Fed, FDIC propose new third-party risk guidance for banks
The Federal Reserve and other US financial regulators jointly proposed new principles-based guidance on 11 September 2026, aiming to refine how financial institutions manage risks from external relationships.

Joint Regulatory Action on Third-Party Risk
The Federal Deposit Insurance Corporation (FDIC), the Federal Reserve Board (FRB), the National Credit Union Administration (NCUA), and the Office of the Comptroller of the Currency (OCC) jointly requested public comment on proposed guidance for third-party risk management on 11 September 2026.
This collective initiative by the US federal bank regulatory agencies aims to assist financial institutions, including banks and credit unions, in better aligning and tailoring their risk management practices for relationships with external providers. The proposed framework is principles-based and, consistent with all supervisory guidance, will not be legally binding.
Its development draws on the agencies' extensive supervisory experience and insights gained from examining current third-party risk management approaches within financial institutions. The overarching goal is to foster both consistency and prudent innovation across the banking industry as institutions navigate their external partnerships.
Enhancing Risk Management Frameworks
The core objective of the proposed guidance, released by the agencies on 11 September 2026, is to provide a comprehensive framework that helps financial institutions identify, assess, and mitigate risks associated with their reliance on third-party services. This includes everything from IT providers to outsourcing partners.
By offering a clearer set of principles, the regulators intend to enable institutions to develop more robust and proportionate risk management programmes that are specific to the unique risks presented by each third-party relationship.
Once the guidance is finalised, the federal bank regulatory agencies plan to supersede all existing third-party risk management guidance, consolidating and updating the regulatory expectations for the sector. Public comments on the proposal are due 60 days following its publication in the Federal Register.
Specific Focus on Community Banks
In a related but separate development on 11 September 2026, the federal bank regulatory agencies also issued a statement concerning community banks' engagement with core service providers.
This statement clarifies specific factors that the agencies will consider when making supervisory and enforcement decisions related to these essential providers, acknowledging the particular operational context of community banks. Concurrently, the Federal Reserve Board independently sought public comment on a distinct proposed third-party risk management guide.
This guide is specifically tailored for community banks supervised by the Federal Reserve and is intended to function as a companion document to the broader, joint guidance. These separate but complementary initiatives underscore a nuanced approach to risk management, recognising the varied operational scales and complexities across the US financial sector.
Implications for Asian Financial Sector Engagement
For Asian financial institutions, particularly those with operations or significant business relationships in the United States, these evolving US regulatory standards, proposed on 11 September 2026, will necessitate close attention.
While directly applicable to US-domiciled entities, new guidance on third-party risk management often influences global best practices and compliance expectations. Asian banks operating US branches or subsidiaries, or those acting as correspondent banks for US institutions, may find their own third-party risk frameworks scrutinised against these emerging benchmarks.
Furthermore, US financial institutions engaging with Asian third-party service providers will likely apply these heightened standards to their international relationships.
As the guidance moves towards finalisation in early 2027, Asian financial sector leaders should review their current risk management policies and vendor due diligence processes to ensure alignment with these updated US regulatory expectations.
This analysis is journalism, not investment advice; consult a licensed professional before making financial decisions.
Pieces are credited to the desk that commissioned and edited them. Our editorial standards, and the desks behind them, are set out on the Editorial Standards and Team pages.
Further reading
- Briefings · Markets
SoftBank Group shares drop 11% after OpenAI delays IPO
The Tokyo-listed investment firm saw its stock decline significantly earlier this week, following an announcement from OpenAI that it would delay its initial public offering and advocate for slower AI development.
Continue reading → - Briefings · Policy
Will South Korea's Corporate Tax Rate Be Reduced?
Finance Minister nominee Lee Hyoung-il confirmed on Sunday that the 25% corporate tax rate, reinstated this year, will not be lowered, influencing business investment forecasts for the coming fiscal periods.
Continue reading → - Briefings · Policy
RBI proposes freezing accounts for cyber fraud
India's central bank seeks public input on proposed amendments to its Know Your Customer directions, aiming to formalise how banks can temporarily freeze accounts linked to cyber fraud by October 2, 2026.
Continue reading →
