Agencies Propose Updated Third-Party Risk Management Guidance — Comment Period Open
The FDIC, Federal Reserve, NCUA, and OCC have jointly proposed updated guidance to help financial institutions manage risks in third-party relationships and are seeking public comment. Crypto firms, fintechs, and payment companies that serve as third-party vendors to regulated financial institutions — or that rely on third-party technology providers themselves — should review the proposal, as it will shape the due diligence, contracting, and oversight standards their bank clients must apply.
What to do
- Download the proposed third-party risk management guidance, evaluate how the proposed standards affect your vendor tier classifications and oversight programs, and consider submitting a comment letter to influence the final guidance.
Who this affects
Does this affect your program?
Pick your institution type for an instant read on whether you're in scope — then see exactly which sections of your own policies this changes.
Source
Read the official publicationThis radar entry is educational and does not constitute legal advice. Summaries are AI-assisted and grounded in the linked official source; always verify against the primary source and consult qualified legal counsel for jurisdiction-specific guidance.