Skip to content

Third-Party Risk Guidance: The AI Inside Your Vendor Contracts

Regulators' Sept. 11 third-party risk proposal reframes vendor risk by AI exposure. See what banks and credit unions should do now.

Third-Party Risk Guidance: The AI Inside Your Vendor Contracts
Third-Party Risk Guidance: The AI Inside Your Vendor Contracts

Quick Answer

 

On September 11, 2026, the Federal Reserve, FDIC, OCC, and NCUA proposed new, principles-based Third-Party Risk Management Guidance to replace the 2023 interagency guidance. The Fed, FDIC, and OCC also issued a statement on how community banks engage “core providers” — vendors running transaction processing, payments, compliance, and customer relationship management. The headline idea, risk-based tailoring, sounds like relief: fewer reviews for low-risk vendors. For most institutions, the honest version runs the other way — CRM vendor files are still graded on record-keeping, years before that CRM shipped AI reading member data and acting on it. A genuine re-grading moves that vendor up the list, not down. Comments on the proposal are due 60 days after Federal Register publication, scheduled for September 15, 2026, putting the deadline at approximately November 14, 2026.

Key Takeaways (TL;DR)

  • What happened: On Sept. 11, 2026, the Fed, FDIC, OCC, and NCUA proposed guidance to replace the 2023 interagency third-party risk framework for banks and credit unions.
  • Already in force: the Fed, FDIC, and OCC also issued a statement on community banks' “core provider” relationships — effective immediately, not open for comment.
  • Proposal, not a rule: comments close 60 days after Federal Register publication (scheduled Sept. 15, 2026) — around Nov. 14, 2026.
  • The AI catch: risk-based tailoring reads like fewer questionnaires for low-risk vendors. Any vendor now shipping embedded AI that reads account or member data — especially your CRM — should get re-graded up, not down.
  • The regulatory hook: the core-provider statement names “customer relationship management” as a function that can make a vendor a core provider — the highest-scrutiny tier.
  • What to negotiate: audit rights over model behavior, advance notice before a vendor defaults-on new AI, and data residency for AI inference.

What the Agencies Proposed on September 11

The Fed, FDIC, OCC, and NCUA jointly requested comment on new Third-Party Risk Management Guidance — a principles-based framework replacing the 2023 interagency guidance. The goal: align oversight with each vendor's actual assessed risk, instead of running every vendor through the same checklist. A core processing provider will almost always land in the higher-risk tier; a back-office vendor can carry a lighter file.

Like the guidance it replaces, the proposal sets no enforceable standard — deviating from it is not itself a violation, though the agencies keep authority over unsafe practices tied to poor third-party oversight. The Fed separately proposed a narrower companion guide for its “traditional community banking organizations,” explicitly excluding banks with more complex arrangements such as bank-fintech partnerships — a gap Governor Barr flags in his dissent (below).

Both documents remain proposals; nothing changes in your exam obligations today. The Federal Register filing lists a scheduled publication date of September 15, 2026, with comments due 60 days after — see Timeline for the exact math.

The Second Document: A Statement That's Already in Effect

September 11 also produced the Fed, FDIC, and OCC's Joint Statement on Community Banks' Engagement with Core Service Providers (NCUA is not a party, since it covers bank and thrift “community banking organizations,” not credit unions). Unlike the guidance, this statement is not out for comment — it took effect immediately and already shapes how examiners weigh a core provider relationship.

Core providers supply the critical systems behind a bank's lines of business, and the statement names the functions explicitly: transaction processing, account management, payments processing, customer relationship management, compliance and reporting, and online banking — CRM sits beside core processing and payments.

A handful of large providers dominate this market, the agencies note, limiting a community bank's negotiating leverage. Examiners will weigh three factors in supervising a core provider relationship:

Factor What the agencies will weigh The question to ask your CRM or core vendor
Transparency Willingness to share due-diligence information, service-level detail, and timely incident disclosure Will the vendor document what its AI features do with your data, and tell you before that changes?
Contract features Exit barriers, opaque pricing and billing, deconversion fees, restrictions on integrating outside tools Can you audit, negotiate, or decline an AI feature the vendor turns on by default?
Technology Security-incident history, handling of end-of-life systems, demonstrated resilience Does the vendor's AI roadmap carry the same security and resilience commitments as its core platform?

A core provider can, in some circumstances, also be treated as an “institution-affiliated party” under the Federal Deposit Insurance Act — meaning the provider itself, not just the bank, can face direct supervisory consequences.

Who This Affects

This is written for community banks and, through the broader proposed guidance, credit unions — specifically COOs, chief compliance officers, and vendor-management owners who sign off on third-party risk assessments. If your institution runs core banking, lending, payments, or customer-facing operations through outside platforms, this proposal and statement already apply to your existing vendor relationships, not just future ones.

The Vendor Re-Grading Most Institutions Will Get Wrong

Risk-based tailoring is being framed, reasonably, as relief: fewer full-scope reviews for the physical-security vendor and the outside law firm, more attention where it belongs. Most vendor-management teams will read that as “do less” across the board.

For any vendor that has shipped embedded AI in the last 18 months, the honest exercise runs the opposite way. Take the CRM: most vendor files still carry it as one line item, risk-graded years ago against what it did then — store contact records, log service notes, route cases to a queue. That grade predates the vendor's own roadmap. Today the same platform likely ships an AI layer reading member or account PII, drafting outbound communications, and increasingly acting — flagging accounts, triaging cases, updating records — without a person reviewing every step. The core-provider statement's own definition puts customer relationship management beside transaction processing and payments; if your CRM is central to servicing or online banking, it likely meets the agencies' test for a core provider.

A genuinely risk-based re-grading moves that vendor up the list the moment its AI starts acting on regulated data unattended. That is not a reason to rip out a CRM — it is a reason to re-rate the vendor against what it does today, not what it did when the contract was signed.

What to Do Before the Comment Window Closes

  1. Re-run the risk assessment against today's product. Pull contracts touching transaction processing, payments, compliance, or your CRM, and re-score each against AI or agentic features added since the last review.
  2. Apply the core-provider test literally. If a vendor delivers any function the statement names — even your CRM — treat it under the three-factor test, whatever your inventory currently calls it.
  3. Negotiate the three clauses the statement all but names. Audit rights over how an AI feature uses your data; advance notice before the vendor changes or defaults-on a model; and data-residency commitments for wherever the AI inference happens.
  4. Use the comment window. The guidance is still shapeable for 60 days after Federal Register publication — file a comment on Regulations.gov under the relevant docket.
  5. Treat the core-provider statement as live today, not pending. It already shapes examiner weight, so a re-graded inventory has value now, regardless of the broader guidance's timeline.

Timeline: What Happens Next

September 11, 2026: The Fed, FDIC, OCC, and NCUA request comment on the proposed guidance; the Fed separately proposes its community bank companion guide; the Fed, FDIC, and OCC issue the core-provider statement, effective immediately.

September 15, 2026 (scheduled): Federal Register publication of both proposals (OCC Docket OCC-2026-0793; Fed Docket OP-1881; FDIC RIN 3064-ZA58; NCUA Docket NCUA-2026-1684).

On or around November 14, 2026: The 60-day comment window closes, 60 days from the scheduled September 15 publication. That date falls on a Saturday, so plan to submit by Friday, November 13.

After the comment period: The agencies finalize the guidance on no set date. Governor Barr's dissent — warning that the “material financial risk” trigger could make examiners slower to flag problems, and that excluding consumer compliance matters could leave a gap — suggests the final text may get more specific, not less.

How Vantage Point Helps

Vantage Point helps community banks and credit unions get two things right: an honestly risk-graded vendor inventory, and a CRM platform — Salesforce, HubSpot, or otherwise — built to survive that grading. Our compliance and security solutions practice runs the vendor and permissions review, mapping which relationships now meet the core-provider test and where AI features have outgrown the contract's access and audit controls. Our Salesforce implementation and advisory team then closes the gaps. Senior consultants only — no junior handoffs; the experts you meet are the experts who deliver.

In one anonymized engagement, Vantage Point rebuilt the Salesforce Financial Services Cloud architecture for a $2.25 billion community bank, cutting manual data entry 93% and processing time 50% while building the audit trail examiners ask for — a 340% ROI within 18 months. See the case study. For related reading, see our guides to reducing Salesforce compliance risk in banks and Agentforce financial services compliance.

Ready to Re-Grade Your Vendor Inventory?

 

The comment window is open and the core-provider statement already applies. Vantage Point's senior consultants can review your CRM and core vendor contracts against the agencies' three factors and help prioritize the clauses worth renegotiating first. Contact Vantage Point to schedule a vendor-risk review, or explore our compliance and security services.

Frequently Asked Questions

What did federal banking regulators propose on September 11, 2026?

The Fed, FDIC, OCC, and NCUA proposed principles-based Third-Party Risk Management Guidance to replace the 2023 interagency guidance, asking banks and credit unions to align vendor oversight with each vendor's actual assessed risk rather than uniform reviews. The Fed also proposed a companion guide for its community banks, and the Fed, FDIC, and OCC issued a related statement on core service providers.

Is the new third-party risk guidance a final rule?

No. It is a proposal open for public comment, not a binding rule — deviating from it is not itself a violation, though examiners can still act on unsafe practices tied to weak third-party oversight. Comments are due 60 days after Federal Register publication.

When does the comment period end?

The Federal Register public-inspection filing lists a scheduled publication date of September 15, 2026. Sixty days from that date puts the deadline at approximately November 14, 2026, a Saturday — plan to submit by Friday, November 13, 2026.

What is the Joint Statement on Community Banks' Engagement with Core Service Providers?

A statement issued the same day by the Fed, FDIC, and OCC (not NCUA, since it covers community banking organizations, not credit unions) on how examiners weigh a core provider's transparency, contract terms, and technology. It took effect immediately and defines core providers as vendors delivering transaction processing, account management, payments, customer relationship management, compliance and reporting, or online banking.

Does the guidance specifically call out artificial intelligence or CRM vendors?

Neither document uses the word AI. The connection is the core-provider statement's own definition, which lists customer relationship management among the functions that can make a vendor a core provider. Vantage Point's read: CRM and other vendors that added AI features reading regulated data should be treated as higher-risk than their files reflect, not lower.

Why did Federal Reserve Governor Michael Barr dissent?

Barr argued a new material financial risk threshold could make examiners slower to flag problems while they are still small, and that both proposals exclude consumer compliance matters, risking a gap once existing guidance is rescinded. His dissent says the proposals could weaken oversight, not that they go too far.

What should a bank or credit union do about a CRM vendor that has added AI features?

Re-run its risk assessment against what it does today, not what it did at signing, and test it against the core-provider definition. If it qualifies, prioritize audit rights over the AI feature's data use, advance notice before the vendor changes or defaults-on a model, and data-residency commitments for wherever the AI processing happens.

This article is regulatory analysis for planning purposes and is not legal advice. Confirm specific obligations and comment-filing details with counsel and your primary regulator before acting.

Sources


Vantage Point is a boutique CRM consulting firm helping businesses transform with Salesforce, HubSpot, and AI — 150+ clients, 400+ engagements, and a 4.71/5 average engagement rating. Learn more at vantagepoint.io.

David Cockrum

David Cockrum

David Cockrum is the founder and CEO of Vantage Point, a specialized Salesforce consultancy exclusively serving financial services organizations. As a former Chief Operating Officer in the financial services industry with over 13 years as a Salesforce user, David recognized the unique technology challenges facing banks, wealth management firms, insurers, and fintech companies—and created Vantage Point to bridge the gap between powerful CRM platforms and industry-specific needs. Under David’s leadership, Vantage Point has achieved over 150 clients, 400+ completed engagements, a 4.71/5 client satisfaction rating, and 95% client retention. His commitment to Ownership Mentality, Collaborative Partnership, Tenacious Execution, and Humble Confidence drives the company’s high-touch, results-oriented approach, delivering measurable improvements in operational efficiency, compliance, and client relationships. David’s previous experience includes founder and CEO of Cockrum Consulting, LLC, and consulting roles at Hitachi Consulting. He holds a B.B.A. from Southern Methodist University’s Cox School of Business.

Elements Image

Subscribe to our Blog

Get the latest articles and exclusive content delivered straight to your inbox. Join our community today—simply enter your email below!

Need help applying this to your CRM roadmap?

Talk to Vantage Point

Vantage Point helps regulated and growth-focused teams implement Salesforce, HubSpot, integrations, data migration, and managed services with practical, senior-led guidance.

Latest Articles

Third-Party Risk Guidance: The AI Inside Your Vendor Contracts

Third-Party Risk Guidance: The AI Inside Your Vendor Contracts

Regulators' Sept. 11 third-party risk proposal reframes vendor risk by AI exposure. See what banks and credit unions should do now.

MuleSoft + Informatica IDMC: Integration & Data Quality

MuleSoft + Informatica IDMC: Integration & Data Quality

Learn how MuleSoft and Informatica IDMC connect, clean, and govern Salesforce data for trusted Data Cloud and Agentforce initiatives.

Salesforce Is Going Slack-First. Compliance Should Notice

Salesforce Is Going Slack-First. Compliance Should Notice

Salesforce's Slack-first shift makes chat a books-and-records channel. What Slack Code means for retention, supervision, and e-discovery.