US Regulators Propose Third-Party Bank Risk Guidance
US banking regulators proposed non-binding third-party risk management guidance, drawing a dissent from Fed Governor Michael Barr.
By Muhamed Porić
October 2, 2026 at 10:10 PM

U.S. banking regulators have jointly proposed principles-based third-party risk management guidance aimed at helping institutions tailor oversight to individual vendor relationships, though the non-binding proposal drew a dissenting vote from Federal Reserve Governor Michael Barr over its risk standards.
The initiative comes as financial institutions increasingly rely on external technology vendors, cloud providers, and service providers for core operations. Compared to previous rigid regulatory mandates, the new framework lets banks scale their oversight efforts based on the specific risk profile of each vendor relationship.
"The proposed guidance intends to assist banking organizations in better aligning and tailoring their third-party risk management practices to the risks of individual third-party relationships," according to a report from Investing.com.
Joint Regulatory Effort and Comment Period
The guidance is backed by four major federal regulatory bodies:
- Federal Reserve
- Office of the Comptroller of the Currency (OCC)
- Federal Deposit Insurance Corp. (FDIC)
- National Credit Union Administration (NCUA)
As supervisory guidance rather than a formal rule, the proposal does not carry the immediate force of law. Public comments on the draft framework are due 60 days following its official publication in the Federal Register, giving financial institutions and industry groups a window to weigh in on the proposed oversight principles.
Governor Barr Dissents Over Risk Standards
While the interagency proposal moved forward, it did not secure unanimous support. Federal Reserve Governor Michael Barr voted against the measure, specifically citing concerns regarding the "material financial risk" standard embedded within the text, according to Briefs.co.
The debate over the material financial risk threshold highlights ongoing tensions among regulators regarding how strictly institutions should monitor smaller vendors versus systemically critical third-party partners. Critics of loose standards argue that undetected vulnerabilities in minor vendors can cascade into broader operational failures, while proponents of flexibility warn that overly prescriptive rules impose heavy compliance burdens on smaller community banks and credit unions.
What Is at Stake for Banking Operations
Effective third-party risk management has become a central focus for financial regulators following several high-profile tech outages and data breaches originating from third-party service providers. By establishing a standardized yet flexible framework, the Fed, FDIC, OCC, and NCUA seek to ensure that banks maintain operational resilience without stifling the adoption of modern financial technology.
Muhamed Porić
Founder and Editor of Embers.
Newsletter
Get Embers in your inbox
The stories that actually moved something, delivered when there's something worth sending, not daily filler.