The news
On September 11, 2026, the FDIC, Federal Reserve, OCC and National Credit Union Administration proposed new third-party risk management guidance that would replace the 2023 interagency guidance issued by the FDIC, Fed and OCC and tailor bank oversight of vendors and fintech partners to each relationship's actual risk.
The proposal, published in the Federal Register on September 15, would rescind the June 2023 interagency guidance along with its supplements. Those include the July 2024 joint statement on bank arrangements with third parties to deliver deposit products, which was aimed at fintech deposit programs, and a 2024 guide for community banks. Comments are due November 16, 2026.
The agencies wrote that the 2023 guidance has been read as a prescriptive checklist, that banks applied heavy oversight regardless of actual risk, and that its wording has been read to discourage deals with newer, innovative firms by indicating they may present elevated risks. The draft says it would strip broad, overly prescriptive wording from the 2023 guidance "that may unduly impede fintechs from entering partnerships with banking organizations," and it cites a May 2026 executive order on integrating financial technology into regulation.
The document also says banks may rely on consortia, standard-setting bodies and certification organizations for parts of due diligence, and that certifications or third-party assessments may be adequate depending on the facts. It adds that a vendor's use of subcontractors alone does not typically create a separate third-party relationship or a presumption of direct bank oversight, though the bank stays responsible for legal compliance. The agencies also issued a joint statement on community banks' dealings with core service providers, and the Fed proposed a companion guide for traditional community banks.
The Fed board was divided. Governor Michael Barr dissented, arguing that a material financial risk threshold for supervisory action makes it less likely banks fix problems early, that excluding consumer compliance could leave a gap in risk if existing guidance is rescinded, and that the community bank guide leaves out banks with complex business models and fintech partnerships. Governor Lisa Cook supported the proposal but asked for input on cybersecurity expectations and on how banks and fintech partners should split duties for consumer protection, recordkeeping and anti-money-laundering controls.
The numbers
- Agencies proposing the guidance
- 4 (FDIC, Fed, OCC, NCUA)
- Comment deadline
- November 16, 2026
- Guidance it would replace
- June 2023 interagency guidance plus 2024 supplements
- Synapse end-user funds still owed after partner-bank resolution process (Banking Dive)
- Up to $95 million
Why CEOs should care
For fintech CEOs and CFOs that depend on sponsor banks, the proposal could shorten diligence for lower-risk services and make shared certifications count. Ask your bank partners now how they plan to re-tier vendors under the draft, which of your services they consider highest risk, and whether an industry certification would replace their own questionnaires. For consumer-facing deposit or lending programs, note that the draft does not directly address consumer compliance and says using third parties does not reduce the bank's responsibility for legal compliance.
For bank CFOs, chief risk officers and boards, the draft invites a rethink of how third-party risk budgets are spent. Map the vendor inventory by assessed risk rather than by activity type, and identify relationships getting heavy review that pose little financial or legal risk. Because Barr dissented and the guidance is non-binding, build a program that would still satisfy a stricter examiner if policy swings back after a future leadership change.
CISOs should note that Cook asked for input on whether the agencies should be more specific about cybersecurity practices. Our read, not the agencies': cyber controls at critical vendors are likely to remain an exam focus even if other expectations loosen. The comment period is the chance to argue for clear lines of responsibility with fintech partners.
The bigger picture
The draft would also retire the July 2024 deposit-products statement. Separately, Banking Dive reported on September 17 that thousands of end users of fintechs tied to middleware firm Synapse, which failed in 2024, were still owed as much as $95 million after a resolution process by its partner banks, and that the CFPB has set aside $55.2 million to reimburse customers of fintechs Yotta and Juno with no disbursement timeline. The agencies argue risk-tiering focuses examiner and bank resources where they are needed; Barr argues it weakens early intervention. Law firm Ballard Spahr, in a September 17 post, read the draft as spelling out specific policy elements banks must address, a different emphasis from the agencies' principles-based framing.
What’s next
Comments close November 16, 2026, after which the agencies must decide whether to finalize the guidance largely as proposed. Fintechs and banks that want shared certifications or clearer allocation of compliance duties should say so in the record, because the final text is likely to shape how partner banks run diligence.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made with our newsroom’s technology tools, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is not published automatically; it is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error





