Two bank technology-risk professionals review infrastructure controls beside a secure server room.
Two bank technology-risk professionals review infrastructure controls beside a secure server room.
01

Four agencies propose a replacement framework

The Federal Reserve, FDIC, NCUA and OCC proposed principles-based guidance for managing third-party relationships. If finalized, the package would replace existing federal third-party-risk guidance rather than create a new binding rule by itself. [1] [2]

The proposal covers the lifecycle of a relationship, including planning, due diligence, contract negotiation, ongoing monitoring and termination. Comments are due 60 days after publication in the Federal Register. [1] [2]

02

Core providers receive a separate community-bank focus

The agencies also issued a statement on community-bank engagement with core service providers. The statement recognizes the operational concentration around critical technology while emphasizing access to records, incident information, accountable contracts and practical exit planning. [1] [2]

Governor Michael Barr argued that a proposed material-financial-risk threshold could narrow expectations too far for complex bank-fintech arrangements. Governor Lisa Cook highlighted questions involving cybersecurity, consumer protection, records and responsibility for anti-money-laundering controls. [3] [4]

03

The operating test is evidence across the vendor lifecycle

A credible implementation should connect business ownership, technical access, data lineage, subcontractors, resilience tests, incident escalation, complaints and termination rights to evidence that management and supervisors can inspect. [1] [2]

This is proposed, non-binding guidance. finorasjournal does not state that existing federal guidance has already been rescinded, and this report is financial-regulation information rather than legal or compliance advice. [1] [2]