NextFin

Agencies Rewrite Bank Outsourcing Rulebook, Splitting the Fed's Own Board

Summarized by NextFin AI
  • Four federal bank regulators proposed replacing the existing third-party risk management rulebook with a principles-based framework keyed to a new "material financial risk" standard, released September 11, 2026.
  • The proposal exposed a Fed board split: Governor Michael S. Barr dissented over fears of supervisory gaps and reduced safe-and-sound operations, while Governor Lisa D. Cook backed a "fresh look" but demanded more specificity on cybersecurity and bank-fintech responsibilities.
  • The operative shift ties supervisory action to materiality rather than the prior lifecycle process-checklist approach, and rescinds the June 6, 2023 interagency guidance to promote consistency and prudent innovation.
  • Two companion moves signal supervisory focus: a joint statement on community banks' core service providers and a Fed-specific guide for Federal Reserve-supervised community banks, with comments due 60 days after Federal Register publication.

NextFin News - The four federal bank regulators moved on Friday to replace the existing rulebook for how banks and credit unions manage third-party relationships with a principles-based framework keyed to a new "material financial risk" standard — and the proposal immediately exposed a split on the Federal Reserve's own board, with Governor Michael S. Barr dissenting over fears it will leave supervisory gaps while Governor Lisa D. Cook backed a "fresh look" but pressed for more specificity on cybersecurity and bank-fintech responsibilities.

The Federal Deposit Insurance Corporation, the Federal Reserve Board, the National Credit Union Administration and the Office of the Comptroller of the Currency jointly requested comment on proposed third-party risk management guidance, released at 10:00 a.m. EDT on September 11, 2026. The agencies said the guidance reflects supervisory experience and lessons learned from examining financial institutions' third-party practices, and is intended to help banks and credit unions "better align and tailor their third-party risk management practices to the risks of individual third-party relationships." When finalized, the agencies plan to rescind the existing third-party risk management guidance and replace it, a move they say will promote consistency and prudent innovation in the banking industry. Comments are due 60 days after publication in the Federal Register.

Two companion moves signal where supervisory attention will actually concentrate. The agencies separately issued a statement on community banks' engagement with core service providers, laying out factors they will weigh in supervisory and enforcement decisions involving those core providers. And the Federal Reserve Board on its own requested comment on a proposed third-party risk management guide for Federal Reserve-supervised community banks, intended as a companion to the interagency guidance.

The Substantive Shift: From Process Checklists to a Materiality Threshold

On its face, the proposal is a calibration rather than a revolution: supervisory guidance is non-binding, and the agencies emphasize a principles-based approach. But the operative change is the introduction of a new standard of "material financial risk" that governs when supervisors will take action. That threshold matters because it flips the supervisory posture embedded in the prior regime. Under the guidance the agencies now plan to rescind — the interagency third-party risk management guidance finalized on June 6, 2023, which itself replaced each agency's earlier guidance — examiners evaluated a bank's third-party risk management across the full relationship lifecycle, from due diligence through termination, regardless of whether a problem had yet crystallized into a material loss. The 2026 proposal, by contrast, ties supervisory action to materiality.

"The interagency guidance incorporates a new standard of 'material financial risk' for supervisors to take action, making it less likely that banks will correct problems before they become material risks to the firm," Governor Barr wrote in his dissenting statement.

Barr's objection is mechanistic, not ideological. He said he could support a principles-based approach that promotes both innovation and safe and sound operations, including compliance with laws and regulations. "But I am concerned that this proposal will reduce safe and sound operations, increase financial and other risk, create undue confusion, and leave gaps in supervisory coverage," he wrote, before concluding with a one-line dissent.

His second concern targets specific language in the proposal. The guidance states that "agencies will give due consideration to a banking organization's reasonable decisions." Barr warned that phrase "may be misinterpreted to mean agencies will give deference to the bank's views on third-party risk management, rather than making an independent judgment." In supervisory practice, that distinction is the difference between a regulator accepting a bank's self-assessment and a regulator testing it. A principles-based regime that leans on "reasonable decisions" shifts the burden of proof toward the examiner, who must now demonstrate unreasonableness rather than simply identify a missing control.

There is a third fault line in Barr's statement, and it is the one most likely to matter for community banks. The two proposals specifically exclude consumer compliance matters. Barr argued that if a final rule rescinds existing guidance, it could either "end up rescinding existing guidance, leaving a big gap in risk, or banks could end up needing to comply with two sets of guidance, sowing confusion and increasing burden." That is a genuine structural problem: consumer-protection obligations tied to third-party relationships — fair lending, unfair-deceptive-abusive acts and practices, servicing rules — do not disappear because prudential guidance changes. If the prudential framework no longer reaches them but consumer-compliance expectations persist, banks face a two-regime compliance burden, which is precisely the duplication the proposal claims to eliminate.

Cook's Conditional Support: Innovation, but Not at the Expense of Specificity

Governor Cook's statement provides the counterweight — support for the direction of travel, with a demand for more granularity where the proposal is thinnest. "I support taking a fresh look at the third-party risk management guidance, particularly as banks are managing larger, more complex vendor relationships and navigating novel, emerging risks," she said.

Cook framed the principles-based approach as a tool for competition. "A principles-based and risk-focused approach may be helpful towards promoting these goals—especially for enabling innovation and competition for vendor services," she wrote. But she then identified the exact areas where flexibility becomes a liability: "However, I welcome comments on whether the agencies should provide greater specificity on effective risk management practices relating to cybersecurity or the allocation of responsibilities for consumer protection, record management, and anti-money laundering in bank-fintech partnerships."

That list is not accidental. Cybersecurity, consumer-protection allocation, record management and anti-money laundering are the four domains where a bank's dependence on a third party is hardest to unwind and where failure is most contagious. A cloud outage can be survived with contingency plans; an AML breakdown embedded in a fintech partner's onboarding flow cannot be patched after the fact. Cook's statement effectively tells the agencies where the comment period should focus: principles are acceptable for vendor selection and pricing, but not for the controls that keep the payment and compliance plumbing intact.

Cook also drew a sharp distinction between the interagency guidance and the Fed's community-bank companion. "In addition, I strongly support the proposed Third-Party Risk Management Guide for Traditional Community Banking Organizations, as a tailored, helpful resource to assist traditional community banks, facing increasingly complex and critical relationships with third-party vendors," she said. The asymmetry between the two documents is telling. The interagency guidance is principles-based and general; the community-bank guide is specific. That suggests the agencies themselves see the principles-based approach as workable only where institutions have the scale and sophistication to translate principles into controls — and that smaller banks need the prescription the larger ones are being freed from.

Why This Is Structural, Not Cyclical

It is tempting to read this as a routine regulatory refresh — guidance gets updated, comments are taken, a final version arrives. That reading would be wrong. This is a structural shift in supervisory philosophy, and it will not revert on its own.

Three pieces of evidence support that call. First, the agencies explicitly plan to rescind the existing guidance and replace it — a deliberate regime change, not an amendment at the margins. Second, the "material financial risk" standard redefines the trigger for supervisory intervention, moving from a process-and-control evaluation to an outcome-and-materiality test. Third, the proposal carves the banking system into distinct supervisory categories — traditional community banks get their own guide, banks with complex business models and bank-fintech partnerships are explicitly excluded from that guide, and core service providers get their own joint statement. That is segmentation by business model, and it implies a durable reallocation of exam resources rather than a temporary emphasis.

The cyclical counter-read would hold that this is simply a response to industry burden complaints, and that once examiners encounter a high-profile third-party failure, the pendulum will swing back toward prescriptive rules. History offers some support: the 2023 guidance itself was a tightening cycle, replacing the agencies' earlier, more fragmented guidance after years of fintech expansion and bank-fintech sponsorship growth. But the mechanism here differs. The 2023 guidance was a reaction to specific failures and gaps; the 2026 proposal is a redefinition of the supervisory threshold itself. A cyclical adjustment changes how hard regulators push; a structural shift changes what they are allowed to push on. Reversing the latter requires new rulemaking, not just a change in exam emphasis.

There is also a time-horizon split worth separating. In the short term — the 60-day comment window and the months after finalization — the practical effect is limited, because supervisory guidance is non-binding and examiners will continue working under existing expectations until the final version takes effect. In the medium term, the effect lands on community-bank compliance costs: a tailored guide should reduce the burden of documenting third-party diligence for traditional community banks that lack large compliance departments. In the long term, the structural question is whether a materiality-based supervisory threshold can detect correlated, system-wide operational risk in concentrated core-provider markets before it materializes — and that is the bet the agencies are making.

The Second-Order Risk: Concentration That Materiality Tests Miss

The first-order effect of the proposal is straightforward: banks get more flexibility, examiners get a higher intervention threshold, and community banks get a tailored guide. The second-order effect is where the risk hides, and it runs through market concentration.

Core service providers — the vendors that run core banking systems, payments processing, and increasingly cloud infrastructure — are inherently concentrated. A handful of providers serve a large share of community banks. When one bank's core provider fails, that is an institution-level event. When a core provider that serves hundreds of community banks fails, that is a system-level event, and every affected bank's exposure is simultaneously "material." A supervisory framework that evaluates materiality at the institution level is structurally blind to that correlation. Each bank can pass its own materiality test while the system accumulates correlated operational risk.

This is the mechanism behind Barr's warning, and it is also the mechanism behind the agencies' separate statement on core service providers. The statement is not decorative. By publicly laying out the factors they will consider in supervisory and enforcement decisions related to core providers, the agencies are signaling where the materiality threshold will be applied most aggressively — and implicitly acknowledging that core-provider relationships are different in kind from ordinary vendor relationships. The companion Fed guide reinforces the same point: according to Barr's statement, the proposed guidance specifies that the community-bank guide is not intended for community banks with more complex business models or third-party relationship profiles, such as complex bank-fintech partnerships. Barr seized on that carve-out: "Experience suggests that many banks with complex business models are especially in need of guidance that better addresses their particular third-party risk management issues, which is not addressed in these proposals."

The adversarial case is that this concern is overstated. The proposal is a sensible calibration: the 2023 guidance was process-heavy, and smaller institutions were spending compliance resources on checklist diligence disproportionate to their actual risk. A principles-based approach lets banks scale their third-party diligence to the risk of the individual relationship, which is genuinely more efficient. And the agencies retain enforcement tools independent of this guidance — the Bank Service Company Act gives regulators examination authority over bank service companies, and the core-services statement preserves a channel for supervisory and enforcement action. From this vantage point, Barr's "gap" is mitigated by the companion guide and the core-provider statement, and Cook's request for specificity is a comment-period ask, not a reason to block the proposal.

That case is coherent, but it rests on an assumption that deserves scrutiny: that institution-level materiality tests, even applied rigorously, will surface correlated operational risk in time. The falsifying signal is observable. If, within 12 to 24 months of finalization, examination findings and enforcement actions show a rise in unresolved third-party deficiencies at community banks — repeat matters requiring immediate attention tied to core-provider oversight — or if a core-provider outage exposes gaps in contingency planning that the materiality threshold failed to surface before the incident, then the deregulatory thesis is wrong and the pendulum will have swung on its own. Watch the agencies' supervisory letters and the frequency of MRIAs referencing third-party and core-provider oversight; that is the early-warning metric.

What Comes Next

The immediate timeline is fixed: comments on the proposed guidance are due 60 days after publication in the Federal Register. The comment period will be the real battleground, and the two Fed statements already map the opposing coalitions. Industry groups and community-bank associations are likely to rally behind the principles-based approach and the tailored community-bank guide, arguing that the 2023 guidance imposed disproportionate burden on smaller institutions. Consumer advocates and prudential hawks will amplify Barr's dissent, pressing for the consumer-compliance carve-out to be narrowed and for more specificity on cybersecurity and AML in bank-fintech partnerships — the exact issues Cook flagged.

Three scenarios are plausible. In the base case, the agencies finalize a principles-based framework with modest clarifications around the "reasonable decisions" language and the consumer-compliance exclusion, adopt the community-bank guide largely as proposed, and use the core-services statement as the primary channel for signaling supervisory expectations on concentration. In the upside case for deregulation advocates, the final guidance narrows the consumer-compliance exclusion and provides the specificity Cook requested, producing a cleaner single regime that reduces duplication. In the downside case, the comment period surfaces evidence of unresolved third-party risk at community banks, the agencies delay finalization or add prescriptive elements, and the materiality threshold is softened — effectively vindicating Barr's dissent.

Short term, expect limited market impact: supervisory guidance is non-binding, and bank stocks rarely reprice on guidance proposals. Medium term, the winners are community banks with simple vendor profiles, which should see lower compliance costs, and core service providers, which gain regulatory clarity around the factors that matter to examiners. The exposed are banks with complex fintech partnerships — explicitly excluded from the community-bank guide and left to navigate the principles-based regime without the tailored roadmap — and the counterparties that serve them.

The central judgment: this is a structural recalibration of bank supervision, not a cyclical easing, and its success depends on whether a materiality-based framework can see correlated operational risk in concentrated vendor markets before it becomes material to everyone at once. The agencies have bet that principles plus targeted statements can do what checklists did — and that core providers, not individual banks, are where the real risk now lives. Barr has bet the opposite. The comment period, and the examination data that follows finalization, will decide which bet was right.

Explore more exclusive insights at nextfin.ai.

Search
NextFinNextFin
NextFin.Al
No Noise, only Signal.
Open App