Critical Service Provider Oversight After the OCC September 2026 Releases

Explore how banks can strengthen critical service provider oversight following the OCC’s September 2026 third-party risk releases.

 

The Office of the Comptroller of the Currency's (OCC) September 11, 2026 releases signal a more tailored approach to third-party risk management, alongside greater attention to core providers serving community banks. Leadership teams can use this opportunity to examine whether their oversight of critical service providers addresses the risks most consequential to their institution.

Our recommendation is to connect provider assessments to business service dependencies, evaluate the bank’s ability to recover or transition services, and make explicit decisions about the exposure that remains. The broader guidance is proposed; the separate core provider statement has been issued. That distinction matters when determining what to do now. 

The Business Issue

When a provider supports payment processing, account access, or another essential banking service, an interruption can quickly become a business problem. Risk leaders need to understand how that dependency affects their institution and which controls can realistically reduce the exposure.

A provider’s “critical” classification can trigger extensive reviews while leaving basic business questions unresolved. Which services would stop during an outage? Can the bank access the information it needs to assess recovery capability? Do contract terms give the institution workable options if performance deteriorates? These are the questions we recommend leadership teams bring into their oversight discussions.

For this article, critical service providers means providers whose disruption could materially affect a bank’s essential services. It is a practical description, not a new regulatory designation. The companion statement’s term “core providers” has a more specific context: providers of critical applications and infrastructure supporting community banks’ essential business functions.

Why It Matters

Through OCC Bulletin 2026-46, the OCC, Federal Reserve, FDIC, and NCUA proposed guidance emphasizing oversight proportionate to each third-party relationship’s assessed risk. The agencies intend to replace existing guidance when the proposal is finalized. The September 11 announcement itself did not finalize that replacement.

The proposal is supervisory guidance, not an enforceable rule. The OCC states that noncompliance with the guidance would not itself result in supervisory action. Banks remain responsible for safe and sound operations and compliance with applicable law.

The proposed guidance questions interpretations of the 2023 guidance that extended heightened oversight broadly based on “critical activities” without sufficiently considering the magnitude and likelihood of harm. It recognizes that core processing relationships will often be higher risk, while allowing for different assessments based on an institution’s circumstances.

Separately, OCC Bulletin 2026-47 announces an issued interagency statement on core providers serving community banking organizations. It explains factors the OCC, Federal Reserve, and FDIC will consider when supervising these providers and exercising their existing enforcement authorities.

The joint statement identifies three areas relevant to supervisory resource allocation:

  • Transparency, including access to relevant diligence information, measurable service levels, timely incident disclosures, and understandable billing.
  • Contract features, including opaque pricing, unsupported or undefined deconversion fees, and excessive restrictions on integration with other providers.
  • Technology, including security incidents, management of obsolete assets, and demonstrated operational resilience.

For bank leaders, these issues connect commercial decisions to operational exposure. Limited information can undermine a risk assessment, while restrictions on integration or exit can narrow the bank’s response options. The core provider statement does not guarantee regulatory intervention in a commercial dispute or transfer the bank’s accountability to its provider. Its supervisory focus concerns core providers serving community banks; the broader leadership recommendations below should be tailored to each institution.

What Leadership Teams Should Do Now

We recommend a focused review of the relationships with the greatest potential to disrupt essential services. The following actions are practical management recommendations, with scope and effort proportionate to the bank’s circumstances.

  1. Confirm the business exposure. Ask business owners and technology leaders to identify the services, customers, and obligations dependent on each selected provider. Include shared infrastructure and important subcontractor dependencies. Challenge classifications based primarily on spend, vendor size, or historical practice, and explain how the assessed impact and likelihood support the level of oversight.
  2. Resolve consequential information and contract gaps. Have risk, procurement, and legal teams identify missing evidence or contractual restrictions that prevent an informed decision. Prioritize access to relevant diligence information, measurable service commitments, incident communication, and workable transition terms. Where a gap cannot be resolved, identify alternative evidence or safeguards and bring the remaining exposure to the appropriate decision maker.
  3. Validate recovery and transition options. Ask operations and technology leaders to walk through a realistic disruption. Confirm whether workarounds can support actual transaction volumes and how long they can be sustained. Separately, assess the data, resources, contractual charges, and time needed to move services. Fund improvements where current assumptions leave an unacceptable business exposure.
  4. Make risk acceptance and escalation explicit. Assign an accountable executive to each consequential exposure. Management reporting should identify the decision required, the proposed action, and the conditions that would trigger reconsideration. Depending on the circumstances, that decision may involve remediation funding, renegotiation, a provider transition, or acceptance of a defined residual risk with a review date.

Begin with one consequential provider and convene the relationship owner and relevant specialists. Compare the assessment, contract, and recovery assumptions; resolve the most significant unanswered question; and use that experience to improve the wider program. This gives leadership a concrete starting point while the proposed guidance moves through the comment process.

Banks can also use concrete examples from that work to inform comments on the proposal. The Federal Register notice sets a November 16, 2026 comment deadline. Distinguish preparation for possible changes from any decision to revise existing policies before final guidance is issued.

Eliassen Group’s Risk and Compliance team supports governance and policy development, risk assessments, control design and testing, and issue remediation. Connect with our team to discuss how these capabilities can support a targeted review of your critical service provider relationships.  

 

Author

Carter Nokes

Senior Manager, Risk & Compliance Solutions

cnokes@eliassen.com

Carter Nokes | LinkedIn