For three years, a bank examiner walking into a $400 million community bank applied roughly the same third-party risk checklist as one walking into a regional bank with a dozen fintech partnerships and a core processor serving millions of accounts. On September 11, four federal regulators said that era is over.

The Office of the Comptroller of the Currency, the Federal Reserve Board, the FDIC and the National Credit Union Administration jointly proposed new supervisory guidance that replaces the existing interagency third-party risk framework with what the agencies call a principles-based approach. The core change is simple to state and significant to apply: banks will be expected to size their oversight to the actual harm a vendor relationship could cause, not to a uniform checklist applied regardless of the vendor’s size or function. The proposal is open for public comment for 60 days following publication in the Federal Register, and the agencies have said they intend to rescind and replace the current guidance once it is finalized.

From Checklist to Risk Score

The distinction matters more than it sounds. Under the old framework, a bank’s relationship with a core banking processor, the kind of vendor a Marqeta or a Thought Machine occupies, could trigger the same documentation burden as a contract with a regional marketing firm. Community banks in particular have argued this pushed them toward two bad outcomes: over-monitoring low-risk vendors to satisfy examiners, and under-resourcing the genuinely consequential relationships, like the fintech middleware providers that sit between a bank’s ledger and a consumer-facing app.

Advertisement

300 × 250

Alongside the third-party risk proposal, the four agencies issued a joint statement specifically addressing community banks’ relationships with core service providers, the handful of large processors that effectively run the technology backbone for thousands of smaller institutions. That statement lays out the factors regulators will weigh when deciding whether to supervise or enforce against a bank over a core-provider relationship, including the due diligence a bank performed, its ongoing monitoring, and the contract terms it negotiated. The Federal Reserve separately opened comment on a companion guide built specifically for the community banks it supervises.

The Regulator’s Case

Comptroller of the Currency Jonathan V. Gould framed the change as part of a broader deregulatory push for smaller institutions. “Today, we are cutting unnecessary regulatory friction, tailoring supervision to actual risk, and strengthening community banks’ ability to manage critical third-party relationships,” Gould said in the OCC’s announcement. “We are giving these vital institutions more freedom to do what they do best, serve their customers, support local businesses, strengthen their communities, and drive economic growth across America.”

The OCC tied the third-party proposal to a string of other changes it has made this year for community banks, including a dedicated supervision track, the removal of certain routine examination activities, a higher asset threshold for qualifying as a community bank, updated model risk management guidance, and simplified licensing and Bank Secrecy Act procedures.

What It Means for the Finance Leader

For a bank’s chief risk officer or a fintech’s head of bank partnerships, the practical effect will show up in due diligence packets, not headlines. A principles-based standard gives banks more latitude to argue that a low-risk vendor, say, a data analytics tool with no access to customer funds, does not need the same annual audit cadence as a payments processor moving deposit balances. That latitude cuts both ways. Examiners retain full authority to demand deeper scrutiny of a relationship they judge genuinely risky, and the core-service-provider statement makes explicit that regulators are watching the concentration of technology risk in a small number of processors that thousands of community banks depend on.

For fintechs that operate as the technology layer inside a bank charter, the shift is worth watching closely. A more risk-calibrated standard could make banks more willing to onboard new middleware and infrastructure partners, since the compliance cost of a new relationship no longer scales automatically with paperwork rather than actual exposure. It could also mean sharper scrutiny for the fintechs whose failure would take down a bank’s core operations, the category the agencies are explicitly targeting with the core-provider statement.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

What to Watch Next

The comment period runs 60 days from Federal Register publication, which means the substance of the final guidance is still negotiable. Community bank trade groups are likely to push for the widest possible discretion in scoring vendor risk, while consumer advocates and some examiners may push back on any framework that gives banks room to under-monitor a fintech partner until something breaks. The core-service-provider statement, not the broader risk-management proposal, is the piece most likely to shape near-term bank-fintech deal terms, since it tells banks exactly what regulators will look at first if a shared vendor relationship goes wrong.

Banks and their fintech partners now have a defined window to shape a rule that will govern how the industry documents risk for years. The agencies have signaled where they want to land. Whether the final guidance holds banks to that same discretion when a core provider actually fails is the question worth tracking once the comment period closes.

Not every route into banking runs through the same regulator, and the charter path a fintech chooses increasingly determines which of these agencies it answers to first. The stakes of getting third-party oversight wrong are not abstract either: a recent government review found the disclosure gap around bank oversight failures has outlived two separate bank collapses without being closed.

Source: Office of the Comptroller of the Currency