor agreements behind their bank account, but those agreements affect things depositors notice directly: whether a mobile banking app works reliably, whether a bank can process transactions during an outage at a vendor, and how quickly a bank responds if a third-party technology problem disrupts customer access to funds. When a core service provider has an outage or security incident, customers of every bank that uses that vendor can be affected at the same time, which is part of why regulators are focused on how banks assess and monitor these relationships.
This proposal and statement do not change deposit insurance, interest rates, or fees. They are aimed at the supervisory relationship between regulators and the banks and credit unions they oversee. But because they touch on vendor reliability and oversight, they are relevant to anyone who banks with an institution, particularly a smaller community bank or credit union, that depends on a handful of outside technology providers to keep basic services running.
What readers can check now
The proposed guidance and the community bank guide are both open for public comment, with comments on the proposed guidance due 60 days after the notice is published in the Federal Register. Readers who want to see the full detail, including statements from Federal Reserve Governors Barr and Cook, can review the joint release directly.
- Ask your bank or credit union whether it has faced any recent service interruptions tied to a technology vendor.
- Check whether your institution publishes information about planned system maintenance or past outages.
- Review the Federal Reserve’s press release for links to the full proposed guidance and the joint statement on core service providers if you want to read the underlying documents yourself.
Anyone who wants a say in how this guidance is finalized can review the Federal Register notices and submit a comment before the 60-day window closes.
This is a News-lane report. It was drafted automatically from the linked primary source and published after automated checks that every figure appears in that source. It is summarised regulatory news, not evergreen guidance and not financial advice. See our AI content disclosure and disclaimer.
