Press Release: Agencies Seek Comment on Proposed Third-Party Risk Management Guidance and Issue Statement on Community Bank Engagement with Core Service Providers
FDIC · 2026-09-11 · Decision-governance relevance 2/5
Regulatory guidance on third-party risk management typically focuses on periodic reviews, governance committees, and risk assessment matrices — all of which depend on decisions that have already been made. The discipline lies upstream: capturing the vendor selection decision, the risk-tolerance approval, and the contract-renewal override as structured records at the moment of authorization, not as slide decks prepared for the board months later. When examiners probe a failed outsourcing relationship, they reconstruct the decision chain backward; institutions that engineer decision records forward — naming the approver, documenting the rationale, linking the evidence, and scheduling the review — avoid the narrative gaps that turn supervisory concerns into enforcement findings. Guidance is helpful; decision records are evidence.
From the FDIC release
PRESS RELEASE | SEPTEMBER 11, 2026 Agencies Seek Comment on Proposed Third-Party Risk Management Guidance and Issue Statement on Community Bank Engagement with Core Service Providers WASHINGTON— Today the Federal Deposit Insurance…
Get these in your inbox.
The weekly executive summary — regulator actions scored for decision-governance relevance. Or follow daily via RSS.
Free. Only when there's activity — quiet weeks, no email.