US regulators want banks to stop following a checklist and start defending their own judgement on vendor risk, a shift now spreading well beyond American banking.
Key takeaways
- On 11 September 2026, the Federal Reserve, FDIC, OCC and NCUA proposed replacing 2023 third-party risk guidance with a single, principles-based framework for banks and credit unions.
- The new approach drops a one-size-fits-all checklist for oversight “proportionate to the risks” each vendor relationship presents, rather than a fixed uniform process.
- Global regulators, across all sectors, are moving the same way: the Basel Committee published its own principles-based third-party risk framework worldwide in December 2025.
- Principles-based does not mean lighter touch. Banks must still build a defensible, board-approved, evidence-backed risk-tiering rationale examiners can test.
Introduction: risk and compliance beyond the checklist
For the best part of 3 years, a compliance officer at a mid-sized US bank has had a simple, if joyless, answer to almost every question about vendor risk: follow the 2023 interagency guidance. It told her what to ask a critical supplier, how often to ask it, and what to file afterwards. It wasn’t inspiring, but it was defensible.
On 11 September 2026, the Federal Reserve, the FDIC, the OCC and the NCUA proposed taking that answer away. The 4 agencies want to rescind their 2023 guidance and replace it with something that sounds, initially, like less work: a principles-based framework that asks banks to size their oversight to the actual risk each vendor presents, rather than applying the same process to every supplier from a payroll provider to a core banking platform.
It is not less work. It is different work, and harder in some respects than the checklist it replaces. It reflects a shift that’s being seen globally by regulators in every sector: a move from prescribed process to defensible judgement.
What US banking regulators are proposing for third-party risk management
The proposal, published in the Federal Register on 15 September 2026 with comments due by 16 November, would formally rescind the 2023 Interagency Guidance on Third-Party Relationships: Risk Management and replace it with a shorter, principles-led document.
Its central claim is:
“There is no one-size-fits-all approach to effective risk management …[and]… each banking organization is responsible for operating in a safe and sound manner and adopting risk management practices that are best suited to managing the specific risks that it faces.”
Proposed Third-Party Risk Management Guidance, Federal Register, 15 September 2026
The proposal is explicit that oversight should be “proportionate to the risks [third-party relationships] present and consistent with the banking organization’s risk appetite and tolerances,” and that non-compliance with the guidance itself will not, on its own, be grounds for supervisory action. (Federal Register, 15 September 2026).
This doesn’t mean the checklist disappears entirely. Legal commentators have pointed out that the proposal still expects banks to maintain board-approved policies covering governance, due diligence, contracting, monitoring, documentation and termination, which is “substantially more concrete than simply telling banks to manage third-party risk.” What has changed is not whether a structured program is expected. It is who decides how intensively each vendor relationship gets scrutinized, and who has to defend that when a regulator asks.
Why principles-based oversight is harder for risk and compliance teams than it sounds
A prescriptive rule is relatively simple for a compliance function. Follow it, document that you followed it, and the conversation with an examiner is largely over. But a principles-based rule forces you to demonstrate that your own reasoning was sound.
That means an institution’s third-party risk program needs a documented, consistent methodology for deciding why one vendor sits in a high-scrutiny tier and another does not, built on evidence rather than instinct.
The change runs deeper than methodology. In a recent article on the trend towards principles-based regulation, CoreStream GRC explored how the onus is shifting onto GRC teams to connect their work directly to the organization’s goals: “If governance, risk and compliance exist only to avoid a fine, an organization has no compass once the fine-avoiding checklist disappears. If they exist to help the business achieve its goals with confidence, the compass still works.”
According to Paul Cadwallader, GRC Strategy Director at CoreStream GRC, there is also a strong commercial case for adopting value-based GRC:
“Value-based GRC is about enabling your investors to back you and help you move faster. Various stakeholders, including regulators, trust you because they know you’ll do the right thing and act with integrity; they’ve seen it and believe in your capability. Rather than hindering progress, these engaged parties actively support you, making processes and approvals significantly quicker.”
Paul Cadwallader, GRC Strategy Director, CoreStream GRC
Regulators are now formalizing the same evidence-of-integrity argument CoreStream GRC has been making to individual clients.
The practical risk is that a principles-based regime is mistaken for a lighter one; it isn’t. A blanket questionnaire sent to every vendor is, at least, consistent and easy to defend as “the process.”
CoreStream GRC has flagged the same false comfort in the narrower context of vendor certifications: a SOC 2 or ISO 27001 report proves controls exist within a defined scope, not that a vendor is secure everywhere else, as the education platform Instructure discovered when it was breached in May 2026 through a feature outside its audited scope. A certificate tells an examiner what was tested, not what was missed, and getting that wrong under a principles-based regime is more exposed than getting a checklist item wrong under a prescriptive one, because there is no fixed standard left to point to. There is only the institution’s own judgement, on the record.

The growing global movement towards a principles-based approach to risk management
This is not an isolated development in North America, nor is it confined to financial services regulation. Regulatory bodies around the globe are moving from prescription to principles.
In December 2025, the Basel Committee on Banking Supervision, the global standard-setter for bank regulation, finalized its own Principles for the Sound Management of Third-Party Risk, explicitly designed to “maintain sufficient flexibility to accommodate evolving practices and regulatory frameworks across jurisdictions” rather than prescribe a fixed process. 9 months later, 4 of the world’s most influential banking regulators have brought their own domestic guidance into line with that philosophy.
Under Article 4, the EU’s Digital Operational Resilience Act (DORA) already scales its expectations to a firm’s size and risk profile rather than applying identical rules to everyone.
In the UK, the Financial Conduct Authority simplified its Senior Managers and Certification Regime (SMCR), trading prescriptive requirements for a framework that still holds firms to account for outcomes.
In the EU, the Omnibus I Directive, adopted in February 2026, cut mandatory reporting data points under the Corporate Sustainability Reporting and Due Diligence Directives by around 70%, replacing prescriptive supply chain checks with a risk-based approach that lets companies “focus on the impacts most likely to occur and be most severe.”
And, back in the USA, the Department of Justice now judges a compliance program against 3 principles-based questions (whether it is well designed, applied in good faith, and actually works in practice), rather than a fixed list of policies.
Jurisdictions around the world are converging on the same basic instinct: a fixed rulebook can’t keep pace with how fast vendor relationships, technology and risk actually change, so the judgement has to sit with the regulated institution instead.
What risk and compliance teams should do now to achieve a principles-based approach
Third-party risk management teams preparing for the proposed rule change should consider 4 points:
- Audit your current tiering logic, not just your vendor list. Most third-party risk programs can produce a list of vendors and a risk rating. Far fewer can explain clearly why each rating was assigned, and whether the same logic was applied to every vendor in that tier. That explanation, not the rating itself, is what a principles-based examiner will test first.
- Build the evidence trail as you go, not after the fact. A defensible judgement needs a paper trail: the evidence considered, who approved the tier, and when it was last reviewed. Retrofitting that after an exam notice arrives is far harder than capturing it as each decision is made.
- Treat proportionality as an ongoing calibration, not a one-off classification. A vendor’s risk profile changes as its role, its sub-contractors and its financial position change. A tiering decision made at onboarding and never revisited is exactly the kind of static judgement a principles-based regime is designed to catch out.
- Choose technology that can flex with the methodology, not just the vendor list. A program built on a rigid, hard-coded workflow will struggle every time the risk-tiering approach itself needs to change. A bespoke, evidence-based approach to third-party risk calls for flexible, customizable technology, like CoreStream GRC, that can adapt as fast as the methodology behind it.
Conclusion: Compliance teams must build the methodology and mind-set for principle-based regulation
The Compliance Officer who once had a checklist to hide behind now has something more demanding: the obligation to show her own judgement was sound, every time, for every vendor. That is a harder standard to meet, but a more honest one, and it is spreading well beyond US banking.
Institutions that treat this as a one-off rewrite of a single guidance document will be back here again the next time a regulator updates its expectations. Institutions that build a genuinely evidence-based, adaptable risk-tiering methodology now will find the next shift far less disruptive than this one.
Perhaps more importantly, they will also be building a platform to align risk management and compliance with their organization’s strategic goals.
If you would like help building a third-party risk program that can defend its own judgement under a principles-based regime, and adapt as that regime keeps evolving, book a workshop with CoreStream GRC’s strategy team.
FAQ on US banking regulators’ move to principles-based risk management
Prescriptive guidance tells an organization exactly what steps to follow and in what order, so compliance can be shown by pointing to completed steps. Principles-based guidance instead sets out an outcome, such as risk being managed “proportionate to the risks presented,” and leaves the organization to decide, and defend, how it gets there. That shifts the burden of proof from following a process onto the organization’s own documented judgement.
Existing programs will not automatically become non-compliant overnight, and the proposal itself states that non-compliance with the guidance alone will not trigger supervisory action. In practice, though, institutions will need to show their risk-tiering decisions are evidenced, consistently applied and kept current, rather than simply pointing to completed checklist items carried over from the old guidance.
It applies directly to US banks and credit unions supervised by the Federal Reserve, FDIC, OCC and NCUA. But the same principles-based logic already underpins the Basel Committee’s global third-party risk framework and the proportionality built into the EU’s Digital Operational Resilience Act, so organizations well outside US banking are facing a similar regulatory shift.
It needs a consistent, written methodology explaining how tiers are assigned, the specific evidence behind each vendor’s rating, the name of who approved it, and a set schedule for revisiting that rating as the vendor’s own risk profile changes over time.


