Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Should Banks Reclassify Third-Party Risk Now or Wait?Third-Party Risk Management
4 min readFor Risk Managers

Should Banks Reclassify Third-Party Risk Now or Wait?

The Question at Hand

Risk managers at banks face a timing dilemma this fall. The OCC, Federal Reserve, FDIC, and NCUA proposed new third-party risk management guidance on September 11, 2026, with comments due by November 16. The proposal rejects the "critical activities" framework from the 2023 guidance, noting it was "interpreted in an overly broad manner." Instead, the new approach tiers risk by the magnitude and likelihood of potential harm.

Should you start re-tiering your vendor inventory now, or wait for the final rule? Your decision hinges on balancing regulatory alignment with operational disruption.

The Case for Reclassifying Now

Some risk teams argue that proactive re-tiering shows responsiveness to regulatory intent. The proposal's criticism of the 2023 guidance is clear. If examiners view the current framework as overbroad, continuing to apply it suggests your team hasn't adapted.

Re-tiering now allows you to identify quick wins. The proposal permits streamlined reviews for lower-risk services like administrative and office support. If you're treating a janitorial contract with the same rigor as a core banking processor, you're wasting resources. Shifting these relationships to a lighter-touch tier frees capacity for higher-risk vendors.

Early movers also gain time to document their rationale. The proposal states that examiners will give "due consideration" to an institution's reasonable judgment on risk assessments. Your written justification for each vendor's tier becomes your primary defense during examinations. Starting the reclassification process now gives you months to refine that documentation before the final rule arrives.

There's also a practical workflow argument. If you wait for the final guidance, you'll face a compressed timeline to complete the re-tier, update your vendor risk policy, retrain your procurement team, and adjust your annual review schedule. Banks that start now can phase the work across Q4 2026 and Q1 2027.

The Case for Waiting

The counterargument is pragmatic: the 2023 guidance remains in force until the agencies finalize the replacement. Re-tiering based on a proposal creates documentation risk. If the final version changes the tiering criteria or adds requirements your early reclassification didn't anticipate, you'll need to redo the work. Worse, you'll have a vendor inventory that doesn't align with either the old or new standard during the gap period.

Waiting preserves your examination posture. Examiners can't fault you for following the current guidance. If you re-tier prematurely and an examination occurs before the final rule, you may face questions about why your vendor classifications don't match the 2023 framework.

The comment period itself suggests the proposal isn't final. The agencies published it in the Federal Register on September 15 and set a November 16 deadline for feedback. Industry groups will submit detailed comments, which could shift the final text. The tiering methodology might change. The definition of "streamlined review" might narrow.

There's also the question of examination capacity. If your institution is scheduled for an on-site examination in Q4 2026, you don't want to introduce a half-completed re-tiering project. Examiners reviewing your vendor risk program will expect to see a coherent framework applied consistently. A work-in-progress classification doesn't meet that standard.

Where Practitioners Actually Land

Most risk managers I've spoken with are taking a middle path: they're inventorying which relationships would re-tier under the proposal but not formally changing vendor risk classifications yet.

This means running a shadow analysis. Pull your current vendor inventory, apply the proposed tiering criteria, and document which vendors would move from high-tier to streamlined review. Identify which relationships you'd handle differently: where you'd accept a shared assessment instead of conducting your own, where you'd skip the on-site visit, where you'd proceed without every requested document.

That analysis gives you two things. First, it's the foundation of a substantive comment letter if your institution plans to submit one. Second, it's a head start on implementation when the final rule arrives. You've already mapped the changes; you just haven't operationalized them.

For the unsafe-or-unsound practice rule, the timeline is clearer. It takes effect on November 2, 2026, and applies to OCC and FDIC-supervised institutions. If you're a national bank or state non-member bank, your issues management process needs to change now. Every MRA issued after November 2 must document either the material financial harm or the specific legal violation that supports it. That's not a proposal; it's a final rule with a hard deadline.

Our Take

Wait on formal re-tiering, but complete the analysis by year-end. The operational risk of reclassifying vendors under a proposal that might change outweighs the benefit of early compliance. You're not behind if you're following the guidance that's in force.

But don't wait to understand the impact. If the final rule arrives in Q1 2027 and you haven't mapped which vendors would shift tiers, you'll scramble. Run the analysis now while you have time to think through edge cases and document your reasoning.

For the unsafe-or-unsound rule, the choice is simpler. Update your issues log template before November 2 to capture the materiality linkage or legal citation for each MRA. Train your remediation team on the new standard. The Federal Reserve didn't join this rule, so if you're a state member bank, confirm which criteria your examiners are applying.

The broader pattern here is regulatory recalibration. Both actions reflect agencies stepping back from standards they now view as too rigid or too broad. That recalibration creates short-term ambiguity, but it's ambiguity you can manage with deliberate preparation.

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide

You Might Also Like