The Office of the Comptroller of the Currency's (OCC) September 11, 2026 releases signal a more tailored approach to third-party risk management, alongside greater attention to core providers serving community banks. Leadership teams can use this opportunity to examine whether their oversight of critical service providers addresses the risks most consequential to their institution.
Our recommendation is to connect provider assessments to business service dependencies, evaluate the bank’s ability to recover or transition services, and make explicit decisions about the exposure that remains. The broader guidance is proposed; the separate core provider statement has been issued. That distinction matters when determining what to do now.
When a provider supports payment processing, account access, or another essential banking service, an interruption can quickly become a business problem. Risk leaders need to understand how that dependency affects their institution and which controls can realistically reduce the exposure.
A provider’s “critical” classification can trigger extensive reviews while leaving basic business questions unresolved. Which services would stop during an outage? Can the bank access the information it needs to assess recovery capability? Do contract terms give the institution workable options if performance deteriorates? These are the questions we recommend leadership teams bring into their oversight discussions.
For this article, critical service providers means providers whose disruption could materially affect a bank’s essential services. It is a practical description, not a new regulatory designation. The companion statement’s term “core providers” has a more specific context: providers of critical applications and infrastructure supporting community banks’ essential business functions.
Through OCC Bulletin 2026-46, the OCC, Federal Reserve, FDIC, and NCUA proposed guidance emphasizing oversight proportionate to each third-party relationship’s assessed risk. The agencies intend to replace existing guidance when the proposal is finalized. The September 11 announcement itself did not finalize that replacement.
The proposal is supervisory guidance, not an enforceable rule. The OCC states that noncompliance with the guidance would not itself result in supervisory action. Banks remain responsible for safe and sound operations and compliance with applicable law.
The proposed guidance questions interpretations of the 2023 guidance that extended heightened oversight broadly based on “critical activities” without sufficiently considering the magnitude and likelihood of harm. It recognizes that core processing relationships will often be higher risk, while allowing for different assessments based on an institution’s circumstances.
Separately, OCC Bulletin 2026-47 announces an issued interagency statement on core providers serving community banking organizations. It explains factors the OCC, Federal Reserve, and FDIC will consider when supervising these providers and exercising their existing enforcement authorities.
The joint statement identifies three areas relevant to supervisory resource allocation:
For bank leaders, these issues connect commercial decisions to operational exposure. Limited information can undermine a risk assessment, while restrictions on integration or exit can narrow the bank’s response options. The core provider statement does not guarantee regulatory intervention in a commercial dispute or transfer the bank’s accountability to its provider. Its supervisory focus concerns core providers serving community banks; the broader leadership recommendations below should be tailored to each institution.
We recommend a focused review of the relationships with the greatest potential to disrupt essential services. The following actions are practical management recommendations, with scope and effort proportionate to the bank’s circumstances.
Begin with one consequential provider and convene the relationship owner and relevant specialists. Compare the assessment, contract, and recovery assumptions; resolve the most significant unanswered question; and use that experience to improve the wider program. This gives leadership a concrete starting point while the proposed guidance moves through the comment process.
Banks can also use concrete examples from that work to inform comments on the proposal. The Federal Register notice sets a November 16, 2026 comment deadline. Distinguish preparation for possible changes from any decision to revise existing policies before final guidance is issued.
Eliassen Group’s Risk and Compliance team supports governance and policy development, risk assessments, control design and testing, and issue remediation. Connect with our team to discuss how these capabilities can support a targeted review of your critical service provider relationships.
Carter Nokes
Senior Manager, Risk & Compliance Solutions