OCC Proposes Tailored Third-Party Risk Rules and Eases Core Provider Oversight Burden
The OCC announced a proposal to tailor third-party risk management requirements to actual risk levels, aiming to reduce compliance burden on community banks while maintaining safety standards — accompanied by new supervisory clarity on core service providers. Fintech and crypto firms that serve as third-party vendors to OCC-supervised banks should expect that the banks' due diligence, contracting, and monitoring obligations toward them may be recalibrated based on risk tier.
What to do
- Monitor the OCC's formal proposal once published in the Federal Register, and assess how a risk-tiered framework could affect your firm's vendor onboarding questionnaires, audit clauses, and ongoing monitoring commitments with bank partners.
Who this affects
Does this affect your program?
Pick your institution type for an instant read on whether you're in scope — then see exactly which sections of your own policies this changes.
Source
Read the official publicationThis radar entry is educational and does not constitute legal advice. Summaries are AI-assisted and grounded in the linked official source; always verify against the primary source and consult qualified legal counsel for jurisdiction-specific guidance.