Agencies Seek Comment on Proposed Third-Party Risk Management Guidance and Issue Statement on Community Bank Engagement with Core Service Providers
NCUA · 2026-09-11 · Decision-governance relevance 2/5
Vendor risk management collapses into checkbox compliance when institutions treat vendor decisions as procurement events rather than governance decisions requiring durable records. The guidance implicitly acknowledges that vendor failures trace to missing selection rationale, absent monitoring ownership, and undocumented continuation decisions at renewal points. Core service providers represent apex dependency decisions—each reliance decision, each access grant, each data-sharing approval demands a named owner and recorded rationale produced at the moment of commitment, not reconstructed during examination. Decisions deserve engineering rigor, especially when a single vendor can cascade risk across an entire institution.
From the NCUA release
FFIEC/Joint Agency
Get these in your inbox.
The weekly executive summary — regulator actions scored for decision-governance relevance. Or follow daily via RSS.
Free. Only when there's activity — quiet weeks, no email.