KEY TAKEAWAYS
Editorial note: The 2023 interagency guidance remains in effect. The framework described here is proposed and may change before it is finalized. Recommendations reflect SBS interpretation and experience.
Bankers have spent years hearing that every third-party relationship must be managed through a sound vendor management process. While this isn't changing any time soon, two interagency releases issued in September 2026 are potentially changing how much work regulators expect you to apply to each relationship — and where they expect that work to land.
These proposed interagency documents sharpen the message in a way that should feel familiar to anyone who has followed the SBS CyberSecurity approach to vendor management. The first is proposed interagency Third-Party Risk Management Guidance from the OCC, Federal Reserve, FDIC, and NCUA. If finalized as proposed, it would rescind and replace the 2023 Interagency Guidance on Third-Party Relationships: Risk Management. The second is a Joint Statement on Community Banks' Engagement with Core Service Providers from the Federal Reserve, FDIC, and OCC, explaining how the agencies will consider core provider relationships when allocating supervisory attention.
Taken together, the direction is clear: Stop treating vendor management like a paperwork exercise. Assess the risk, focus oversight where the potential harm is greatest, and expect more accountability from the providers most critical to banking operations. The biggest proposed change is not more vendor management. It is more risk-based vendor management.
What Is Changing from the 2023 Guidance?
The 2023 guidance already supported a risk-based approach and organized third-party risk management around the familiar lifecycle of planning, due diligence, contract negotiation, ongoing monitoring, and termination. This proposal is not a rejection of either.
The agencies explain, however, that the 2023 guidance has frequently been interpreted too broadly, with too little practical tailoring based on actual risk. They identify three concerns:
- Previous guidance can be read like a one-size-fits-all checklist.
- An emphasis on activities labeled "critical" can pull attention away from the actual magnitude and likelihood of harm.
- Directive words such as "should" can be taken as prescriptive requirements rather than examples to be tailored.
Three shifts follow from those concerns.
From "Critical Activities" to Assessed Relationship Risk
The proposal centers risk ratings on both the magnitude of potential harm and the likelihood that the harm will occur. A provider may be important, but the institution still needs to evaluate the actual relationship, services, dependencies, controls, and reasonably foreseeable consequences.
From Broad Checklists to Proportional Oversight
The proposed guidance repeatedly says due diligence, contracting, monitoring, staffing, and reporting should be proportionate to risk. Lower-risk relationships may justify less detailed, less frequent, or alternative oversight. Higher-risk relationships should receive more rigorous attention.

From a Stage-by-Stage Exercise to an Integrated Risk Decision
The familiar lifecycle remains, but the proposal reorganizes the framework around risk identification and assessment, risk oversight, residual risk acceptance, and governance. It also encourages institutions to look across stages, so controls are complementary rather than redundant.
The Risk Management Lifecycle Is Not Disappearing
The familiar stages of planning, due diligence, contract negotiation, ongoing monitoring, and termination are not going anywhere. The practical change is how much work an institution applies at each stage based on the importance and risk of the third party. The proposal gives institutions more room to use reasonable judgment, document that judgment, and scale the work to the risk, and examiners will give due consideration to those judgments.
One caveat matters more than any other: This guidance is still proposed. The 2023 guidance remains in effect unless and until the agencies finalize a replacement.
Why the Core Provider Statement Matters
At the same time the agencies are proposing more proportionate third-party oversight, they are pointing directly at one category that will usually warrant greater attention: core service providers.
The Joint Statement recognizes what community bankers already know. Core relationships are almost always a bank's most material, complex, most important, and highest-risk vendor relationships. The core provider market is concentrated, and banks often have limited negotiating leverage. The agencies say they are looking more closely at core banking provider transparency, contract language and requirements, technology capabilities, and the difficulty of exiting a core relationship when deciding the nature, extent, and frequency of supervisory activity directed at those providers.
The statement specifically highlights timely due-diligence information, measurable and enforceable service levels, disclosure of operational and security incidents, opaque pricing and back billing, deconversion fees, integration restrictions, end-of-life technology, and operational resilience. It also makes clear that a bank remains responsible for safe and sound operations when services are outsourced.
That is not a new checklist for banks. It is a regulatory signal that the quality of a core provider's documentation, contracts, technology, and resilience can affect the supervisory attention that provider receives. It also gives bankers stronger language for conversations they should already be having with their most critical providers.
It is also evidence that vendor management works best as a collective effort across the financial sector. That shared pressure is again pushing core banking providers to meet market demand rather than overlook the needs of small and midsized institutions, at least on the documentation side. Customer service may take a little longer.
Where This Lines Up with What SBS Has Taught for Years
The entire point of doing vendor management is to help your institution make better business and cybersecurity decisions. A vendor risk assessment is not a compliance formality; it identifies which relationships are most important and could materially affect operations, customers, information, financial condition, compliance, and reputation. What you learn from your vendor risk assessment should drive what happens next.
Our Certified Banking Vendor Manager (CBVM) program shows you how to put these ideas into practice. CBVM will help you understand exactly how to identify the vendors that are truly critical, decide which vendors you want to work with, determine which ones remain a good fit, and know how to respond when a vendor has red flags, a breach, a security incident, or simply proves to be a poor partner.
CBVM also shows you how to build a practical 80/20 approach to vendor management: Direct most of your focus and spend toward critical and significant vendors. The higher the vendor risk, the more questions to ask, the more evidence to analyze, the more frequently to review, and the more risk mitigation to expect. Higher-risk relationships earn deeper due diligence, stronger contract review, more frequent monitoring, meaningful metrics, resilience evidence, and documented risk decisions. Lower-risk relationships still need documentation and monitoring to stay defensible, but you don't need to consume the same resources, which may be better spent elsewhere. A small software vendor that provides a niche service to one of your teams should not command the same effort as a core processor, online banking platform, cloud provider, or managed service provider.
What Bankers Should Do Now
- Do not retire the 2023 guidance yet: The new document is a proposal, open for comment for 60 days from the date of filing with the Federal Register. Continue operating under current guidance while monitoring the rulemaking and preparing for a more explicitly tailored framework.
- Pressure-test your vendor risk ratings: Confirm that ratings reflect both potential impact and likelihood, and that "critical" is not applied so broadly it loses meaning. If every vendor that touches customer information is automatically rated critical, you have room to improve.
- Compare effort to risk: Review frequency, documentation requests, contract scrutiny, monitoring, staffing, and reporting should visibly scale with risk. Your highest-risk relationships should receive the most attention; lower-risk ones can be reviewed less often.
- Revisit core provider governance: Document areas of risk with core provider contracts, including limitations in transparency or contract language. Evaluate service levels and incident reporting requirements to ensure they meet your needs. Understand termination and switching constraints, and account for resilience and technology life-cycle concerns.
- Document judgment, not just documents: A folder full of SOC reports is not a risk decision. Show what the evidence means, what gaps remain, whether residual risk is acceptable, and who accepted it.
Start with Risk, Not Paperwork
These two releases are thematically connected. The proposed guidance says third-party oversight should be tailored to the risk each relationship presents. The Joint Statement says core providers are often where the most consequential risk, dependency, and limited leverage reside.
That is not a call to do less vendor management. It is a call to do better vendor management, and the institutions that get there first will spend less time defending their programs and more time strengthening them.
Start with risk. Focus on the vendors that matter most. Gather evidence, analyze it, document the decision, monitor what changes, and keep improving. That has been the SBS message for years. If the proposal is finalized, it will simply make that message easier for bankers to defend.
![]()
Build a Vendor Program That Holds Up Under Scrutiny
Utilize SBS's knowledge and experience, combined with your team's insights into internal processes, people, and culture, to create a tailored approach to next-level cybersecurity.
Read More
As your organization grows and incorporates more vendor relationships, the need for a strong vendor management program also grows.
Read More
Jon Waldman
Jon Waldman is the Co-Founder and President of SBS CyberSecurity, where he oversees the SBS service teams and the SBS Institute. For more than 20 years, Jon has helped hundreds of organizations identify and understand cybersecurity risks to allow them to make better and more informed business decisions. Jon's passion for cybersecurity training and education led him to be a driving force in the development of the SBS Institute. Designed for the banking industry, the Institute provides specialized cybersecurity education and now offers more than 10 certification courses, with State Association partnerships in 30+ states.Jon maintains his CISA, CRISC, and CDPSE certifications. He received his Bachelor of Science in Computer Information Systems and his Master of Science in Information Assurance with an emphasis in Banking and Finance Security from Dakota State University, a Center of Academic Excellence in Information Assurance Education designated by the NSA.
