Regulators Propose Rules to Help Community Banks Manage Vendor Risks

Regulators Propose Rules to Help Community Banks Manage Vendor Risks

2026-09-11 economy

Washington, Friday, 11 September 2026.
Federal banking regulators released new guidance on September 11, 2026, to help community banks manage risks with major technology providers and strengthen systemic financial stability.

Streamlining Supervisory Expectations

On September 11, 2026, federal banking regulators jointly requested public comment on proposed guidance designed to assist financial institutions in managing risks associated with third-party relationships [1]. The Federal Reserve Board, the Federal Deposit Insurance Corporation, the National Credit Union Administration, and the Office of the Comptroller of the Currency collectively aim to align supervisory expectations with the evolving risks of individual third-party relationships [1]. This proposed guidance adopts a principles-based approach and is intended to be non-binding, reflecting lessons learned from examining financial institutions’ third-party risk management practices [1]. Upon finalization, the agencies plan to rescind existing third-party risk management guidance to promote consistency and prudent innovation within the banking industry [1]. Comments on the proposed guidance are due 60 days after publication in the Federal Register [1]. Separately, the Federal Reserve Board requested comment on a proposed third-party risk management guide specifically for Federal Reserve-supervised community banks, serving as a companion document to the broader proposed guidance [1].

Concentration Risk in Focus

The urgency for robust third-party risk management is underscored by recent global infrastructure failures, such as the outage affecting Norway’s BankID digital identity service on September 3–4, 2026 [4]. This incident, the longest in two decades, impacted 4.2 million users and halted property sales, legal contracts, and government services for two days [4]. The service provider, DXC Technology, has managed BankID’s infrastructure since October 2021, marking the second multi-day national-scale failure caused by the provider in a five-year period [4]. Concentration risk was similarly highlighted in February 2024, when a cyberattack on the US clearinghouse Change Healthcare disrupted systems processing approximately 15 billion transactions annually [4]. Post-attack surveys conducted by the American Hospital Association revealed that 94% of nearly 1,000 surveyed hospitals experienced financial impact, while 60% faced revenue losses of at least $1 million per day [4]. The financial volatility associated with such disruptions is significant; UnitedHealth Group reported direct response and business-disruption costs of $872 million in Q1 2024, with full-year impacts estimated between $1.15 and $1.35 per share, a range difference of 0.2 [4].

Broader Regulatory Context

This initiative occurs amidst a wider regulatory push to modernize financial infrastructure and security standards. On September 8, 2026, the Office of the Comptroller of the Currency jointly issued answers to frequently asked questions regarding the use of government-issued verifiable digital credentials under the Customer Identification Program Rule [3]. This bulletin clarifies how banks may use state-issued mobile driver’s licenses and other digital credentials to comply with identification rules, applicable to all community banks [3]. Concurrently, discussions around tokenized deposits and blockchain ledgers are influencing deposit recordkeeping rules, with the FDIC proposing changes to permit FDIC insurance for tokenized deposits if adopted [2]. Regulatory attention also extends to security against advanced cryptographic attacks, following an Executive Order concerning security against advanced cryptographic attacks signed in June 2026, though the exact day is not specified in available text [alert! ‘exact day not specified in text’] [2]. Additionally, the FDIC has implemented a new two-phase deposit insurance application process, with Phase 1 requiring a 120-day review for contingent authorization [2]. These combined efforts indicate a comprehensive strategy to enhance operational resilience and mitigate systemic risks across critical financial technology infrastructure [1][2][3].

Sources


Banking Regulation Risk Management