Scrutineer.ai

Scrutineer · By framework

Interagency guidance on third-party relationships software

The 2023 Interagency Guidance on Third-Party Relationships still governs bank vendor oversight. On September 15, 2026 the OCC, Fed, FDIC and NCUA proposed replacing it with a shorter, risk-based text that also covers credit unions. Comments close November 16, 2026.

Scrutineer tiers each vendor by risk and keeps the decision an examiner reads.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Interactive walkthrough on a sample company, not a scan of your systems.

Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with interagency TPRM guidance

The proposal retires "critical activities" and scores the relationship instead

The 2023 guidance asked banks to apply heavier oversight to third parties supporting "critical activities", and the final text uses that phrase nine times. The 2026 proposed text does not use it once. The agencies say the old test focused on the activity rather than on the relationship or the harm, so banks applied heightened diligence to relationships that posed little risk. The proposal replaces it with a two-part test: a relationship is higher risk when disruption, attack or breach of contract could cause a non-trivial violation of law, material financial harm or significant disruption to operations or customers, and there is a material likelihood of that happening. If your tiering questionnaire still asks "does this vendor support a critical activity", it answers a question the new text no longer asks.

Non-enforceable guidance still needs a file your examiner can read

The proposal says plainly that it sets no enforceable standards, that deviating from its examples is not by itself a basis for supervisory action, and that a missing contract term an examiner considers best practice is not enough for an adverse finding. That reads like less work. It moves the work instead. The agencies say they will give due consideration to a bank's reasonable decisions, and a decision is only reasonable to an examiner if it is written down: the risk assessment behind a tier, the diligence you could not get and what you relied on instead, and a new component the 2023 text did not have, residual risk acceptance, where you record which risks you chose to accept and why. The checklist shrinks. The reasoning you must be able to show grows.

Credit unions are in scope, and community banks under $30 billion get their own guide

The 2023 guidance came from the Fed, FDIC and OCC. The 2026 proposal adds the NCUA and defines banking organizations to include insured credit unions, so a credit union's vendor program now answers to the same interagency text. The Fed published a companion proposal the same day for traditional community banking organizations, meaning banks under $30 billion in assets that serve their local communities and do not run complex fintech partnerships. It walks through eight vendor categories: core providers, IT infrastructure, cybersecurity, payment processing and digital banking, loan management systems, card issuing and processing, BSA/AML and financial crime platforms, and fraud detection. Four considerations run across all of them: operational resilience, system and information security, compliance with rules, and financial resilience.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Scores each third-party relationship on magnitude and likelihood of harm, the two-part higher-risk test in the 2026 proposal, and keeps the rationale next to the tier
  • Lets you keep low-risk relationships such as clerical, professional support and office support vendors out of the full assessment workflow, which the proposal explicitly allows
  • Records the diligence you could not obtain, what you relied on instead (a SOC report, a certification, consortium results, public sources) and why that was enough
  • Keeps a residual risk acceptance record for each higher-risk relationship, with the approver and date, so the decision exists before the exam rather than being reconstructed during it
  • Pulls subservice organizations and complementary user entity controls out of vendor SOC 2 reports, so subcontractor risk is evidenced from documents you already hold
  • Tracks contract review dates and flags relationships whose risk changed after a renegotiation, an incident or a change in services, the reassessment triggers the proposal names
  • Maps your own controls to SOC 2, ISO 27001 and GLBA from the same library, so the bank's information security program and its vendor program draw on one evidence base
  • Produces board and senior management reporting on higher-risk relationships from live data, one of the six governance practices the proposal lists
interagency TPRM guidance readiness_report
Readiness 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Every finding links to the evidence behind it

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

2023 guidance against the 2026 proposal

What changes for your third-party risk program if the proposal is finalized

Most summaries of the proposal list its principles. This table sets each part of a working TPRM program against the 2023 text that governs today and the 2026 proposed text, then names the record that carries you through either version. Read from the Federal Register documents 88 FR 37920 and FR Doc. 2026-18859.

Program element 2023 guidance (in force today) 2026 proposal Record that works under both
Who it covers Banks supervised by the Fed, FDIC and OCC Adds the NCUA and insured credit unions One program description naming your regulator
Tiering Heavier oversight for relationships supporting critical activities Higher risk means magnitude and likelihood of a legal violation, material financial harm or significant disruption A scored risk assessment per relationship, with the rationale
Inventory A complete inventory, including related subcontractors as appropriate May skip extensive inventories for low-risk clerical, professional and office support vendors A full list, with low-risk vendors marked and not assessed in depth
Due diligence Fourteen listed factors, from strategies and goals to contractual arrangements with other parties Scaled to risk; alternative sources, consortia and certifications may be enough Diligence performed, gaps, and the substitute evidence relied on
Contracts Seventeen listed considerations, from right to audit to regulatory supervision No generally applicable expected contract terms, even for higher-risk relationships Terms negotiated, terms refused, and the risk accepted as a result
Subcontractors Diligence and contract terms on reliance on subcontractors Subcontractors alone do not create a separate relationship or presume direct oversight Subservice organizations from each SOC report, reviewed at the primary vendor
Residual risk Not a separate component A named component: decide which risks to accept and on what information A signed acceptance record for each higher-risk relationship
Governance Board oversight, independent reviews, documentation and reporting Six practices, including a periodic independent review of the program Board reporting and the latest independent review on file

Good questions

Questions about interagency TPRM guidance

It is the Interagency Guidance on Third-Party Relationships: Risk Management that the Federal Reserve, FDIC and OCC issued on June 6, 2023 (OCC Bulletin 2023-17, SR 23-4, FIL-29-2023). It replaced each agency's earlier vendor guidance and sets principles for managing third parties across a life cycle of planning, due diligence, contract negotiation, ongoing monitoring and termination, scaled to the bank's size and risk.
Yes. The September 15, 2026 proposal would replace the 2023 guidance and the related supplemental resources, including the 2024 community bank guide and the bank-fintech deposit statement, but only once the agencies finalize it. Until then the 2023 text is what examiners apply, so keep your program aligned with it while you prepare for the change.
The proposal centers the program on risk identification and assessment, drops the "critical activities" concept, defines higher-risk relationships by magnitude and likelihood of harm, says no contract terms are generally expected, allows lighter diligence from alternative sources for lower-risk vendors, adds residual risk acceptance, and extends coverage to credit unions through the NCUA.
Comments on both the interagency proposal and the Fed's companion community bank guide must be received by November 16, 2026. The OCC docket is OCC-2026-0793, the Fed docket for the interagency text is OP-1881, and the NCUA docket is NCUA-2026-1684. The community bank guide is Fed docket OP-1880.
The 2023 guidance does not, because the NCUA did not issue it. The 2026 proposal would change that: the NCUA is a co-issuer and the text defines banking organizations to include insured credit unions. A credit union following NCUA vendor due diligence expectations today should plan for the interagency text once it is final.
The 2023 guidance names five: planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination, with governance running across all of them. The 2026 proposal reorganizes this into four components: risk identification and assessment, risk oversight (diligence, contracts, monitoring and termination), residual risk acceptance, and governance.
In the Fed's proposed companion guide, it is a banking organization with less than $30 billion in assets that focuses on serving its local community. The guide excludes community banks with complex business models or third-party profiles, such as bank-fintech partnerships where the fintech rather than the bank markets or provides access to the product.
No. Guidance is not a rule, and the proposal states that non-compliance with it will not by itself result in supervisory action. The agencies can still act on violations of law, unsafe or unsound practices or other material risks that result from weak third-party risk management, which is why the documented reasoning behind your tiers and acceptances matters.
No. Scrutineer is vendor risk and compliance software. It scores and tiers relationships, runs questionnaires, reads vendor SOC reports and keeps the record of each decision. It does not examine your bank, it does not supply credit or financial statement analysis of a provider, and it is not legal advice. Your risk and compliance officers make and own the decisions.

Keep reading

Guides that go deeper on this framework

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification