OCC, Fed, FDIC & NCUA Propose Unified Third-Party Risk Management Guidance
Four federal banking regulators are jointly proposing updated third-party risk management guidance that emphasizes risk-proportionate oversight and replaces existing agency-specific guidance. The proposal encourages institutions to tailor their vendor management programs to the actual risk level of each relationship, size, and complexity of the organization. This is directly relevant to any bank or fintech that relies on third-party technology providers, crypto rails, or payment processors.
What to do
- Map your current third-party inventory against the proposed risk-tiering framework and identify any vendor relationships that may require enhanced due diligence under the new guidance before it is finalized.
Who this affects
Does this affect your program?
Pick your institution type for an instant read on whether you're in scope — then see exactly which sections of your own policies this changes.
Source
Read the official publicationThis radar entry is educational and does not constitute legal advice. Summaries are AI-assisted and grounded in the linked official source; always verify against the primary source and consult qualified legal counsel for jurisdiction-specific guidance.