On September 15, 2026, the Office of the Comptroller of the Currency (OCC), the Federal Reserve, the Federal Deposit Insurance Corporation (FDIC), and the National Credit Union Administration (NCUA) jointly published proposed guidance that would replace the 2023 interagency guidance on third-party risk management (TPRM). The stated goal is narrower, more risk-based oversight that promotes bank-fintech partnerships: the agencies say the 2023 guidance has often been read as a one-size-fits-all checklist, applied at the same intensity to a core processor and a facilities vendor alike, and that this has discouraged banks from partnering with newer, innovative third parties, including fintechs. Comments on the proposal are open through November 16, 2026.
One part of the proposal in particular makes room for exactly the kind of shared infrastructure this blog keeps arguing for.
The proposal explicitly discusses banks participating in co-ventures, consortia, or relying on standard-setting and certification organizations that issue assessments confirming a third party meets defined risk management and compliance standards. The agencies frame this as a legitimate way to gain efficiency, additional leverage in due diligence and monitoring, and access to expertise a bank couldn't build alone, particularly for community banks.
Co-ops and shared utilities have existed in banking for decades. What's new is four federal regulators stating clearly that shared infrastructure for managing third-party and data-sharing risk is a legitimate, recognized part of how this can work, not a workaround.
The proposal notes (footnote 12, page 20) that many third parties connect to a bank's systems through Application Programming Interfaces (APIs), vendor portals, or similar means, and that access alone doesn't automatically make a relationship higher risk. Where that access doesn't touch critical data and is properly segmented, the agencies say a bank may be able to manage the risk primarily through sound cybersecurity practices, rather than the full third-party risk management process built for vendors who are handling core operations or holding sensitive data on a bank's behalf. Full third-party risk management, as the guidance itself lays out, involves due diligence on a third party's financial condition and business practices, negotiated contract terms, ongoing performance monitoring, and termination planning. That process was built for outsourcing arrangements, where a bank hands off an operational function and needs assurance the third party can perform it. An API relationship built for consumer-permissioned data sharing is a different animal: the bank isn't outsourcing an activity, it's exposing a data connection. Treating both the same way is exactly the “overly broad” application the agencies say they're trying to correct.
For banks navigating open banking and open finance data-sharing arrangements, this is regulatory recognition that the risk profile of a data connection isn't the same as the risk profile of a vendor relationship, and shouldn't require the same oversight machinery.
This guidance sits underneath a bank's statutory obligations, not above them. A TPRM concern was never meant to be a reason to slow-walk data-sharing duties like those under Section 1033, and this proposal reinforces that hierarchy rather than complicating it. The comment window is open through November 16, 2026, and that's exactly the point where language like this gets sharpened or narrowed.
For an industry that has spent years arguing that data-sharing risk and outsourcing risk aren't the same thing, this is the moment to say so on the record.
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place.
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place.