CiberLATAMbywhalemate

OCC, Fed Expand Oversight of Third Parties

The OCC said public comments are due 60 days after Federal Register publication. The proposal moves ahead with the Fed

Whalemate Labs · AI-assisted researchPublished:Updated 4 min read

The Federal Reserve, FDIC, NCUA and OCC proposed new third-party risk management guidance for banks and credit unions in the U.S. The OCC also clarified that public comments are due 60 days after Federal Register publication.

Update September 13, 2026: The OCC clarified that the deadline for public comments on the proposal runs 60 days from its publication in the Federal Register, not from the Sept. 11 announcement. The rest of the article remains unchanged, with that clarification on the consultation process.

The Federal Reserve, the FDIC, the NCUA and the OCC on Sept. 11, 2026 proposed new third-party risk management guidance for banks and credit unions in the United States. If finalized, the framework would replace the current guidance and aims to align each institution’s controls with the risk level of each outside vendor, based on potential harm and the likelihood it will occur.

What changes under the new third-party guidance?

The proposal would push institutions to focus resources where risk is highest and tailor controls to each bank’s size, complexity and risk profile. The OCC said the goal is a more proportional approach for community and regional institutions, with supervision centered on relationships that could have the greatest impact on the bank.

The new framework concentrates on four main areas, operational resilience, information security, legal compliance and financial resilience. The vendors covered include payment processors, digital banking companies, cybersecurity firms and financial crime prevention platforms.

The OCC also issued a separate bulletin on risk-based supervision of core services provided to community banks. According to that document, examiners will assess how institutions identify and manage operational and cyber risks tied to outsourced services.

The American Bankers Association read the proposal as placing special emphasis on core provider practices for community banks, with closer scrutiny of contracts, performance, cybersecurity and business continuity. Bloomberg also said the market views it as part of a broader review of critical technology vendors, with possible effects on providers that work across borders with banks in Latin America.

What other federal guidance moved that same week?

On Sept. 8, 2026, the OCC, FinCEN, the Federal Reserve, the FDIC and the NCUA published FAQs on the use of government-issued verifiable digital credentials within the Customer Identification Program under the Bank Secrecy Act and Anti-Money Laundering rules. The text explains how state mobile driver's licenses and other digital credentials can be used to identify customers without weakening security and verification controls.

At the same time, the federal incident-notification regime for cybersecurity incidents remains in force for banks supervised by the OCC, Federal Reserve or FDIC. Institutions must notify their primary regulator as soon as possible and no later than 36 hours after determining that an incident met the reporting threshold, under the joint rule in effect since 2022 and codified in Title 12, Part 53.

That 36-hour clock applies when the incident has caused, or is likely to cause, a critical disruption to banking operations for four or more hours. The notification must include operational impact, the nature of the incident and planned remediation steps, according to analysis by Phoenix Strategy Group.

The same regime also applies to bank service providers, which must alert their bank clients when an incident causes, or could cause, a material service disruption or degradation of at least four hours. NetBankAudit said that requirement reinforces the third-party risk dimension of the banking cybersecurity framework.

What comes next for reporting and incidents?

CIRCIA will add another notification clock for entities treated as critical infrastructure in the financial sector. RiskTemplates said the final rule is expected in September 2026 and would require substantial cyber incident reports to CISA within 72 hours, plus 24 hours to report ransomware payments.

That analysis notes that, for financial services, reporting to CISA will run alongside existing obligations to the OCC, FDIC, SEC, NYDFS and state breach-notification laws. BryceStreet added that the 72-hour and 24-hour deadlines are set by the law passed by Congress in 2022, leaving CISA limited room to loosen them.

Reuters also reported that in 2026 federal supervisory agencies began multiple enforcement actions against financial institutions over alleged Bank Secrecy Act violations and significant deficiencies in AML/CFT programs. On another front, Davis Polk said the OCC and FDIC adopted a joint rule redefining what counts as an unsafe or unsound practice, while CryptoSlate reported a reputational-risk rule that took effect on June 9, 2026 and limits supervisory measures based solely on that criterion.

The regulatory picture also includes the 2025 guidance on crypto asset custody, which stressed stronger cybersecurity controls for banks offering virtual asset safekeeping. Yale School of Management observed that the new third-party guidance and the core provider statement point to tighter supervision of the technology chain serving community and midsize banks, including institutions with international correspondent relationships.

Sources

View all