Skip to main content

folkfox

Skip to main content
Skip to content
FINTECH AND NEO-BANKING

Third party risk management: the proposed reset banks should not sell as settled

Four US agencies have asked for comment on a proposed reset of third party risk management guidance. The commercial job is not to announce a finished rule. It is to explain the consultation, the customer impact and the evidence your bank can already show.

Quick answerThird party risk management guidance proposed on 11 September is nonbinding and open for a 60-day comment window. Banks should describe it as a consultation, then make their vendor controls easier for customers to understand.
SECTION 01

What was published, and what was not#

A fox that hears a gate move does not tell the den a new road has opened. It checks the latch. On 11 September, the Federal Reserve, FDIC, NCUA and OCC requested comment on proposed third party risk management guidance. That wording matters. The agencies have not issued a final rule, and the material is nonbinding supervisory guidance rather than a new legal obligation.

The proposal says it would help banks and credit unions align their third party risk management work with the assessed risk of each relationship. If finalised, the agencies plan to rescind existing guidance and replace it. Until then, a bank should not imply that its supplier, platform or customer journey is already certified against a new standard. A fintech should not turn a consultation into a compliance badge. That is a short, sharp scent trail to a credibility problem.

Comments are due 60 days after Federal Register publication. The window creates a useful public moment for product, risk and communications teams to compare notes. It does not create a countdown to a final operating rule.

third party risk management proposal shown as a paper trail through a bank archive
A consultation is a trail to inspect, not a rulebook to claim.

The phrase that must survive the homepage#

Use a sentence that a cautious customer, a procurement lead and a regulator can all read the same way: the agencies have proposed nonbinding third party risk guidance and invited comment. That is plainer than saying the rules have changed. It is also true. In financial services, plain proof has a longer life than a clever launch line.

SECTION 02

Why a risk-based approach is back on the table#

The 35-page proposed third party risk guidance says the 2023 approach was often interpreted too broadly. Banks told the agencies that they struggled to see which considerations applied to a core processor, a fintech or a facilities vendor, and that examples could start to look like a one-size-fits-all checklist. The proposed answer is not less care. It is oversight matched to the relationship, the institution and the likely harm.

That distinction has a commercial consequence. A payments platform can explain what it does, where data flows, how incidents are handled and who owns customer communication without pretending it carries the same bank vendor risk as a core ledger provider. Specificity gives sales teams a firmer trail. It helps buyers ask the right questions before procurement turns them into a spreadsheet nobody can navigate.

The agencies say the draft would focus attention on material financial risks, legal and regulatory compliance, and resource allocation. It also says a tailored approach can support responsible innovation. Read that carefully: it is a proposed supervisory preference, not a regulatory permission slip for every bank-fintech arrangement.

The documents issued on 11 September
Bar chart comparing the page counts of two official third party risk documentsProposed guidance: 35Core-provider statement: 740302010035Proposed guidance7Core-providerstatement
Bar chart comparing the page counts of two official third party risk documents
ItemValue
Proposed guidance35
Core-provider statement7
The proposed guidance is 35 pages. The accompanying community-bank core-provider statement is 7 pages. Both are official documents, neither is a final rule.

The numbers are modest, but the reading work is not. A short public statement can still alter the questions a board asks a core service provider. Product marketing should make room for that scrutiny before it creates a webinar, a sales deck or a press quote.

SECTION 03

The sharper signal sits with the core provider#

Alongside the proposal, the agencies issued a joint statement on community banks' engagement with core service providers. It treats core processing, account management, payments, customer relationship management, compliance reporting and online banking as material functions. It also recognises that these relationships can make due diligence, contract negotiation and ongoing monitoring harder for smaller institutions.

That is the useful commercial tension. A core service provider can say it gives a community bank scale, but it should also make transparency, exit planning, service standards and data access easy to find. If a buyer must chase a vendor for the answer, the brand promise is already thinner than the product pitch.

The statement says the agencies will consider whether provider practices unreasonably limit a community banking organisation's due diligence, ongoing monitoring or ability to negotiate terms. A vendor does not need to wait for a supervisory conversation to improve its evidence room. The work is immediate, quiet and practical: name the controls, name the owner and show the client what happens when a service changes.

third party risk management evidence room with a fox examining a vendor contract
Transparency is a customer experience, not a footnote.

This is where folkfox fintech marketing meets the dull but decisive work of institutional trust. The most useful page may not be the brightest campaign page. It may be the one a bank can send to its risk committee without a second rewrite.

SECTION 04

How to communicate a consultation without overclaiming#

There is an obvious temptation to frame third party risk management as a fresh obstacle or a finished compliance event. Neither reading is supported by the material published this week. The better story is narrower: a proposed guidance document asks for a more risk-focused, tailored approach, and firms can use the comment period to test whether their own explanations make sense to a buyer.

Start with the product page. Separate statements of current fact from statements about the proposal. Current fact: your platform uses a named security review or publishes an incident process, if it genuinely does. Proposal: the agencies have invited comment on guidance that could replace existing material if finalised. Keep those two sentences apart. Blurring them makes a current control sound regulator-endorsed and a future consultation sound inevitable.

Governor Lisa D. Cook's separate statement is also a useful brake on breezy summaries. She supports a fresh look, while inviting comment on greater specificity for cybersecurity and the division of consumer-protection, records and anti-money-laundering responsibilities in bank-fintech partnerships. Those are live questions, not settled answers.

The proposal in four checkable facts

Participating agencies

4

Federal Reserve, FDIC, NCUA and OCC

Comment window

60 days

After Federal Register publication

Current status

0 final rules

It is proposed, nonbinding guidance

A brand strategy that can carry this distinction calmly is a competitive asset. So is content marketing that turns complex assurance material into clear customer language without flattening the legal facts.

SECTION 05

A practical third party risk management checklist for growth teams#

Third party risk management belongs in the growth room because a bank's vendor relationships often sit inside the product customers buy. They influence onboarding, account access, payment timing, support and data handling. If marketing publishes a promise that product, legal or the core service provider cannot support, the trust loss arrives before the customer reaches the small print.

Put one accountable person from product, risk and customer communications around the same table. Read the proposal against the claims already on the site. Flag any headline that says compliant, approved, secure or always-on without explaining the condition beneath it. Replace it with the proof you can show today. This is the patient prowl: slower than a campaign sprint, far cheaper than a public correction.

The OCC's joint release repeats the central point: the agencies seek comment on proposed guidance and have issued a separate core-provider statement. That is the full news. Everything else is an interpretation that should be labelled as one.

For acquisition teams, the test is simple. Can a prospect find the data-handling explanation, the service boundary and the escalation route before they surrender their details? If not, the campaign is asking the customer to leap a hedge in the dark. SEO and GEO can make the evidence findable, while paid social should never outrun it.

The fox does not mistake a consultation for a conclusion. Neither should a bank, a fintech or the agency writing its next landing page.

There is a useful audit hidden in this news cycle. Take the five pages a procurement lead is most likely to read: security, privacy, data processing, platform reliability and pricing. Can each page say where the business relies on a third party without losing the customer in abstraction? Can it name the difference between a contractual promise, an operational practice and an aspiration? The exercise exposes the copy that has been asked to carry more certainty than the business can prove.

Do the same with sales enablement. A good answer to a third party risk management question has a source, an owner and a date. It does not need to be theatrical. A short response that says who reviews a control, how a client learns about a material change and where to find the relevant term will usually do more for trust than a glossy architecture diagram full of unnamed shields.

For a community bank, the customer impact is often closer than the policy language makes it sound. A core service provider may sit behind the app a customer opens, the transfer they expect to clear, the balance they read or the support agent who sees their history. That is why bank vendor risk cannot stay entirely inside procurement. The quality of the relationship surfaces in ordinary moments, and customers judge those moments before they know the vocabulary behind them.

This does not mean every supplier should become a public case study. Contracts, security architecture and incident details need proper handling. It means the public-facing explanation should be proportionate to the promise. If a fintech asks people to move their money, connect an account or trust a payment flow, it should make the relevant boundaries clear enough for a cautious person to decide whether to proceed. That is not an extra compliance layer. It is the product story.

The next 60 days are therefore a listening period, not a licence to rewrite history. Teams can document questions, compare client experience with their own processes and contribute where they have useful evidence. They should leave the definitive language to the agencies. The strongest marketing line during a consultation is often the one that admits what is still being considered, then shows the customer what the company already does in the open.

The proposed text sits against an existing supervisory baseline. For the historical record, consult the agencies’ 2023 joint release, the Federal Reserve’s SR 23-4 letter, its guidance attachment, the FDIC’s financial-institution letter and the FDIC’s 2023 release. Those are context for comparing documents, not evidence that the 2026 proposal has taken effect.

Questions

Frequently asked questions#

What is third party risk management in banking?

Third party risk management is how a bank or credit union identifies, assesses and manages risks created by suppliers, service providers and other external relationships. The level of oversight should match the relationship, the institution and the likely harm.

Is the September 2026 third party risk guidance a final rule?

No. The Federal Reserve, FDIC, NCUA and OCC requested comment on proposed, nonbinding guidance. The agencies say they plan to replace existing guidance only if the new guidance is finalised.

How long is the comment period for the proposed guidance?

Comments are due 60 days after publication in the Federal Register. The release did not announce a final rule or immediate new compliance deadline.

What is a core service provider for a community bank?

The agencies use the term broadly for firms supporting essential functions such as processing, account management, payments, customer relationship management, compliance reporting and online banking.

What should fintech marketing say about the proposal?

State that the guidance is proposed and nonbinding, link to the primary material, and describe only controls the company can evidence today. Do not imply regulatory approval or a completed rule change.

Keep reading

Read more on this topic#

Need financial product marketing that can face the hard questions?

folkfox turns complex fintech evidence into clear product stories, search pages and campaigns that do not outrun the facts.

Want folkfox in your Google results and AI answers? Set folkfox as a preferred source.