The Regulators Answered
By: Paul Schaus
September 15, 2026
On Friday, September 11, the federal banking agencies released two documents that will reshape how financial institutions manage the vendors they depend on: a proposed rewrite of the interagency third-party risk management guidance and a joint statement on core service providers. The timing was fitting. Twenty-five years after this industry rebuilt itself around the lessons of operational resilience, its regulators turned to the modern form of the same question — the systems and providers no institution can operate without. In March, I wrote that the regulators were listening and asked what banks should do about it. This is the answer — I have read the documents and my verdict is simple: this is the most meaningful rebalancing of the bank-vendor relationship the agencies have put on paper in many years.
Start with what landed on the table. The first document is proposed third-party risk management guidance from the OCC, the Federal Reserve, the FDIC, and, for the first time in this framework, the NCUA. Third-party risk management, TPRM in the trade, is the discipline of vetting, contracting with, and monitoring every vendor a bank relies on — and the proposal would rescind and replace the 2023 interagency guidance that has governed it, along with the 2024 community bank guide and the 2024 statement on bank-fintech deposit arrangements. Comments are due 60 days after Federal Register publication.
The second document is a joint statement on community banks' engagement with core service providers from the Federal Reserve, the FDIC, and the OCC. It is the follow-through on the OCC's November 2025 request for information about core provider practices — the RFI I covered in March. The industry told the agencies what it thought. The agencies, it turns out, were taking notes.
The 2023 guidance organized vendor oversight around a "critical activities" test, and in practice it produced exactly what a test produces: documentation. Banks built programs that papered every relationship — the landscaping contract alongside the core processor — because examiners rewarded completeness and punished gaps. The agencies now say so themselves; the proposal states the 2023 guidance "unintentionally incentivized overly-process-driven approaches that fail to prioritize higher-risk relationships and focus risk management efforts and resources where they are needed."
The replacement is built on judgment instead. Risk assessment becomes a function of two questions — how much harm could this relationship cause and how likely is that harm — and oversight scales to the answer. Three features deserve every bank CEO's attention, because each one converts a longstanding grievance into a defensible position.
First, the guidance is explicitly non-enforceable — and that term deserves a translation because it changes how the document gets used. A regulation is law; an examiner can cite an institution for violating it. Guidance is the agencies' description of sound practice, and for years the industry's complaint has been that examiners treated guidance as if it were regulation anyway. This proposal renounces that in writing: it "does not set forth enforceable standards or prescriptive requirements," and deviation from it "will not alone be a basis for supervisory action." In practice, that means an examiner cannot write up your institution for managing third-party risk differently than the guidance describes — supervisory criticism must rest on an actual law, a regulation, or a genuine safety and soundness problem, not on a departure from the document itself. Second, on contracts, the proposal says what no interagency document has said this plainly: there are "no generally applicable expected contract terms for third-party relationships — even for higher-risk relationships," and the absence of a term an examiner considers best practice "would not alone be a sufficient basis for an examiner to communicate an adverse finding." Third, the guidance accepts reality on negotiating power. A bank that cannot win every contract term from a dominant vendor may reasonably proceed anyway — document the residual risk, the risk that remains after mitigations, against its board-approved risk appetite, and move on. It even endorses banks negotiating "as a group with other organizations," with an appropriate caution that collective activity must comply with antitrust law.
Two smaller passages matter more than their word count suggests. The due diligence section names "external industry experts familiar with the third party, the relevant industry, or with market standard terms and practices" as a legitimate supplement to a bank's own diligence, paired with a warning that "reliance on third parties for risk management purposes can itself involve risks." And a footnote in the termination section observes that termination cost planning includes "whether alternative providers may be willing to buy out the remaining term of the contract." When the agencies start describing exit economics in footnotes, they are telling you they expect exits to happen.
A word for the CFOs before anyone celebrates that footnote, because accounting does not match the economics. When a bank terminates a core contract early, the termination fee is an expense the day it is incurred, and any unamortized implementation costs the bank capitalized on the old system are written off at the same time. The buyout coming the other way is not symmetrical: under GAAP, consideration received from a vendor is generally presumed to be a reduction of the price of that vendor's services, which means the new provider's incentive typically spreads as an expense reduction over the life of the new contract. Pain this quarter, relief over the next seven years. The treatment can differ where the payment is structured as a reimbursement of specific, identifiable termination costs — so structure the deal with your accountants before you sign, not after. And boards should judge an exit on the cash economics over the life of the contract, not on the year-one earnings optics — the examiners grading your third-party risk decisions are reading the risk assessment, not the efficiency ratio.
The joint statement is addressed to the core providers, so let me be plain about who that means. A core provider is the technology company that runs a bank's central processing system — the core, the system of record that keeps every account, posts every transaction, and calculates every balance — along with the surrounding systems most community banks buy from the same vendor: payments processing, online banking, reporting, and compliance. Most community institutions rent this entire stack from one of a handful of large firms, and no bank can operate a single day without it. The statement tells those providers that their own business practices will now inform how intensively they are examined, what goes into the examination reports their client banks receive, and whether they are added to the agencies' service provider examination program. The statement calls community banks "community banking organizations," CBOs in its shorthand, and concedes the structural problem in plain terms: "a significant percentage of the core provider market is represented by just a few large providers, which limits CBOs' negotiating power."
The practices the agencies name will be familiar to any management team or board that has sat through a core renewal. I have walked institutions through these conversations for many years, and this list reads like meeting minutes — the items the CFO reads aloud, the ones the directors ask why the bank ever signed. Withholding due diligence information. Contract clauses that block a bank from comparing the provider's offering against competitors. Service-level agreements — contract sections that define what performance the bank is entitled to — without measurable standards. Slow disclosure of operational issues and security incidents. Opaque pricing, complex billing, and extensive "back billing" windows — the period during which a provider can reach back and retroactively charge for items missing from prior invoices. Unsupported or contractually undefined deconversion fees — the charges a provider levies when a bank leaves for a competitor — called out particularly where the provider itself breached the contract or underperformed its service levels. And restrictions on third-party integration, the contractual friction that keeps a bank from connecting the fintech tools its customers want.
Then comes the sentence that will occupy the providers' general counsel for months. The agencies state that core providers may qualify as "institution-affiliated parties" under the Federal Deposit Insurance Act, as persons who "participate in the conduct of the affairs of an insured depository institution," and thus "may be held liable for the practices or violations of a CBO as an institution-affiliated party." An institution-affiliated party is a legal status, not a metaphor, and it opens the door to direct enforcement against a provider under the same statute the agencies use against bank insiders. The theory is untested. The threat does not have to be tested to change behavior.
One more group should read that passage carefully: the advisors — my own industry included. The advisory ecosystem around a bank takes several forms — consulting firms like ours, individual practitioners in business for themselves, and the law firms — and the Federal Deposit Insurance Act's definition of institution-affiliated party reaches all of them, through two separate doors, based on what the advisor does rather than how the business is organized. The first door names consultants outright: the same provision the agencies just applied to the core providers covers any "consultant" who "participates in the conduct of the affairs" of an insured institution. The second door covers any independent contractor — and the statute's own examples are attorneys, appraisers, and accountants — under a higher bar: knowing or reckless participation in a violation, a breach of fiduciary duty, or an unsafe or unsound practice causing more than minimal loss. An advisor who provides analysis, options, and recommendations, with the institution making the decisions, is not participating in the conduct of the bank's affairs. An advisor who effectively makes the decisions for the bank is participating, no matter what the engagement letter says. The proposed guidance draws the same line from the bank's side: consultants are third-party relationships like any other, legitimate as a supplement to a bank's own diligence, and a risk when they substitute for it.
Management and boards will apply the same conduct test to their advisors that the agencies just applied to the vendors, and the first question is how the advisor is paid. Banks buy this kind of help under various fee structures: a fixed fee agreed in advance, time and materials, or a percentage of the savings the advisor claims to have won. The first two have their tradeoffs, but neither one moves with the answer the advisor gives you. The percentage model does, and the math works against the bank even though the bank writes the check: a fee tied to claimed savings rewards the advisor for defining savings generously, for favoring the long contract extension that makes the savings number bigger, and for closing quickly rather than negotiating fully. That economics deserves the same scrutiny the agencies just directed at a vendor's back-billing clause. The second question is whether the advisor takes anything from the other side of the table — referral fees, reseller margins, or vendor incentives included. An advisor whose fee does not move with the outcome is free to tell the bank the deal on the table is a bad one. If your advisor's compensation depends on the answer they give you, you have not hired an advisor. You have hired another counterparty.
Here is the detail most of the coverage will skip, and it is the one that determines who these documents reach. The agencies did not write a list of companies. They wrote a definition, and the definition is functional: core providers are "third parties that provide the critical systems applications and infrastructure that support the operation and essential functions of one or more of a CBO's lines of business, including, for example, through the provision of transaction processing, account management, payments processing, customer relationship management, compliance and reporting, online banking, and other material functions."
Read that list slowly. Online banking is named. Payment processing is named. Compliance and reporting is named. And the list ends with "other material functions," which is an open door, not a fence. The legal foundation was always this broad: under the Bank Service Company Act, a service performed for a bank by contract is examinable to the same extent as if the bank performed it itself, wherever the provider is headquartered and whatever it calls its product.
Now make it concrete, because the way banks buy technology is exactly why the definition matters. Most banks buy account processing from one of the large vendors — three providers control roughly 70% of the community bank market — and then build around it with other third parties: a digital banking vendor for online and mobile, a card processor, a payment hub for electronic transactions, a loan origination system for commercial lending. The industry habit is to call only the account-processing vendor "the core." The statement does not. Under the agencies' definition, each of those vendors qualifies on their own, because each runs an essential function the bank cannot operate without. Account processing is the heart of the definition. Online banking is named in it. Payment processing is named in it — card processing included. The loan origination system runs the essential functions of the commercial lending line. The agencies' word "core" describes the importance of the function, not the name on the master agreement. The test for each contract fits in one sentence: can the institution run its business without this vendor tomorrow? If the answer is no, the definition describes that vendor, and both sides should plan accordingly. Dependence, not product category, is what the agencies drew a circle around.
The chart below is CCG Catalyst's analysis of the two documents, built from our reading of the full text and our work advising institutions on the vendor relationships the agencies describe. It sorts the landscape by classification rather than by vendor name, because the analysis holds for every vendor in a class, and it shows both sides of the market: what each classification means for the financial institutions that buy, and what it means for the technology vendors that sell. Banks and credit unions read the institution column together — where their situations genuinely diverge, the next section explains how.
| Classification | Why the definition reaches it | Impact for financial institutions | Impact for technology vendors |
|---|---|---|---|
| Core processing | Named outright — the ledger is the essential function | Renewal leverage: the factor list converts old grievances into citable negotiating positions, and exam intensity now follows vendor conduct | The standard contract gets rewritten or explained to an examiner — deconversion, back-billing, and benchmarking clauses are now supervisory topics |
| Core hosting, resellers, and managed services | "Critical systems applications and infrastructure" — the channel is the relationship the institution experiences | The factor list applies to the contract and invoice you receive, with the manufacturer's terms treated as the layer underneath | A channel that translates opaque terms into clean client paper gains value; one that passes the opacity through inherits its supplier's scrutiny |
| Digital banking platforms | "Online banking" is named in the definition | Integration rights against the core become a negotiable, supervisory-backed term | The integration factor protects their access to the core; their own pricing, service levels, and exit terms face the same list |
| Payments and card processing | "Payment processing" is named | Pricing transparency, billing complexity, and exit terms are reviewable against the factor list | Complex billing and undefined fees stop being sales objections and become examination factors |
| Banking-as-a-service and ledger infrastructure | Transaction processing and account management for accounts the institution answers for | Sponsor and fintech programs reopen with the 2024 statement's rescission; oversight can scale program by program | Designs that keep the institution in control of its ledger are favored; the "we handle the compliance" pitch collides with the reliance warning |
| Loan origination and servicing systems | Essential functions of the lending line of business | Sits high in the institution's own risk ranking; oversight scales to materiality, not to a checklist | Materiality pulls them into scope; measurable service levels and clean data-exit terms become the differentiators |
| Fraud, BSA/AML, and compliance systems | "Compliance and reporting" is named | The reliance warning applies twice here — the institution still owns the judgment its tools inform | The winning position is tooling that makes the institution's own judgment faster and better documented, not a substitute for it |
| Advisors and consultants — firms, independent practitioners, law firms | Reached by the FDI Act directly: "consultants" who participate in an institution's affairs, and independent contractors including attorneys | Apply the same conduct test — keep decisions inside the institution, and scrutinize any fee that moves with the outcome | Advisory-lane work is protected; making the client's decisions, or outcome-contingent compensation, draws the same scrutiny as vendor lock-in |
The chart treats banks and credit unions as one column, and for most purposes that is right. This is a genuine rebalancing for both charters: programs built to the 2023 standard can be right-sized, which frees compliance resources currently spent documenting the office supply vendor; the fintech chill that followed the 2024 statement lifts, consistent with the direction of Executive Order 14405 on integrating financial technology into regulatory frameworks; and every institution walking into a renewal now carries a citable federal document listing, factor by factor, the contract practices the examiners themselves consider obstacles to sound risk management. I have argued for years that the procurement process in this industry is broken; the agencies just handed institutions the leverage to start fixing it one contract at a time.
But the machinery underneath differs in one way that matters. The proposed guidance carries four signatures — OCC, Federal Reserve, FDIC, and NCUA — which puts credit unions inside the interagency third-party framework for the first time. The joint statement carries three, the banking agencies only. And behind that difference sits a structural one: the banking agencies can examine service providers directly under the Bank Service Company Act, while the NCUA's equivalent vendor examination authority lapsed in 2002 and has never been restored, despite the agency's repeated requests to Congress.
The practical translation: for banks, the statement is leverage with an enforcement engine behind it — up to and including the institution-affiliated-party theory. For credit unions, the same documents arrive as leverage without the engine — negotiating language, risk-based framework, and the factor list all apply, but the examination pressure on vendors runs through the banking agencies and reaches the credit union market indirectly, because the major providers serve both charters and will not maintain two sets of paper. When a core provider shortens its back-billing window or defines its deconversion schedule to satisfy a bank examiner's factor list, its credit union clients inherit the reform. Spillover is not a strategy, but in this market, it is a real force — and credit union executives should time their own renewals to catch it.
Notice what the framework never asks: how big the vendor is, where it is from, or what category its product occupies. Every consequence keys off conduct — transparency, contract behavior, technology investment. For the large core providers, the statement is a direct shot, and the rational response is to reform the paper before the examiners arrive; over the next 12 to 24 months, I expect the standard contracts to move on back-billing, deconversion schedules, benchmarking carve-outs, measurable service levels, and integration rights — with resistance during the comment period and uneven adoption after it. For everyone else on the chart, the asymmetry rearranges the map: a client-owned cooperative whose governance already delivers what the factor list demands can put the statement beside its standard contract and invite the comparison, and a vendor of any size whose margins depend on exit friction and billing opacity now carries a supervisory profile its sales team will have to explain.
Now the caveats. The guidance is proposed, not final, and it is non-binding by its own terms. The statement governs how the agencies allocate supervisory attention; it creates no new rule. Examiner behavior in the field typically lags Washington policy by a year or more, so an institution should not expect its next exam team to have absorbed the new philosophy. And the shift from checklist to judgment cuts both ways: the agencies promise "due consideration to a banking organization's reasonable decisions," which means management now owns the burden of showing its decisions were reasonable. A checklist, whatever its faults, told you when you were done. Judgment never does.
My advice fits in five sentences. Read both documents, not a summary of them, because the leverage lives in the specific language. Take the one-sentence test to your vendor inventory and rank every relationship by it — the vendors you cannot operate without belong at the top of your risk assessment, whatever their product category. Pull those contracts and mark them against the statement's factor list — back-billing, deconversion, benchmarking, service levels, integration rights — and if a renewal falls in 2027 or 2028, start the work now, because the providers' standard paper will be at its most negotiable while this spotlight is on. Recalibrate your third-party risk program to the risk-based model, board risk appetite statement included, so the resources come off the low-risk files and onto the relationships that can hurt you. And file a comment letter, because the agencies just demonstrated that they read them.
The regulators listened. Then they answered. They did not draw a fence around specific companies — they drew a circle around dependence, and nearly everyone selling into this industry is standing inside it.
CCG Catalyst advises banks and credit unions on core provider strategy, contract negotiation, vendor selection, and third-party risk. If your institution is approaching renewal or mapping its vendor inventory against this framework, reach out to our team at www.ccgcatalyst.com.
See our latest announcement: CCG Catalyst's Paul Schaus Named a 2026 Top Consultant by Consulting Magazine
By: Paul Schaus | Founder & Managing Partner, CCG Catalyst Consulting
Disclaimer: The views expressed in this article represent the perspective of CCG Catalyst Consulting based on our direct experience advising financial institutions. This commentary is intended to stimulate industry discussion and does not constitute legal, accounting, or regulatory advice.