Vendor management used to mean a contract in a file drawer and a renewal date circled on the calendar. Now it means SOC reports, risk tiers, contract reviews, and always feeling one step behind. Community bankers know vendor management can’t be treated as a side task, but that doesn’t make it any less overwhelming. It seems like every conversation about third-party risk comes with a warning about increased regulatory scrutiny, yet many institutions are still trying to sort out what really deserves their attention.
Third-Party Risk Management Covers Every Relationship
In June 2023, the Federal Reserve, the FDIC, and the OCC issued a single interagency framework designed to give clarity to existing third party risk management expectations that were scattered throughout several agency documents. The wording alone signaled a shift that you’ve likely felt over the last few years. The 2023 guidance used the term “third party” more than 260 times and “vendor” only a handful. It also widened the definition to cover any business relationship, whether there’s a signed contract or money changes hands, from a core processor down to a courier service. And nearly 70 percent of the guidance’s 160-plus statements addressed what happens before a relationship even started: planning, due diligence, and contract negotiation.
For a team already stretched thin, that redrew how much work had to happen before a new vendor’s solution could even be introduced. The expectations themselves weren’t new. Rather, they had been taking shape for years through FFIEC handbooks, agency guidance, and exam feedback. What was new was the clear requirement that every relationship had to be touched, and the specific (long) list of due diligence items.
What the 2026 Proposed Guidance Means for Banks and Credit Unions
The next shift is already on the table, and for you, it could be a welcome change. On September 11, 2026, the OCC, the Federal Reserve, the FDIC, and the NCUA jointly proposed new guidance for financial institutions that retains the risk management concepts but replaces the detailed 2023 framework with a more principles-based approach. It’s still just a proposal, with the comment period open into November, but two details stand out. It pulls credit unions into the same conversation as banks for the first time, instead of the separate NCUA letter that’s covered them since 2007. And it clarifies that not all third parties are created equal, and that institutions should put more oversight where the actual risk is highest rather than applying the same checklist everywhere.
This approach allows institutions to make “reasonable decisions” when determining the level of oversight each vendor requires. There is even reason to hope that institutions may be able to pare down their vendor inventories by taking a practical look at relationships that may not need to be included in a third-party risk management program.
A Vendor Manager’s Work is Never Done
Third-party management or vendor management, no matter what you call it, has been brought up in every compliance conversation with community bankers this year, usually in the same breath as staffing pressure. Due diligence requirements have increased, adding to the growing workload carried by existing staff. Documentation lives with the vendor, not the institution, so getting a SOC report or a signed contract means chasing someone who isn’t in a hurry. One banker described it plainly: a new vendor comes onboard, and the team is then tasked with piecing together exactly what was purchased, how it works, and what oversight will be needed going forward.
The challenges aren’t fading. The list of third parties keeps growing, risk assessments go stale faster than anyone expects, and renewal dates are tracked across multiple systems by different people who, in many cases, have full-time jobs outside of vendor management. But diligence is necessary. When a bank brings on a third party, it takes on that provider’s risks too. Regulators expect financial institutions to manage that inherited risk. And at most community financial institutions, keeping track of all of it falls to one or two people. When the person tracking vendor risk is also running three other programs, important things can get missed.
When Third-Party Vendor Oversight Falls Behind
It happens all the time. There are brighter burning fires. Documentation gets skipped. Risk tiers don’t get updated. That shows up exactly where you don’t want it: in an exam. And even as the conversation shifts toward a more risk-focused approach, letting vendor management slide will still create problems when examiners are asking questions. The other cost is quieter but just as real. Every hour spent chasing a vendor for a contract is an hour not spent on the lending decision, the product launch, or the strategic work that grows the bank.
What Good Oversight Actually Takes
None of this is easy, and it was never supposed to be. Vendor oversight done right takes people who read the fine print, ask vendors tough questions, and keep chasing a document until it arrives. Updating a risk tier honestly, instead of copying last year’s answer forward, requires discipline. Somebody also has to be willing to have the uncomfortable conversation with a vendor who isn’t holding up their end.
Community banking runs on this kind of unglamorous diligence. It doesn’t get headlines, and no one thanks you for the SOC report you tracked down in March. It shows up months later, in a clean exam and a board that trusts the numbers in front of them without asking twice.
Rather than treating every vendor the same, the proposed guidance encourages institutions to focus their efforts on where they will have the greatest impact. Look at your vendor list. Which vendors could do the most damage if they slipped? Which risk tiers haven’t changed in over a year? And if an examiner asked for the documents behind those tiers tomorrow, how long would it take to find them?
Keep Your Vendor Oversight Program Exam-Ready
We track vendor documents and renewal dates, keep your cybersecurity assessment, information security program, and business continuity plan current, and help you prepare for audits and board meetings, so your team can focus on the calls only you can make.

Sources:
- Federal Reserve Board – Agencies issue final guidance on third-party risk management
- FFIEC IT Examination Handbook InfoBase – II.C.20 Oversight of Third-Party Service Providers
- Third-Party Relationships: Interagency Guidance on Risk Management | OCC
- Federal Register : Proposed Interagency Guidance on Third-Party Relationships: Risk Management
- FDIC – Agencies Seek Comment on Proposed Third-Party Risk Management Guidance (Sept. 11, 2026):
- Federal Register – Proposed Third-Party Risk Management Guidance (Sept. 15, 2026):