Skip to content
Navanta logo
  • 877-778-7774
  • Support
    • Our Story
    • Our People
    • Join Our Team
    • View All Solutions
    • Core Banking
    • Managed IT
      • Bankers Private Cloud
      • Bankers Essentials
      • Cyberthreats
      • M365 Management
    • CRM
    • Advisory
      • Risk Management
      • Virtual CIO
      • Virtual ISO
      • Security Awareness Training
    • View All Resources
    • Articles
    • CEO Update
    • Client Spotlight
      • Core Banking
      • CRM
      • Cyberthreats
      • Exams & Audits
      • Information Security
      • Managed IT
    • Navanta in the News
    • Upcoming Events
    • Recorded Webinars
  • Brand FAQs
  • Contact Us
      • Our Story
      • Our People
      • Join Our Team
      • View All Solutions
      • Core Banking

        Keep community focus with a core that runs reliably.

      • Managed IT

        Simplify banking IT with one trusted partner.

      • CRM

        Know every customer. Grow every relationship

      • Advisory

        Navigate IT and risk with clarity and confidence.

      • Have something in mind?
        Bankers Private Cloud
      • Bankers Essentials
      • Cyberthreats
      • M365 Management
      • Risk Management
      • Virtual CIO
      • Virtual ISO
      • Security Awareness Training
      • View All Resources
      • Browse By Type
        Articles
      • CEO Update
      • Client Spotlight
      • Navanta in the News
      • Upcoming Events
      • Recorded Webinars
      • Browse by Topic
        Core Banking
      • CRM
      • Cyberthreats
      • Exams & Audits
      • Information Security
      • Managed IT
  • Brand FAQs
  • Contact Us
Articles

Refocusing Third-Party Oversight on the Risks That Matter Most

September 30, 2026

  • EXAMS & AUDITS
  • RISK MANAGEMENT
  • STRATEGIC PLANNING
  • THIRD-PARTY VENDOR

Vendor management used to mean a contract in a file drawer and a renewal date circled on the calendar. Now it means SOC reports, risk tiers, contract reviews, and always feeling one step behind. Community bankers know vendor management can’t be treated as a side task, but that doesn’t make it any less overwhelming. It seems like every conversation about third-party risk comes with a warning about increased regulatory scrutiny, yet many institutions are still trying to sort out what really deserves their attention.

Third-Party Risk Management Covers Every Relationship

In June 2023, the Federal Reserve, the FDIC, and the OCC issued a single interagency framework designed to give clarity to existing third party risk management expectations that were scattered throughout several agency documents. The wording alone signaled a shift that you’ve likely felt over the last few years. The 2023 guidance used the term “third party” more than 260 times and “vendor” only a handful. It also widened the definition to cover any business relationship, whether there’s a signed contract or money changes hands, from a core processor down to a courier service. And nearly 70 percent of the guidance’s 160-plus statements addressed what happens before a relationship even started: planning, due diligence, and contract negotiation.

For a team already stretched thin, that redrew how much work had to happen before a new vendor’s solution could even be introduced. The expectations themselves weren’t new. Rather, they had been taking shape for years through FFIEC handbooks, agency guidance, and exam feedback. What was new was the clear requirement that every relationship had to be touched, and the specific (long) list of due diligence items.

What the 2026 Proposed Guidance Means for Banks and Credit Unions

The next shift is already on the table, and for you, it could be a welcome change. On September 11, 2026, the OCC, the Federal Reserve, the FDIC, and the NCUA jointly proposed new guidance for financial institutions that retains the risk management concepts but replaces the detailed 2023 framework with a more principles-based approach. It’s still just a proposal, with the comment period open into November, but two details stand out. It pulls credit unions into the same conversation as banks for the first time, instead of the separate NCUA letter that’s covered them since 2007. And it clarifies that not all third parties are created equal, and that institutions should put more oversight where the actual risk is highest rather than applying the same checklist everywhere.

This approach allows institutions to make “reasonable decisions” when determining the level of oversight each vendor requires. There is even reason to hope that institutions may be able to pare down their vendor inventories by taking a practical look at relationships that may not need to be included in a third-party risk management program.

A Vendor Manager’s Work is Never Done

Third-party management or vendor management, no matter what you call it, has been brought up in every compliance conversation with community bankers this year, usually in the same breath as staffing pressure. Due diligence requirements have increased, adding to the growing workload carried by existing staff. Documentation lives with the vendor, not the institution, so getting a SOC report or a signed contract means chasing someone who isn’t in a hurry. One banker described it plainly: a new vendor comes onboard, and the team is then tasked with piecing together exactly what was purchased, how it works, and what oversight will be needed going forward.

The challenges aren’t fading. The list of third parties keeps growing, risk assessments go stale faster than anyone expects, and renewal dates are tracked across multiple systems by different people who, in many cases, have full-time jobs outside of vendor management. But diligence is necessary. When a bank brings on a third party, it takes on that provider’s risks too. Regulators expect financial institutions to manage that inherited risk. And at most community financial institutions, keeping track of all of it falls to one or two people. When the person tracking vendor risk is also running three other programs, important things can get missed.

When Third-Party Vendor Oversight Falls Behind

It happens all the time. There are brighter burning fires. Documentation gets skipped. Risk tiers don’t get updated. That shows up exactly where you don’t want it: in an exam. And even as the conversation shifts toward a more risk-focused approach, letting vendor management slide will still create problems when examiners are asking questions. The other cost is quieter but just as real. Every hour spent chasing a vendor for a contract is an hour not spent on the lending decision, the product launch, or the strategic work that grows the bank.

What Good Oversight Actually Takes

None of this is easy, and it was never supposed to be. Vendor oversight done right takes people who read the fine print, ask vendors tough questions, and keep chasing a document until it arrives. Updating a risk tier honestly, instead of copying last year’s answer forward, requires discipline. Somebody also has to be willing to have the uncomfortable conversation with a vendor who isn’t holding up their end.

Community banking runs on this kind of unglamorous diligence. It doesn’t get headlines, and no one thanks you for the SOC report you tracked down in March. It shows up months later, in a clean exam and a board that trusts the numbers in front of them without asking twice.

Rather than treating every vendor the same, the proposed guidance encourages institutions to focus their efforts on where they will have the greatest impact. Look at your vendor list. Which vendors could do the most damage if they slipped? Which risk tiers haven’t changed in over a year? And if an examiner asked for the documents behind those tiers tomorrow, how long would it take to find them?

Keep Your Vendor Oversight Program Exam-Ready

We track vendor documents and renewal dates, keep your cybersecurity assessment, information security program, and business continuity plan current, and help you prepare for audits and board meetings, so your team can focus on the calls only you can make.

Explore Our Risk Management Support

Sources:

  • Federal Reserve Board – Agencies issue final guidance on third-party risk management
  • FFIEC IT Examination Handbook InfoBase – II.C.20 Oversight of Third-Party Service Providers
  • Third-Party Relationships: Interagency Guidance on Risk Management | OCC
  • Federal Register : Proposed Interagency Guidance on Third-Party Relationships: Risk Management
  • FDIC – Agencies Seek Comment on Proposed Third-Party Risk Management Guidance (Sept. 11, 2026):
  • Federal Register – Proposed Third-Party Risk Management Guidance (Sept. 15, 2026):

Join the Navanta Navigators Brief

Insights for community bankers navigating technology, security, and growth.

More in Exams & Audits

  • Laptop with magnifying glass for Cyber Risk Assessment
    ARTICLES

    A Guide to Selecting the Right Replacement for the FFIEC CAT

    Read the Article
  • ARTICLES

    Enhance Risk Management with Key Takeaways from the FFIEC DA&M Booklet

    Read the Article
  • AI and Copilot in Banking Webinar Series hosted by Navanta
    RECORDED WEBINARS

    AI and Copilot in Banking: Making Strategic Decisions with Confidence – Two Part Webinar Series

    Watch the Recordings
White Navanta logo
  • Linkedin
  • Get to Know Us
    • Our Story
    • Our People
    • Join Our Team
  • Find Your Solution
    • Core Banking
    • Managed IT
    • CRM
    • Advisory
  • Explore Resources
    • Articles
    • Client Spotlight
    • Events & Webinars
  • Contact Us
    • 877-778-7774
    • [email protected]

  • 877-778-7774
  • Support
  • Privacy Policy
© 2026 Navanta
Contact Us

Client Login

  • MyBPC

    Previously MyBankonIT. Log in here to access your client portal for Bankers Private Cloud.

    Sign In

  • theSafeTM

    Sign in here to access your account information and resources in theSafe as usual.

    Sign In

  • Navanta CRM

    Previously Quest Analytics IQCRM. Continue to use these existing CRM links:

    Product Updates Technical Requirements CRM Email Support