BANKING OPERATIONS & FINTECH · SEPTEMBER 12, 2026

Bank Regulators Propose a New Third-Party Risk Framework

Four federal financial regulators proposed principles-based, nonbinding guidance for banks and credit unions to manage third-party relationships and separately addressed community-bank engagement with core service providers.

Community banker and technology operations lead reviewing secure third-party systems
PFCS INSIGHTSBank Regulators Propose a New Third-Party Risk Framework

What the September 11 announcement says

Source publication date: September 11, 2026. The National Credit Union Administration, Federal Deposit Insurance Corporation, Federal Reserve Board, and Office of the Comptroller of the Currency requested comment on proposed guidance for managing risks in financial institutions' third-party relationships. The proposal is principles-based and nonbinding. Comments are due 60 days after publication in the Federal Register.

PFCS VISUAL BRIEFThird-party risk proposal
4 agenciesjoint regulatory proposal
  1. 01Principles-based and nonbinding
  2. 02Comments due after Federal Register publication
  3. 03Borrowers should protect process continuity
Educational visual · Transaction terms and lender requirements vary.

The proposal aims to align supervision

The agencies said the proposed framework reflects supervisory experience and is intended to help banks and credit unions tailor risk management to the risk of each third-party relationship. If finalized, the federal banking agencies plan to rescind existing third-party-risk guidance and replace it with the new guidance. The regulators also issued a statement describing factors relevant to community banks' engagement with core service providers, and the Federal Reserve separately proposed a companion guide for supervised community banks.

Why this can matter to borrowers and investors

Financial institutions rely on providers for core processing, document delivery, data, identity checks, payments, servicing, cloud technology, and other functions. Vendor review, contracting, security, access, conversion, or incident response can influence a lender's operating process and timing, but the announcement does not change an existing loan agreement or promise faster credit. Its effect will depend on the final guidance and each institution's implementation.

Practical borrower takeaway

Maintain your own dated copies of submissions, approvals, term sheets, closing documents, statements, and servicing correspondence. Use verified lender channels, confirm sensitive requests and wire instructions independently, limit unnecessary data sharing, and identify a human escalation contact. Ask early whether a third-party platform, appraisal, environmental provider, payment system, or other vendor controls a milestone in the financing timeline, then preserve contingency time without treating proposed guidance as a substitute for legal, cybersecurity, or lender advice.

PFCS borrower takeaway

Borrowers using bank portals, fintech channels, or third-party loan services should keep an independent transaction file, verify requests and payment instructions, and allow time for lender vendor, data-security, and operational reviews.

Discuss a financing need →

This independent summary is based on the cited source and is provided for general educational purposes only. Terms and program requirements may change.