Skip to content
TECH CEO Daily
FintechBreaking

Bank regulators propose third-party risk management guidance rewrite to ease fintech ties

The four agencies would scrap the 2023 interagency guidance and a 2024 statement on fintech deposit programs in favor of oversight tailored to each relationship's risk.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Four federal agencies proposed on September 11, 2026 to replace the 2023 third-party risk management guidance.
  • 2The draft says old language may have discouraged bank partnerships with fintechs and would also retire a 2024 deposit-program statement.
  • 3Comments are due November 16, 2026; Fed Governor Michael Barr dissented, warning of gaps in supervisory coverage.

The news

On September 11, 2026, the FDIC, Federal Reserve, OCC and National Credit Union Administration proposed new third-party risk management guidance that would replace the 2023 interagency guidance issued by the FDIC, Fed and OCC and tailor bank oversight of vendors and fintech partners to each relationship's actual risk.

The proposal, published in the Federal Register on September 15, would rescind the June 2023 interagency guidance along with its supplements. Those include the July 2024 joint statement on bank arrangements with third parties to deliver deposit products, which was aimed at fintech deposit programs, and a 2024 guide for community banks. Comments are due November 16, 2026.

The agencies wrote that the 2023 guidance has been read as a prescriptive checklist, that banks applied heavy oversight regardless of actual risk, and that its wording has been read to discourage deals with newer, innovative firms by indicating they may present elevated risks. The draft says it would strip broad, overly prescriptive wording from the 2023 guidance "that may unduly impede fintechs from entering partnerships with banking organizations," and it cites a May 2026 executive order on integrating financial technology into regulation.

The document also says banks may rely on consortia, standard-setting bodies and certification organizations for parts of due diligence, and that certifications or third-party assessments may be adequate depending on the facts. It adds that a vendor's use of subcontractors alone does not typically create a separate third-party relationship or a presumption of direct bank oversight, though the bank stays responsible for legal compliance. The agencies also issued a joint statement on community banks' dealings with core service providers, and the Fed proposed a companion guide for traditional community banks.

The Fed board was divided. Governor Michael Barr dissented, arguing that a material financial risk threshold for supervisory action makes it less likely banks fix problems early, that excluding consumer compliance could leave a gap in risk if existing guidance is rescinded, and that the community bank guide leaves out banks with complex business models and fintech partnerships. Governor Lisa Cook supported the proposal but asked for input on cybersecurity expectations and on how banks and fintech partners should split duties for consumer protection, recordkeeping and anti-money-laundering controls.

The numbers

Agencies proposing the guidance
4 (FDIC, Fed, OCC, NCUA)
Comment deadline
November 16, 2026
Guidance it would replace
June 2023 interagency guidance plus 2024 supplements
Synapse end-user funds still owed after partner-bank resolution process (Banking Dive)
Up to $95 million

Why CEOs should care

For fintech CEOs and CFOs that depend on sponsor banks, the proposal could shorten diligence for lower-risk services and make shared certifications count. Ask your bank partners now how they plan to re-tier vendors under the draft, which of your services they consider highest risk, and whether an industry certification would replace their own questionnaires. For consumer-facing deposit or lending programs, note that the draft does not directly address consumer compliance and says using third parties does not reduce the bank's responsibility for legal compliance.

For bank CFOs, chief risk officers and boards, the draft invites a rethink of how third-party risk budgets are spent. Map the vendor inventory by assessed risk rather than by activity type, and identify relationships getting heavy review that pose little financial or legal risk. Because Barr dissented and the guidance is non-binding, build a program that would still satisfy a stricter examiner if policy swings back after a future leadership change.

CISOs should note that Cook asked for input on whether the agencies should be more specific about cybersecurity practices. Our read, not the agencies': cyber controls at critical vendors are likely to remain an exam focus even if other expectations loosen. The comment period is the chance to argue for clear lines of responsibility with fintech partners.

The bigger picture

The draft would also retire the July 2024 deposit-products statement. Separately, Banking Dive reported on September 17 that thousands of end users of fintechs tied to middleware firm Synapse, which failed in 2024, were still owed as much as $95 million after a resolution process by its partner banks, and that the CFPB has set aside $55.2 million to reimburse customers of fintechs Yotta and Juno with no disbursement timeline. The agencies argue risk-tiering focuses examiner and bank resources where they are needed; Barr argues it weakens early intervention. Law firm Ballard Spahr, in a September 17 post, read the draft as spelling out specific policy elements banks must address, a different emphasis from the agencies' principles-based framing.

What’s next

Comments close November 16, 2026, after which the agencies must decide whether to finalize the guidance largely as proposed. Fintechs and banks that want shared certifications or clearer allocation of compliance duties should say so in the record, because the final text is likely to shape how partner banks run diligence.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made with our newsroom’s technology tools, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is not published automatically; it is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

FDICFederal ReserveOCCBank-fintech partnerships

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

How this story was made. Researched and written using our newsroom’s technology tools and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Weekdays, 6 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.