On September 11, 2026, the Federal Reserve, FDIC, OCC, and NCUA proposed new, principles-based Third-Party Risk Management Guidance to replace the 2023 interagency guidance. The Fed, FDIC, and OCC also issued a statement on how community banks engage “core providers” — vendors running transaction processing, payments, compliance, and customer relationship management. The headline idea, risk-based tailoring, sounds like relief: fewer reviews for low-risk vendors. For most institutions, the honest version runs the other way — CRM vendor files are still graded on record-keeping, years before that CRM shipped AI reading member data and acting on it. A genuine re-grading moves that vendor up the list, not down. Comments on the proposal are due 60 days after Federal Register publication, scheduled for September 15, 2026, putting the deadline at approximately November 14, 2026.
The Fed, FDIC, OCC, and NCUA jointly requested comment on new Third-Party Risk Management Guidance — a principles-based framework replacing the 2023 interagency guidance. The goal: align oversight with each vendor's actual assessed risk, instead of running every vendor through the same checklist. A core processing provider will almost always land in the higher-risk tier; a back-office vendor can carry a lighter file.
Like the guidance it replaces, the proposal sets no enforceable standard — deviating from it is not itself a violation, though the agencies keep authority over unsafe practices tied to poor third-party oversight. The Fed separately proposed a narrower companion guide for its “traditional community banking organizations,” explicitly excluding banks with more complex arrangements such as bank-fintech partnerships — a gap Governor Barr flags in his dissent (below).
Both documents remain proposals; nothing changes in your exam obligations today. The Federal Register filing lists a scheduled publication date of September 15, 2026, with comments due 60 days after — see Timeline for the exact math.
September 11 also produced the Fed, FDIC, and OCC's Joint Statement on Community Banks' Engagement with Core Service Providers (NCUA is not a party, since it covers bank and thrift “community banking organizations,” not credit unions). Unlike the guidance, this statement is not out for comment — it took effect immediately and already shapes how examiners weigh a core provider relationship.
Core providers supply the critical systems behind a bank's lines of business, and the statement names the functions explicitly: transaction processing, account management, payments processing, customer relationship management, compliance and reporting, and online banking — CRM sits beside core processing and payments.
A handful of large providers dominate this market, the agencies note, limiting a community bank's negotiating leverage. Examiners will weigh three factors in supervising a core provider relationship:
| Factor | What the agencies will weigh | The question to ask your CRM or core vendor |
|---|---|---|
| Transparency | Willingness to share due-diligence information, service-level detail, and timely incident disclosure | Will the vendor document what its AI features do with your data, and tell you before that changes? |
| Contract features | Exit barriers, opaque pricing and billing, deconversion fees, restrictions on integrating outside tools | Can you audit, negotiate, or decline an AI feature the vendor turns on by default? |
| Technology | Security-incident history, handling of end-of-life systems, demonstrated resilience | Does the vendor's AI roadmap carry the same security and resilience commitments as its core platform? |
A core provider can, in some circumstances, also be treated as an “institution-affiliated party” under the Federal Deposit Insurance Act — meaning the provider itself, not just the bank, can face direct supervisory consequences.
This is written for community banks and, through the broader proposed guidance, credit unions — specifically COOs, chief compliance officers, and vendor-management owners who sign off on third-party risk assessments. If your institution runs core banking, lending, payments, or customer-facing operations through outside platforms, this proposal and statement already apply to your existing vendor relationships, not just future ones.
Risk-based tailoring is being framed, reasonably, as relief: fewer full-scope reviews for the physical-security vendor and the outside law firm, more attention where it belongs. Most vendor-management teams will read that as “do less” across the board.
For any vendor that has shipped embedded AI in the last 18 months, the honest exercise runs the opposite way. Take the CRM: most vendor files still carry it as one line item, risk-graded years ago against what it did then — store contact records, log service notes, route cases to a queue. That grade predates the vendor's own roadmap. Today the same platform likely ships an AI layer reading member or account PII, drafting outbound communications, and increasingly acting — flagging accounts, triaging cases, updating records — without a person reviewing every step. The core-provider statement's own definition puts customer relationship management beside transaction processing and payments; if your CRM is central to servicing or online banking, it likely meets the agencies' test for a core provider.
A genuinely risk-based re-grading moves that vendor up the list the moment its AI starts acting on regulated data unattended. That is not a reason to rip out a CRM — it is a reason to re-rate the vendor against what it does today, not what it did when the contract was signed.
September 11, 2026: The Fed, FDIC, OCC, and NCUA request comment on the proposed guidance; the Fed separately proposes its community bank companion guide; the Fed, FDIC, and OCC issue the core-provider statement, effective immediately.
September 15, 2026 (scheduled): Federal Register publication of both proposals (OCC Docket OCC-2026-0793; Fed Docket OP-1881; FDIC RIN 3064-ZA58; NCUA Docket NCUA-2026-1684).
On or around November 14, 2026: The 60-day comment window closes, 60 days from the scheduled September 15 publication. That date falls on a Saturday, so plan to submit by Friday, November 13.
After the comment period: The agencies finalize the guidance on no set date. Governor Barr's dissent — warning that the “material financial risk” trigger could make examiners slower to flag problems, and that excluding consumer compliance matters could leave a gap — suggests the final text may get more specific, not less.
Vantage Point helps community banks and credit unions get two things right: an honestly risk-graded vendor inventory, and a CRM platform — Salesforce, HubSpot, or otherwise — built to survive that grading. Our compliance and security solutions practice runs the vendor and permissions review, mapping which relationships now meet the core-provider test and where AI features have outgrown the contract's access and audit controls. Our Salesforce implementation and advisory team then closes the gaps. Senior consultants only — no junior handoffs; the experts you meet are the experts who deliver.
In one anonymized engagement, Vantage Point rebuilt the Salesforce Financial Services Cloud architecture for a $2.25 billion community bank, cutting manual data entry 93% and processing time 50% while building the audit trail examiners ask for — a 340% ROI within 18 months. See the case study. For related reading, see our guides to reducing Salesforce compliance risk in banks and Agentforce financial services compliance.
The comment window is open and the core-provider statement already applies. Vantage Point's senior consultants can review your CRM and core vendor contracts against the agencies' three factors and help prioritize the clauses worth renegotiating first. Contact Vantage Point to schedule a vendor-risk review, or explore our compliance and security services.
The Fed, FDIC, OCC, and NCUA proposed principles-based Third-Party Risk Management Guidance to replace the 2023 interagency guidance, asking banks and credit unions to align vendor oversight with each vendor's actual assessed risk rather than uniform reviews. The Fed also proposed a companion guide for its community banks, and the Fed, FDIC, and OCC issued a related statement on core service providers.
No. It is a proposal open for public comment, not a binding rule — deviating from it is not itself a violation, though examiners can still act on unsafe practices tied to weak third-party oversight. Comments are due 60 days after Federal Register publication.
The Federal Register public-inspection filing lists a scheduled publication date of September 15, 2026. Sixty days from that date puts the deadline at approximately November 14, 2026, a Saturday — plan to submit by Friday, November 13, 2026.
A statement issued the same day by the Fed, FDIC, and OCC (not NCUA, since it covers community banking organizations, not credit unions) on how examiners weigh a core provider's transparency, contract terms, and technology. It took effect immediately and defines core providers as vendors delivering transaction processing, account management, payments, customer relationship management, compliance and reporting, or online banking.
Neither document uses the word AI. The connection is the core-provider statement's own definition, which lists customer relationship management among the functions that can make a vendor a core provider. Vantage Point's read: CRM and other vendors that added AI features reading regulated data should be treated as higher-risk than their files reflect, not lower.
Barr argued a new material financial risk threshold could make examiners slower to flag problems while they are still small, and that both proposals exclude consumer compliance matters, risking a gap once existing guidance is rescinded. His dissent says the proposals could weaken oversight, not that they go too far.
Re-run its risk assessment against what it does today, not what it did at signing, and test it against the core-provider definition. If it qualifies, prioritize audit rights over the AI feature's data use, advance notice before the vendor changes or defaults-on a model, and data-residency commitments for wherever the AI processing happens.
This article is regulatory analysis for planning purposes and is not legal advice. Confirm specific obligations and comment-filing details with counsel and your primary regulator before acting.
Vantage Point is a boutique CRM consulting firm helping businesses transform with Salesforce, HubSpot, and AI — 150+ clients, 400+ engagements, and a 4.71/5 average engagement rating. Learn more at vantagepoint.io.