Daily Hypernovelty Lead — Money rails — September 15, 2026

The Residual Risk Stayed With the Bank

Proposed interagency third-party guidance keeps leftover risk with the bank. A vendor exam report is not a substitute.

A bank operations desk at dusk with an open vendor binder, a stamped report to one side, and an unsigned residual-risk line on a paper form.

The leftover is still the bank's. A borrowed exam report is not the showing.

A banking organization has ultimate responsibility to establish and maintain sound risk management practices and comply with applicable laws and regulations, and its use of third parties does not diminish that responsibility to the same extent as if the activities were performed internally, according to proposed interagency third-party risk management guidance the Office of the Comptroller of the Currency, the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, and the National Credit Union Administration published in the Federal Register on September 15, 2026 as document 2026-18859 (91 FR 58536).[1][2] The ACTION line is proposed interagency guidance and a request for comment. Comments must be received on or before November 16, 2026.[1] FederalRegister.gov is an unofficial XML copy, so anyone who needs legal notice should use the official edition on govinfo.[1][2]

That duty still applies after the work has moved. It covers affiliates, highly regulated service providers, and subcontractors, and it covers the case where elements of the banking organization's own risk management practices are performed by a third party.[1] The use of subcontractors alone does not typically create an independent third-party relationship or a presumption of direct oversight of those subcontractors.[1] The proposed text does not set enforceable standards. Non-compliance with the guidance would not, by itself, result in supervisory action. The Office of Information and Regulatory Affairs determined the proposal is not a significant regulatory action under section 3(f) of Executive Order 12866.[1]

So the 2023 document remains in force until a finalization replaces it. If the agencies finalize this proposal, it would replace the June 9, 2023 Interagency Guidance on Third-Party Relationships: Risk Management (88 FR 37920) and the supplemental resources named in the notice.[1] The agencies write that, based on stakeholder feedback and supervisory experience, the 2023 guidance frequently has been interpreted in an overly broad manner and with an insufficient focus on tailoring. Banking organizations have reported struggling to see which of a long list of considerations apply to core providers, fintechs, or facilities maintenance vendors. Heightened oversight of relationships supporting "critical activities" has, they say, been focused more on the activity than on the magnitude and likelihood of harm. Example language using "should" has been read as a requirement. The 2023 guidance has also been read to discourage arrangements with newer third parties because it indicates they may present elevated risks.[1]

The proposed text then names residual risk, the risk remaining after mitigating measures. The agencies treat acceptance of that leftover as a component of the work. They do not expect banking organizations to eliminate third-party risk. Some residual risk is unavoidable, including when a banking organization lacks bargaining power to get the due diligence, contract terms, or monitoring it wants, or when alternative options are limited.[1] The relationships include core processors, cloud processing and storage, compliance tools, and fintech partners that provide access to financial services.[1]

Two footnotes then block a shortcut that would skip that leftover. Footnote 14 says no supervisory or regulatory agency is responsible for a banking organization's third-party risk management, and that banking organizations should not rely on a third party being supervised as a substitute for managing that risk.[1] Footnote 17, citing 12 U.S.C. 1464(d)(7)(D) and 1867(c)(1), says reports of examination of certain large third parties are not tailored to any individual banking organization, may be targeted rather than comprehensive, are the property of the agencies, and are not a proxy or substitute for independent due diligence.[1]

The same day's Board-only companion, document 2026-18852 published as 91 FR 58438, Docket OP-1880, is a proposed guide for traditional community banking organizations with less than $30 billion in assets that focus on serving their local communities.[3][4] Comments on that guide are also due November 16, 2026. It would not be a rule, and it is not intended for complex bank-fintech partnerships in which a fintech, rather than the bank, markets, distributes, or otherwise provides access to the products or services.[3] This remains proposed guidance. It does not decide a named vendor file, and it is not legal, compliance, banking, or investment advice.

Verification bottleneck

This scarce check is whether a named third-party relationship file can show independent due diligence and a residual-risk decision, before anyone treats an agency exam report of the vendor, or the fact that the vendor is regulated, as that showing.

  • Work can already live at a core processor, a cloud provider, a compliance tool, or a fintech partner. The proposed text still puts the duty on the banking organization.
  • Boards, examiners, and later commenters would have to verify which relationship was assessed, what harm was judged material and likely, what residual risk was accepted, and whether a borrowed exam report was used as a stand-in.
  • Watch the November 16, 2026 comment deadline, whether any finalized text actually replaces 88 FR 37920, and whether the Board under-$30 billion guide stays out of complex bank-fintech partnerships.

Opportunities

Where value may appear is a one-relationship residual-risk worksheet. For a single vendor it would record the product or service, whether the work lives inside or at the vendor, any subcontractors, what due diligence was obtained, what bargaining power blocked, whether an agency exam report of the vendor is in the file, what residual risk was accepted and by whom, and whether the Board community-bank guide even applies. Legal conclusions stay with qualified counsel. Idea fodder only.

Sources

[1] Office of the Comptroller of the Currency, Board of Governors of the Federal Reserve System, Federal Deposit Insurance Corporation, and National Credit Union Administration, "Proposed Third-Party Risk Management Guidance," 91 FR 58536, September 15, 2026, FR Doc. 2026-18859. https://www.federalregister.gov/documents/2026/09/15/2026-18859/proposed-third-party-risk-management-guidance

[2] Official PDF, 91 FR 58536. https://www.govinfo.gov/content/pkg/FR-2026-09-15/pdf/2026-18859.pdf

[3] Board of Governors of the Federal Reserve System, "Proposed Third-Party Risk Management Guide for Traditional Community Banking Organizations," 91 FR 58438, September 15, 2026, FR Doc. 2026-18852, Docket No. OP-1880. https://www.federalregister.gov/documents/2026/09/15/2026-18852/proposed-third-party-risk-management-guide-for-traditional-community-banking-organizations

[4] Official PDF, 91 FR 58438. https://www.govinfo.gov/content/pkg/FR-2026-09-15/pdf/2026-18852.pdf