Federal regulators propose more flexible bank-fintech oversight
Four federal banking agencies are seeking public comment on proposed guidance that would give banks and credit unions more discretion in overseeing fintechs, payment processors, core technology providers and other vendors.
The Office of the Comptroller of the Currency, Federal Reserve Board, Federal Deposit Insurance Corporation and National Credit Union Administration announced the proposal on September 11, 2026. It is non-binding supervisory guidance, not a final rule, and it does not immediately change the obligations of banks, credit unions or consumers.
What the proposal would change
If finalized, the guidance would rescind and replace existing third-party risk-management guidance. The proposed framework would emphasize the reasonably assessed risks of each relationship instead of applying the same broad expectations to every vendor arrangement.
Oversight would be tailored to the services involved, the risks presented by the relationship, and the financial institution’s size, complexity and risk profile. The agencies said that approach could reduce checklist-style compliance work and support responsible innovation. Whether it would preserve sufficiently strong safeguards in practice remains part of the debate.
The proposal covers relationships involving fintech companies, payment processors, core service providers, technology vendors and other third parties that perform functions for banks or credit unions.
Why consumers should care
Third-party companies may maintain account records, process payments, support mobile-banking applications, provide customer service or assist with compliance and dispute resolution. Problems at those companies can affect customers even when the account is held at a bank or credit union.
Risks identified in the agencies’ materials include delayed access to deposits, payment disputes, weak complaint and error-resolution processes, fraud, cybersecurity incidents, data-privacy problems and confusion about deposit insurance.
A 2024 interagency statement on bank arrangements with third parties also discussed potential effects on Regulation E dispute investigations, Regulation DD disclosures, complaint handling and access to deposit records. It warned that customers may not understand whether funds are held at an insured bank or how deposit insurance applies when a nonbank company is involved.
Banks would remain responsible
The proposal would not transfer a bank’s legal responsibilities to its vendors. Banks and credit unions would remain responsible for complying with consumer-protection laws, safety-and-soundness requirements, anti-money-laundering rules and other applicable obligations when a third party performs work on their behalf.
That distinction matters when a customer reports a payment error, suspects fraud, cannot access an account or needs account records. The proposed guidance is non-binding, while statutes, regulations and other enforceable requirements would continue to apply.
Regulators disagree on details
Federal Reserve Governor Lisa Cook supported a principles-based, risk-focused approach but called for greater specificity on cybersecurity and on how consumer-protection, record-management and anti-money-laundering responsibilities should be allocated in complex bank-fintech partnerships.
Governor Michael Barr dissented. He said the proposal could create supervisory gaps and confusion, and questioned its use of a “material financial risk” standard and language directing agencies to give due consideration to a bank’s reasonable decisions. Barr’s statement is a dissenting regulatory view, not a finding that the proposal will cause consumer harm.
Community banks and core providers
The agencies also issued a separate statement about community banks’ relationships with core service providers. These providers may supply transaction processing, account management, payments processing, online banking, compliance systems and other essential infrastructure.
The statement says regulators will consider issues such as a core provider’s transparency, service-level performance, security-incident disclosures, billing practices and contract terms when deciding how to allocate supervisory attention. The agencies said many community banks have limited negotiating power because a small number of large providers account for a significant share of the core-services market.
What happens next
The next formal milestone is publication in the Federal Register. The agencies said comments will be due 60 days after publication, but the proposal currently contains a placeholder rather than a fixed calendar date.
Comments may influence how any final guidance addresses fintech partnerships, community-bank relationships, cybersecurity and the division of consumer-protection responsibilities. Until a final action is issued, consumers should not assume that bank oversight requirements or their existing protections have changed.
Sources
- OCC joint release on proposed third-party risk guidance
- 2024 interagency statement on third-party deposit arrangements
Look for updates to this story
Discover more from Interactive News
Subscribe to get the latest posts sent to your email.