All developments
OCCVendor / TPRMSeptember 11, 2026

Agencies Propose Updated Third-Party Risk Management Guidance — Comment Period Open

The FDIC, Federal Reserve, NCUA, and OCC have jointly proposed updated guidance to help financial institutions manage risks in third-party relationships and are seeking public comment. Crypto firms, fintechs, and payment companies that serve as third-party vendors to regulated financial institutions — or that rely on third-party technology providers themselves — should review the proposal, as it will shape the due diligence, contracting, and oversight standards their bank clients must apply.

What to do

  • Download the proposed third-party risk management guidance, evaluate how the proposed standards affect your vendor tier classifications and oversight programs, and consider submitting a comment letter to influence the final guidance.

Who this affects

Bank / Credit UnionFintech / NeobankPayments CompanyCrypto ExchangeCrypto CustodianMoney Services BusinessOther

Does this affect your program?

Pick your institution type for an instant read on whether you're in scope — then see exactly which sections of your own policies this changes.

Source

Read the official publication

This radar entry is educational and does not constitute legal advice. Summaries are AI-assisted and grounded in the linked official source; always verify against the primary source and consult qualified legal counsel for jurisdiction-specific guidance.

Related developments

OCC

OCC Updates Cybersecurity Examination Work Program for Banks

The OCC has revised its Cybersecurity Supervision Work Program (CSW), which examiners use to assess cybersecurity risk at national banks and federal savings associations, updating its structure and references to reflect the evolving threat landscape and adoption of standardized frameworks. For compliance and risk officers at banks, neobanks, and trust companies under OCC supervision, this signals updated examiner expectations around cybersecurity controls and preparedness. Crypto custodians and fintechs with bank charters or partnerships should also take note, as vendor and third-party cybersecurity risk is often assessed through this lens.

FDIC

FDIC Joins Interagency Third-Party Risk Management Guidance Proposal

The FDIC is participating in the same four-agency interagency proposal to update third-party risk management guidance for banking organizations, signaling broad regulatory alignment on vendor oversight expectations. FDIC-supervised institutions, including state non-member banks that frequently partner with fintechs and crypto firms, should treat this proposal as a preview of future examination standards. The agencies intend to rescind and replace existing guidance, making this a significant structural change for compliance programs.

OCC

OCC Joins Interagency Proposed Third-Party Risk Management Guidance

The OCC is co-issuing the same interagency third-party risk management proposal alongside the Fed, FDIC, and NCUA, signaling a unified supervisory approach across the federal banking agencies. National banks and federal savings associations should treat this as a near-certain indicator of forthcoming binding expectations on vendor oversight. The proposal's emphasis on risk-proportionate controls is particularly relevant for institutions using crypto or fintech service providers.

Federal Reserve

OCC, Fed, FDIC & NCUA Propose Unified Third-Party Risk Management Guidance

Four federal banking regulators are jointly proposing updated third-party risk management guidance that emphasizes risk-proportionate oversight and replaces existing agency-specific guidance. The proposal encourages institutions to tailor their vendor management programs to the actual risk level of each relationship, size, and complexity of the organization. This is directly relevant to any bank or fintech that relies on third-party technology providers, crypto rails, or payment processors.

Stay ahead of every rule change

PliOS monitors FinCEN, OCC, OFAC, the SEC and CFTC and tells you which of your policies each new rule affects — with the edit already drafted. Start free.

Run My Free Assessment