Your Shred Company Isn't Your Core Processor, and the Agencies Agree
On September 15, the OCC, the Federal Reserve, the FDIC, and NCUA published proposed guidance on third-party risk management (91 FR 58536). If the agencies finalize it, it replaces the 2023 Interagency Guidance on Third-Party Relationships and the supplemental resources issued with it, including the 2024 third-party risk guide for community banks. Comments are due November 16, 2026.
Credit unions should look at whose names are on it. The Fed, FDIC, and OCC issued the 2023 guidance without NCUA. This time NCUA signed on, and footnote 1 defines "banking organizations" to include insured credit unions.
The direction is toward less work on low-risk vendors and away from checklists. For a credit union where one person runs vendor management alongside everything else, that's good news. It's also only a proposal, so the right response today is to read it, comment if you have something to say, and keep running your current program.
What the agencies say went wrong
The agencies say institutions read the 2023 guidance as a checklist, partly because its examples were overly detailed and its scenarios idealized. They say it pushed heightened oversight onto a wide range of relationships without regard to how much risk each one posed. They also say it implied "an impossible goal of risk elimination, rather than risk management" (58537-58538).
What the proposal says
The guidance is non-enforceable. Deviation from the guidance or its examples, even where an examiner thinks it runs contrary to best practices, "will not alone be a basis for supervisory action" (58540). The agencies keep their authority to act on violations of law, unsafe or unsound practices, and material risks from weak third-party risk management. The guidance won't be the hook for a finding, but a bad vendor outcome still can be.
The framework has four components: risk identification and assessment; risk oversight, which covers due diligence, contract negotiation, ongoing monitoring, and termination; residual risk acceptance; and governance (58539-58540).
Risk assessment drives the rest. The proposal describes higher-risk relationships using two tests together. The relationship could cause a non-trivial violation of law, material financial harm, or a significant operational disruption, and there must be a material likelihood that the harm occurs under current or reasonably foreseeable conditions (58540). A vendor that could do damage but probably won't doesn't clear both tests.
The inventory work shrinks. An institution may decide not to keep extensive inventories of relationships posing limited risk, such as clerical tasks, professional services like auditors and lawyers, and office support like physical security (58540). Footnote 9 says that where there is no written agreement, or no clear consideration, an activity is "unlikely to constitute a third-party relationship" (58539).
On contracts, the agencies write that "there are no generally applicable expected contract terms for third-party relationships," and they say this holds even for higher-risk relationships (58541). Standard form contracts may be sufficient for lower-risk vendors, and the absence of a term an examiner prefers would not alone support an adverse finding (58542).
The proposal also deals with the vendors you can't push around. It acknowledges limited negotiating power and third parties that won't permit on-site visits or share what you ask for. An institution can still proceed if it understands the risks and the residual risk is within its risk appetite and tolerances (58541-58542). That flexibility has a limit, because when a vendor won't provide information reasonably necessary for due diligence and monitoring, outside sources may not be enough to keep you within your appetite (58541). The residual risk section is blunt about the goal: "The agencies do not expect banking organizations to eliminate third-party risk" (58544).
Two more pieces help small shops. Shared due diligence through consortia, consultants, and certification organizations is explicitly allowed, and the agencies note that outside technology and expertise may let community banks in particular benefit from capabilities they couldn't build alone (58543). The governance practices include a risk appetite for third-party risk and periodic independent reviews of the program (58544).
Where credit unions are different
The proposal doesn't mention NCUA's own letters on third-party relationships, 07-CU-13 and 01-CU-20. The notice says the agencies plan to rescind and replace existing third-party guidance, and footnote 5 invites comment on what else should be rescinded, but it never says whether NCUA's letters are on that list. As of October 7, 2026, NCUA hasn't addressed the question. Until it does, your examiner still has those letters.
Some monitoring examples assume tools banks have and we don't. One is reviewing reports of examination from the agencies' supervision of certain large third parties (58542, footnote 17). NCUA has no comparable authority to examine credit union vendors, and credit unions can't obtain FFIEC service provider exam reports through NCUA. Footnote 17 does warn that relying on those reports without your own due diligence would be inconsistent with sound risk management, so banks can't lean on them much either.
What I'd do right now
Don't tear up your program. Keep running it to current NCUA expectations until the final guidance is out and NCUA explains how it fits with the letters. Rebuilding now and again after the final wastes a small staff's time.
Comment if you have something to say. I expect banks to dominate this docket, so a short letter from a credit union explaining how the guidance lands on a small shop will stand out. Footnote 5 is the place to ask NCUA what happens to 07-CU-13 and 01-CU-20. Footnote 15 asks whether the final should list characteristics of high-risk relationships, and you can say whether that would help you or box you in. NCUA's docket is NCUA-2026-1684 on regulations.gov.
Some steps make sense whatever the final says:
Write a short third-party risk appetite statement and take it to your board.
Document residual risk acceptance when a vendor won't give you what you ask for. Record what you requested, what you received, what compensates for the gap, and who accepted the risk.
Make sure someone independent, your Supervisory Committee or internal audit, reviews the program periodically.
Then take an honest look at scope. If your program applies full due diligence to every vendor, or runs the same contract checklist on your shred company and your core processor, the proposal tells you that's more than you need. You don't have to cut anything today, but you can start sorting which vendors deserve the effort.
A free starting point
If you want a program built around tiers, my Vendor Management Package is free to download and share on https://mycurisk.com/vendor. It sorts vendors into Critical, Important, and Incidental tiers, with due diligence that scales by tier. Important vendors split into Discretionary and Utility, so a dominant provider you can't negotiate with gets a review that fits the relationship. It also has a pathway for documenting gaps when a vendor won't provide an item. The tiered, risk-based design is consistent with the direction the agencies proposed, and I plan to update the package after the final guidance is published.
The views in this post are my own and do not represent the official position of Kings Federal Credit Union. This post discusses proposed guidance that may change before it is finalized, and it is not legal advice.

