On September 11 the OCC, Fed, FDIC and NCUA proposed replacement guidance for third-party risk management. The Federal Register version went up September 15 and comments close November 16. Nothing is final. The 2023 guidance is still the one your examiner is carrying. But if you have spent the last three years building a program to the 2023 text, read the preamble of this one, because it is the agencies describing your program back to you and saying they did not mean for it to turn out that way.
What they said
We have read a lot of regulatory preambles. This one is blunt. The agencies say the 2023 guidance "frequently has been interpreted in an overly broad manner," and then they explain how that happened. It tried to cover core processors, fintech partners and the HVAC contractor in one document, so banks could not tell which parts applied to whom. The "critical activities" idea made banks scale oversight to what the vendor did instead of to how much damage the relationship could do and how likely that was. Every "should" in the examples got read as a rule. And banks told the agencies they were sticking with vendors that had breached contracts or were charging above market because they thought the goal was zero risk.
If you work in this field, none of that is news. What is new is a regulator writing it down.
What replaces it
The five-stage lifecycle is gone as the skeleton. Planning, due diligence, contracting, monitoring and termination still exist, but they now sit under four components, and the first one does most of the work.
Risk identification and assessment comes first and everything else keys off it. Risk is magnitude of harm times likelihood of harm, per relationship. You can assess the whole relationship or each activity, your call. You do not have to inventory your auditors, your outside counsel or the security guard company if you have decided they are low risk. That one sentence will delete a few thousand rows from some inventories we have seen.
Risk oversight is where diligence, contracts, monitoring and termination now live, with depth set by the assessment. For low-risk vendors, the proposal says less detailed diligence, or public and "alternative" sources, may be enough. And then there is a paragraph we read several times to make sure we were not imagining it: banks may rely on "third-party technologies or processes to supplement or assist" their own oversight, and community banks in particular may benefit from "advanced technology and industry expertise otherwise unavailable." We have not seen prior guidance say that this plainly. If you have, tell us.
Residual risk acceptance gets its own heading. The agencies say they do not expect risk elimination, that some residual risk is unavoidable, and that deciding what to accept is part of the job. Anyone who has tried to close a vendor review without a place to write "we looked, we accept it" will know why this matters.
Governance is roles, appetite, reporting, documentation, independent review. Same as before, with more "no one right way" language.
The footnotes
The practical changes hide in the footnotes.
Footnote 12: a vendor with API or network access to systems that are segmented and do not hold critical data is "not necessarily higher risk," and you can handle it through your cyber program instead of TPRM.
Subcontractors: using them "alone does not typically create an independent third-party relationship or create a presumption of direct banking organization oversight." Fourth-party risk runs through your vendor's contract and your vendor's own program. Most fourth-party sections in the policies we see would need rewriting.
Footnotes 9 and 15 are questions rather than statements. Should the guidance only apply to vendors with a written agreement? Should the agencies publish a list of what makes a relationship high risk? They want comments on both. We had opinions, and we filed them. More on that below.
The whole thing is non-binding, which it says about every other page. Deviating from it "will not alone be a basis for supervisory action." The agencies will give "due consideration" to a bank's reasonable decisions. We counted: that phrase appears five times.
The core provider statement
Released the same day, and if you run a community bank or credit union it may be the more useful of the two documents. The Fed, FDIC and OCC list the core provider behaviors they will now weigh when deciding how hard to examine a core: not sharing SOC reports and pen test results, contract terms that stop you from comparing offerings, opaque pricing, back-billing windows, deconversion fees that are not defined anywhere, limits on third-party integrations. They also say a core may be an "institution-affiliated party" and liable directly. That is a regulator handing you a negotiation checklist for your next renewal. Read it here.
There is also a Fed companion guide for Fed-supervised community banks, built around four risk areas and eight vendor categories. Worth a read if that is you.
So what
Brian Shaw on our team has been calling this "less bad TPRM," and that is the right summary. You can only do less for your low-risk vendors if you know which ones those are, and that knowledge does not come from a default tier. It comes from having looked. The proposal moves the hard part of the job from collecting documents to deciding things and writing down why. If your program runs on questionnaire volume, that is going to feel like more work. If it runs on evidence and judgment, this guidance describes what you already do.
We filed our comment letter with the OCC on September 24 and copied the Fed, FDIC and NCUA. The summary is in What we told the OCC, and the full seven-page letter is here as a PDF.
