📈 Get daily crypto insights that make you smarter about your money

Fed, FDIC, OCC and NCUA Propose Risk-Based Third-Party Risk Rules for Bank Vendors — Crypto Service Providers in Scope

Four United States financial regulators have jointly proposed new third-party risk guidelines that would let banks and credit unions scale their oversight of outside vendors to the actual risk of each relationship, replacing guidance issued in 2023 and 2024. The framework is nonbinding, but its reach extends to the technology companies that supply crypto custody, stablecoin, payment and blockchain services to regulated banks — making the outcome directly relevant to digital-asset service providers courting bank clients.

A risk-based framework replaces one-size-fits-all oversight

The Federal Reserve, the Federal Deposit Insurance Corporation, the National Credit Union Administration and the Office of the Comptroller of the Currency announced the proposal on September 11. Under the draft guidelines, financial institutions would consider both the potential harm from an outside provider and the likelihood that the harm occurs. Where a relationship carries limited risk, banks could rely on less detailed checks, standard contracts and less frequent monitoring.

The framework would also allow an institution to accept some residual risk after weighing its own risk appetite, tolerance and ability to operate safely. Agency staff stressed that the principles do not impose enforceable requirements, and a bank would not face supervisory action solely because it failed to follow the guidance. Comments remain open for 60 days after the proposal appears in the Federal Register. Once the rules are finalized, the agencies plan to withdraw the current third-party risk framework and substitute the revised version.

Federal Reserve staff offered a candid assessment of why the change is needed. According to the agencies, existing guidance has sometimes been applied too broadly, encouraged process-heavy reviews and failed to account for differences among vendors. Staff also said banks have read the current framework as discouraging engagement with newer service providers — a point with clear implications for young fintech and crypto infrastructure firms that lack long audit histories.

Why vendor oversight dominates bank technology

As technology has become central to banking, institutions have outsourced a growing share of their operations. Outside providers now routinely handle payment processing, cybersecurity, online banking platforms, fraud detection, card programs and anti-money-laundering systems. The bank remains responsible for risks tied to services it no longer operates itself, which is precisely the gap the guidelines try to manage.

Community banks get a dedicated guide

Alongside the main proposal, the Federal Reserve requested comments on a companion guide for traditional community banking organizations under its supervision, defined as locally focused banks with less than 30 billion USD in assets. The guide covers four main areas: operational resilience, information security, legal compliance and financial resilience. It also explains how smaller banks could assess eight common vendor groups, including core service providers, payment processors, digital banking companies, cybersecurity firms and financial-crime platforms.

For each category, the document outlines issues that smaller banks may weigh during due diligence, contract negotiations, ongoing monitoring and a potential migration to another provider. Fed staff said smaller institutions had asked for more practical direction than the high-level principles in the existing framework provided. Complex bank-fintech arrangements — cases in which one or more fintech companies market, distribute or provide access to a bank’s products — would not fall under the community bank guide.

Regulators turn attention to core providers

A separate statement on core providers addresses the vendors that supply the systems banks need for transaction processing, account management, payments, compliance, customer relations and online banking. The Fed, FDIC and OCC said a small number of large companies control much of this market, limiting the negotiating leverage of community banks.

Banks have reported difficulty obtaining due diligence records, negotiating workable contract terms and monitoring these vendors. Regulators said they may consider a provider’s transparency, contract practices and technology investment when deciding the scope and frequency of examinations. They may also look at whether providers disclose security incidents on time, supply audit and security records, maintain aging technology and allow clients to connect services from other companies. Opaque pricing, retroactive billing and undefined exit fees may likewise influence supervisory decisions.

Barr dissents, Cook asks for more

Federal Reserve Governor Michael Barr opposed both proposals, arguing that their wording could weaken oversight rather than strengthen it. He objected to a proposed “material financial risk” standard for supervisory action, warning that the threshold could make banks less likely to correct problems before they become material to the institution. Barr also questioned language saying regulators would give due consideration to a bank’s reasonable decisions, suggesting institutions could read it as requiring supervisors to defer to bank judgment rather than make independent assessments.

On consumer compliance, Barr said the proposals could leave existing guidance removed without a clear replacement for consumer-protection issues, or force banks to follow two sets of standards at once. He further noted that the community bank guide excludes institutions with complex business models and vendor relationships — including some bank-fintech partnerships — which he argued may have the strongest need for detailed third-party risk instructions. “I dissent,” Barr wrote.

Federal Reserve Governor Lisa Cook supported reviewing the current framework but requested feedback on whether the final version should say more about cybersecurity, record management, consumer protection and the division of anti-money-laundering duties in bank-fintech partnerships. She also backed the separate community bank guide and invited comment on what additional resources smaller institutions need when evaluating technology companies and core providers.

What it means for crypto firms

Although the proposal creates no digital-asset-specific rules, its scope covers technology companies that provide crypto custody, stablecoin, payment or blockchain services to regulated banks. Institutions would evaluate such third parties according to the service and the risk involved, regardless of the underlying technology.

The proposal also continues a broader shift in how U.S. regulators treat bank engagement with digital assets. In April 2025, the Federal Reserve withdrew prior-notification expectations for certain crypto and dollar-token activities. A July 2025 interagency statement explained how existing risk-management principles apply when banks safeguard crypto assets, and an OCC bulletin from the same period said banks should assess outside service providers before offering custody while creating no new supervisory expectations.

The new all-bank proposal additionally permits institutions to share due diligence through consortia, standard contracts and certification bodies — a mechanism that could lower the barrier for specialized crypto infrastructure providers seeking bank clients. For an industry still arguing that clarity, not leniency, is what it needs from Washington, the draft guidelines signal that regulators want vendor oversight to be proportionate rather than punitive. Whether Barr’s warnings about supervisory gaps prove prescient will depend in part on the comments the agencies receive over the next 60 days.

14 thoughts on “Fed, FDIC, OCC and NCUA Propose Risk-Based Third-Party Risk Rules for Bank Vendors — Crypto Service Providers in Scope”

  1. the harm times likelihood framing is straight out of basel playbooks. credit unions have been begging for exactly this since the 2023 guidance buried them in paperwork

  2. Risk-based instead of one-size-fits-all is genuinely good news for smaller custody providers. The 2023 guidance was so heavy that community banks just stopped experimenting.

    1. That is the optimistic read. My take is this just formalizes what examiners already demanded informally, now with extra paperwork attached.

    2. Agreed, and the residual risk acceptance language is the sleeper detail. A community bank can now formally accept a lower tier vendor instead of pretending everything is systemically important.

  3. nonbinding guidance that no compliance department will actually treat as nonbinding. banks are gonna read this as mandatory anyway and freeze half their vendor reviews lol

    1. exactly. the 2023 framework was technically optional too and look how that went, plenty of banks just stopped onboarding newer providers entirely

  4. compliance_gremlin

    nonbinding framework, four agencies, zero enforcement teeth. seen this movie before, the examiners will treat it like gospel anyway lol

    1. examiners treating nonbinding guidance as binding is literally why banks dumped crypto clients in 2023. hope this one actually sticks

  5. 60 day comment window on rules that directly hit crypto custody and stablecoin vendors. the big shops will file, small providers wont even know the window is open

    1. @LedgerLena aint that always the deal tho. whoever can afford counsel writes the comment letter, whoever is busy shipping product eats the result

    2. 60 days is generous by crypto standards tbh. the real filter is federal register formatting, half the small vendors wont even parse the proposal text

    3. ^ this. small blockchain infra firms have no regulatory team, they find out when a bank client sends a 200 question diligence form out of nowhere

  6. four agencies aligning on anything is the rare part here. last time the fed and occ could not even agree on definitions, vendors got four different questionnaires for the same bank

  7. harm times likelihood is just basel speak and thats fine. four agencies agreeing on one questionnaire instead of four is the actual win for anyone selling custody rails to banks

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$77,126.00+0.6%ETH$2,513.04+3.0%SOL$102.18+3.2%BNB$725.00+2.2%XRP$1.35+1.4%ADA$0.2054+0.1%DOGE$0.0841+1.1%DOT$1.04-6.5%AVAX$7.43-0.2%LINK$11.50+0.1%UNI$5.95-0.3%ATOM$1.64-8.3%LTC$53.14+2.0%ARB$0.1381-3.3%NEAR$2.40-3.3%FIL$0.7798-0.7%SUI$0.7223-0.8%BTC$77,126.00+0.6%ETH$2,513.04+3.0%SOL$102.18+3.2%BNB$725.00+2.2%XRP$1.35+1.4%ADA$0.2054+0.1%DOGE$0.0841+1.1%DOT$1.04-6.5%AVAX$7.43-0.2%LINK$11.50+0.1%UNI$5.95-0.3%ATOM$1.64-8.3%LTC$53.14+2.0%ARB$0.1381-3.3%NEAR$2.40-3.3%FIL$0.7798-0.7%SUI$0.7223-0.8%
Scroll to Top