DataVisuals The decision governance company Score your institution

Regulatory guidance on third-party risk management typically focuses on periodic reviews, governance committees, and risk assessment matrices — all of which depend on decisions that have already been made. The discipline lies upstream: capturing the vendor selection decision, the risk-tolerance approval, and the contract-renewal override as structured records at the moment of authorization, not as slide decks prepared for the board months later. When examiners probe a failed outsourcing relationship, they reconstruct the decision chain backward; institutions that engineer decision records forward — naming the approver, documenting the rationale, linking the evidence, and scheduling the review — avoid the narrative gaps that turn supervisory concerns into enforcement findings. Guidance is helpful; decision records are evidence.

From the FDIC release

PRESS RELEASE | SEPTEMBER 11, 2026 Agencies Seek Comment on Proposed Third-Party Risk Management Guidance and Issue Statement on Community Bank Engagement with Core Service Providers WASHINGTON— Today the Federal Deposit Insurance…

Read the original FDIC release →

Get these in your inbox.

The weekly executive summary — regulator actions scored for decision-governance relevance. Or follow daily via RSS.

Free. Only when there's activity — quiet weeks, no email.

← Back to all Watch items