2026 Third-Party Risk Management Proposal: What Banks Should Ask Their KYC and Identity Vendors
Key Highlights
- On September 15, 2026, the OCC, Federal Reserve, FDIC, and NCUA proposed new interagency guidance on third-party risk management (TPRM). Comments are due November 16, 2026.
- If finalized, the proposal would replace the 2023 interagency guidance and the resources that supplement it, including the 2024 joint statement on bank-fintech deposit arrangements.
- The proposal ties the depth of oversight to risk. Low-risk vendors get lighter oversight, and relationships that could cause significant harm get deeper oversight.
- KYC and identity vendors handle sensitive customer data, sit on the critical path for opening accounts, and support BSA/AML compliance. That puts them near the top of most banks' risk tiers.
- The proposal is guidance and would not set enforceable standards. Banks remain responsible for operating in a safe and sound manner.
What did the agencies propose?
The proposal was published in the Federal Register on September 15, 2026 (91 FR 58536). It rewrites the 2023 Interagency Guidance on Third-Party Relationships rather than adding to it.
The agencies say the 2023 guidance was sometimes treated as a one-size-fits-all checklist. The new draft asks banks to tailor their TPRM practices to their size, complexity, and risk profile, and to the nature of each third-party relationship.
It organizes TPRM into four components:
- Risk identification and assessment: finding third-party relationships and assessing their risks.
- Risk oversight: due diligence and vendor selection, contract negotiation, ongoing monitoring, and termination.
- Residual risk acceptance: making informed decisions about the risk that remains after controls.
- Governance: the policies, roles, and reporting that hold the program together.

OCC Bulletin 2026-46 says the proposed guidance would not set enforceable standards or prescriptive requirements, and banks not following it would not result in supervisory action. The proposal still states that each bank is responsible for operating in a safe and sound manner.
What is actually different from the 2023 guidance?
Three changes matter most for technology vendors.
Harm and likelihood matter more than labels. The 2023 guidance applied heightened oversight to "critical activities." The proposal instead looks at how much harm a relationship could cause and how likely that harm is. Examples include financial harm, operational disruption, and legal or regulatory violations.
Effort scales with risk. Due diligence, contract terms, monitoring, and documentation can be lighter for low-risk relationships and more thorough for higher-risk ones. The agencies point to the differences between providers of core financial products and services, fintechs, and facilities maintenance vendors as an example of why oversight should not look the same for every relationship.
Remaining risk can be accepted, if the decision is informed. Banks are not expected to eliminate all third-party risk. They are expected to decide which risks they accept and to document those decisions.
The likely result is that banks will spend less time on low-risk vendors and more time on the relationships that really matter.

Why do KYC and identity vendors land in a higher-risk tier?
Ask the proposal's questions about an identity vendor, how much harm it could cause and how likely that harm is, and the answer is clear.
- Sensitive data. Identity vendors process names, dates of birth, Social Security numbers, government ID images, and biometrics.
- Regulatory outcomes. Their results feed directly into CIP verification, fraud decisions, and sanctions screening. A weak vendor becomes a BSA/AML problem for the bank.
- Operational dependency. If the vendor goes down, digital account opening stops.
- Dependencies of their own. Identity vendors rely on data sources, cloud providers, and model components. The proposal notes that a vendor's use of subcontractors does not typically, by itself, create a separate third-party relationship for the bank. Those subcontractors still affect the vendor's risk.
- Model risk. Liveness checks, deepfake detection, and document forensics lose accuracy as attacks evolve.
One point does not change: a bank can outsource verification, but not responsibility for it. The bank still needs a reasonable belief that it knows each customer's true identity.
What should banks ask their KYC and identity vendors?
The questions below follow the stages in the proposal. Adjust how deep you go based on your own risk assessment.
| Stage | Question to ask | Evidence to request |
|---|---|---|
| Risk assessment | Which customer data and biometrics do you process and store, and for how long? | Data flow diagram, retention schedule |
| Risk assessment | Which of our compliance obligations depend on your output? | A map of each API result to the CIP, fraud, and screening step it supports |
| Due diligence | How is our data secured, and who audits it? | Independent security reports and certifications, penetration test summary |
| Due diligence | Which data sources do you query, and where are their gaps? | Source list, coverage by state and document type |
| Due diligence | How do you measure and monitor detection of spoofed selfies, deepfakes, and fake documents? | Accuracy metrics, test method, model change log |
| Due diligence | Which subcontractors and subprocessors handle our data? | Current list, and how you notify us of changes |
| Contract | What uptime do you commit to, and what happens if you miss it? | SLA terms, service credits, status history |
| Contract | Do we get audit rights, breach notification deadlines, and access for regulators? | The relevant contract clauses |
| Monitoring | What will you report to us on a regular basis? | Pass, fail, and manual review rates; incidents; data-source outages |
| Monitoring | How will you tell us about changes to models, data sources, or workflows? | Change management policy |
| Termination | How do we exit without losing records or stopping onboarding? | Data export format, deletion certificate, transition support |
Two questions separate strong vendors from weak ones:
- Can the vendor show how a single verification decision was made, including which checks ran and on what evidence?
- Can the vendor tell you where its coverage is thin before you discover it in production?
How should banks use the comment period?
The proposal is not final, so nothing has to be rebuilt by November 16. The window is still worth using.
- Re-rank your vendors by how much harm each relationship could cause and how likely it is. Identity, KYC, and AML vendors will likely move up. Many low-risk vendors can move down.
- Update due diligence for identity vendors using the questions above. Focus on model performance and data-source coverage, which older questionnaires often skip.
- Write down the risks you accept. Record what you accepted and why.
- Consider submitting a comment. Banks with strong views on bank-fintech arrangements, or on lighter oversight for smaller institutions, can comment until November 16, 2026.
Where Signzy fits
Signzy provides KYC, KYB, and AML verification to banks, credit unions, and fintechs. Banks evaluating Signzy, or any identity vendor, can use the table above as their due diligence request list.
The goal is the same whichever vendor you choose. You want one whose controls, coverage, and audit trail you can explain to an examiner.
Related reading: How to choose a vendor for KYC, Top 10 KYC companies for US fintech onboarding, and Understanding deepfake risk by customer journey.
Related Solution
Sources
- OCC, Federal Reserve, FDIC and NCUA, "Proposed Third-Party Risk Management Guidance," 91 FR 58536, Sept. 15, 2026: https://www.occ.gov/news-issuances/federal-register/2026/91fr58536.pdf
- OCC Bulletin 2026-46: https://www.occ.gov/news-issuances/bulletins/2026/bulletin-2026-46.html
FAQ
Is the 2026 TPRM proposal binding?
When are comments due?
Does the proposal treat fintech vendors as higher risk?

Saurin Parikh
Saurin is a Sales & Growth Leader at Signzy with deep expertise in digital onboarding, KYC/KYB, crypto compliance, and RegTech. With over a decade of professional experience across sales, strategy, and operations, he’s known for driving global expansions, building strategic partnerships, and leading cross-functional teams to scale secure, AI-powered fintech infrastructure.
Related Blogs
View all
How To Choose a Vendor for KYC? 9 Key Factors to Keep in Mind

Top 10 KYC Companies for US Fintech Onboarding in 2026: 7-Point Comparison Across CIP, AML, Liveness, Document OCR, Fraud Signals, APIs, and 30-Day Implementation

Understanding Deepfake Risk by Customer Journey in 2026
The best in business
The global API marketplace for KYC, KYB, & AML
Explore the end-to-end verification stack trusted by 1,000 businesses.
Get in touch





