Scrutineer · By framework
Interagency guidance on third-party relationships software
The 2023 Interagency Guidance on Third-Party Relationships still governs bank vendor oversight. On September 15, 2026 the OCC, Fed, FDIC and NCUA proposed replacing it with a shorter, risk-based text that also covers credit unions. Comments close November 16, 2026.
Scrutineer tiers each vendor by risk and keeps the decision an examiner reads.
Control-mapped findings · linked evidence · you decide what to remediate
Interactive walkthrough on a sample company, not a scan of your systems.
›
Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with interagency TPRM guidance
The proposal retires "critical activities" and scores the relationship instead
The 2023 guidance asked banks to apply heavier oversight to third parties supporting "critical activities", and the final text uses that phrase nine times. The 2026 proposed text does not use it once. The agencies say the old test focused on the activity rather than on the relationship or the harm, so banks applied heightened diligence to relationships that posed little risk. The proposal replaces it with a two-part test: a relationship is higher risk when disruption, attack or breach of contract could cause a non-trivial violation of law, material financial harm or significant disruption to operations or customers, and there is a material likelihood of that happening. If your tiering questionnaire still asks "does this vendor support a critical activity", it answers a question the new text no longer asks.
Non-enforceable guidance still needs a file your examiner can read
The proposal says plainly that it sets no enforceable standards, that deviating from its examples is not by itself a basis for supervisory action, and that a missing contract term an examiner considers best practice is not enough for an adverse finding. That reads like less work. It moves the work instead. The agencies say they will give due consideration to a bank's reasonable decisions, and a decision is only reasonable to an examiner if it is written down: the risk assessment behind a tier, the diligence you could not get and what you relied on instead, and a new component the 2023 text did not have, residual risk acceptance, where you record which risks you chose to accept and why. The checklist shrinks. The reasoning you must be able to show grows.
Credit unions are in scope, and community banks under $30 billion get their own guide
The 2023 guidance came from the Fed, FDIC and OCC. The 2026 proposal adds the NCUA and defines banking organizations to include insured credit unions, so a credit union's vendor program now answers to the same interagency text. The Fed published a companion proposal the same day for traditional community banking organizations, meaning banks under $30 billion in assets that serve their local communities and do not run complex fintech partnerships. It walks through eight vendor categories: core providers, IT infrastructure, cybersecurity, payment processing and digital banking, loan management systems, card issuing and processing, BSA/AML and financial crime platforms, and fraud detection. Four considerations run across all of them: operational resilience, system and information security, compliance with rules, and financial resilience.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Scores each third-party relationship on magnitude and likelihood of harm, the two-part higher-risk test in the 2026 proposal, and keeps the rationale next to the tier
- Lets you keep low-risk relationships such as clerical, professional support and office support vendors out of the full assessment workflow, which the proposal explicitly allows
- Records the diligence you could not obtain, what you relied on instead (a SOC report, a certification, consortium results, public sources) and why that was enough
- Keeps a residual risk acceptance record for each higher-risk relationship, with the approver and date, so the decision exists before the exam rather than being reconstructed during it
- Pulls subservice organizations and complementary user entity controls out of vendor SOC 2 reports, so subcontractor risk is evidenced from documents you already hold
- Tracks contract review dates and flags relationships whose risk changed after a renegotiation, an incident or a change in services, the reassessment triggers the proposal names
- Maps your own controls to SOC 2, ISO 27001 and GLBA from the same library, so the bank's information security program and its vendor program draw on one evidence base
- Produces board and senior management reporting on higher-risk relationships from live data, one of the six governance practices the proposal lists
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
2023 guidance against the 2026 proposal
What changes for your third-party risk program if the proposal is finalized
Most summaries of the proposal list its principles. This table sets each part of a working TPRM program against the 2023 text that governs today and the 2026 proposed text, then names the record that carries you through either version. Read from the Federal Register documents 88 FR 37920 and FR Doc. 2026-18859.
| Program element | 2023 guidance (in force today) | 2026 proposal | Record that works under both |
|---|---|---|---|
| Who it covers | Banks supervised by the Fed, FDIC and OCC | Adds the NCUA and insured credit unions | One program description naming your regulator |
| Tiering | Heavier oversight for relationships supporting critical activities | Higher risk means magnitude and likelihood of a legal violation, material financial harm or significant disruption | A scored risk assessment per relationship, with the rationale |
| Inventory | A complete inventory, including related subcontractors as appropriate | May skip extensive inventories for low-risk clerical, professional and office support vendors | A full list, with low-risk vendors marked and not assessed in depth |
| Due diligence | Fourteen listed factors, from strategies and goals to contractual arrangements with other parties | Scaled to risk; alternative sources, consortia and certifications may be enough | Diligence performed, gaps, and the substitute evidence relied on |
| Contracts | Seventeen listed considerations, from right to audit to regulatory supervision | No generally applicable expected contract terms, even for higher-risk relationships | Terms negotiated, terms refused, and the risk accepted as a result |
| Subcontractors | Diligence and contract terms on reliance on subcontractors | Subcontractors alone do not create a separate relationship or presume direct oversight | Subservice organizations from each SOC report, reviewed at the primary vendor |
| Residual risk | Not a separate component | A named component: decide which risks to accept and on what information | A signed acceptance record for each higher-risk relationship |
| Governance | Board oversight, independent reviews, documentation and reporting | Six practices, including a periodic independent review of the program | Board reporting and the latest independent review on file |
Good questions
Questions about interagency TPRM guidance
Keep reading
Guides that go deeper on this framework
Vendor tiering
How to set the tiers the new magnitude and likelihood test asks for, and which vendors stay out of scope.
Read the guideFourth-party risk
Why the proposal stops presuming direct oversight of subcontractors, and what you still review.
Read the guideBest third-party risk management software
The TPRM platforms banks shortlist, compared by what each was first built to do.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification