We filed a comment letter on the proposed interagency TPRM guidance on September 24. It is seven pages and you can read the whole thing here (PDF). This is the summary, with a bit of why we said what we said.
Why bother
Vendors do not usually comment on bank guidance. We did because we watch this guidance get applied across a lot of institutions, from community banks with a few hundred vendors to national banks with tens of thousands, and that is a view the agencies do not otherwise get. Also, honestly, because the 2023 guidance created a good share of the work our customers hired us to get through, and we would rather build for a world where that work is proportionate to the risk.
We filed with the OCC under Docket ID OCC-2026-0793 and copied the Fed, FDIC and NCUA, since all four agencies are behind the proposal.
The short version
We support the proposal. The agencies' account of what went wrong with the 2023 guidance is accurate and, if anything, polite. At many programs we work with, a marketing agency and a core processor get the same 200-question form, the same annual review and roughly the same staff time. Nobody thinks that is sensible. They do it because nobody has told them they can stop.
We also spent a paragraph on how we expect the proposal to be misread. It tells banks to stop doing the parts of TPRM that never managed any risk. That is different from doing less of it, and we think the difference will get lost. You can only skip work on a low-risk vendor if you know it is low risk, which takes an actual assessment. The proposal asks more of a program's judgment and less of its filing cabinet.
The three questions
The agencies asked three direct questions in the footnotes. Our answers:
Should there be a list of high-risk characteristics?
We went back and forth on this one internally. A list is precisely how the 2023 guidance became a checklist. But without one, every bank writes its own, and the homemade ones we have seen are longer, sorted by vendor type instead of by harm, and never revisited. So yes, with a warning label. We proposed seven characteristics (customer data access, operational dependence, no real alternative, customer-facing discretion, concentration, reliance on subcontractors, track record) and asked that the list be framed as things to weigh against mitigants rather than a scoring sheet. We also asked that nothing on it refer to the type of company. "Fintech" is not a risk characteristic. Neither is "uses AI."
Should it only apply to relationships with a written agreement?
Yes. It gives the inventory a defensible boundary, and everything else in the proposal sits on the inventory. But "written agreement" has to include click-through terms and order forms nobody negotiated, or a large share of the SaaS and data vendors that actually matter fall out. We also asked for the reverse to be stated: a signed agreement with a low-risk vendor does not by itself create an expectation of oversight beyond what the assessment supports.
Should other guidance be rescinded?
We said leave it alone and instead publish one page listing which prior bulletins and statements are still in force. The inconsistency we see in exams comes from the twenty-year stack, not from any single document in it.
The section we cared about most
The proposal says banks can lean on public sources, consortia, outside experts and "third-party technologies or processes," and that community banks in particular stand to benefit. We think that is the most useful paragraph in the document for smaller institutions, and also the one most likely to get quietly ignored in an exam. So we asked for four additions.
Say that software-assisted analysis counts. If a tool reads a SOC 2 report, pulls the exceptions and maps them to your control expectations, the resulting conclusion should be as good as one a person reached reading the same report, as long as you understand the method, keep the evidence and own the result. Some examiners today treat tool-assisted review as weaker by definition. If the final text is silent, they will keep doing that.
Say that using a risk tool does not mean the tool's vendor has to be overseen like your core. Without that sentence there is a loop in the logic, and cautious compliance officers resolve loops by not adopting the tool.
Put a short governance expectation in writing: you can trace a conclusion back to its evidence and forward to the action taken, and a named person owns each consequential decision. That gives banks a target and examiners a consistent question.
Make the sequence explicit. Understand the relationship and look at what evidence already exists before you send anything to the vendor. Then ask only for what is missing. If what you already have supports a defensible conclusion, another questionnaire adds cost and nothing else.
Everything else
Quickly, since the letter goes through these in more detail:
Say the risk assessment is iterative. Plenty of institutions treat the initial rating as permanent.
Say that watching for events (a breach, an ownership change, a lapsed cert) can replace an annual reassessment when nothing has changed. Risk does not move because a calendar date arrived.
Keep the subcontractor language exactly as drafted.
Treat a documented residual risk acceptance as evidence of a working program. Today it often gets written up as a gap. And expect every material finding to end somewhere: remediation, tighter monitoring, escalation or acceptance.
Ship examiner procedures and training with the final text. "Due consideration" is only worth what happens in the exam room.
On the core provider statement, two asks. Recognize that when a core will not share information and the bank has no realistic way to leave, a documented acceptance of that residual risk is a reasonable decision. And push cores to publish SOC reports, pen test results and standard assessments through standard, machine-readable channels, because that is what would let the technology the proposal endorses work on the relationships that matter most.
What now
Comments close November 16. The 2023 guidance stays in effect until something final is published, probably some months after that. We will update this post when it happens. If you are working on your own comment and want to compare notes, or want to talk through what the proposal would mean for your program, get in touch.
