Four agencies, one date, one text open to comments
The central bank AI dossier received an indirect response on September 11, 2026, when four US federal agencies requested comments on proposed guidance for managing risk in third-party relationships. The joint statement[1] is signed by the Federal Deposit Insurance Corporation, Federal Reserve Board, National Credit Union Administration, and Office of the Comptroller of the Currency.
The text stems from the agencies' supervisory experience and lessons learned from examinations of vendor management practices. The stated purpose is to help banks and credit unions align those practices with the risk of each individual relationship.
The proposal adopts a principles-based approach. Supervisory guidance, by its nature, remains non-binding. Comments are due within sixty days of publication in the Federal Register.
The regulatory gap: revocation, replacement, consistency
Until now, the industry has worked under the existing interagency guidance on third-party relationships.
The statement announces the next step with clarity. Once the new text is finalized, the agencies plan to revoke the existing guidance and replace it with the final version. The stated objective: consistency in supervision and prudent innovation in the banking sector.
The gap concerns method before content. Principles-based guidance asks banks to calibrate controls to each vendor's profile. A list of specific obligations would have given the General Counsel a checklist with firm dates.
This difference matters for those preparing the supervisory examination. The perimeter remains broad, and the burden of demonstrating adequacy falls on the bank, which must explain its calibration choices with supporting documentation.
Core service providers: the taxonomy that governs supervision
In a separate action, the same agencies published a statement on the relationship between community banks and core service providers. The document identifies factors that authorities will consider in supervisory and enforcement decisions on those relationships.
The category describes those who provide core processing infrastructure: accounts, payments, accounting records, digital channels. It is the operational backbone of thousands of small institutions.
The taxonomy is the most powerful governance tool in the entire package. Those who fall within the category attract supervisory attention and carry different weight at the negotiating table. Those outside travel as ordinary vendors, with controls calibrated by the bank itself.
One common interpretation sees this choice as relief for smaller institutions. An opposite reading views it as an invitation to better document dependence on a few concentrated vendors. The consultation text supports both readings.
Where third-party models end up
A credit scoring engine delivered in the cloud is, legally speaking, a third-party relationship. The same applies to a conversational assistant in a branch or an anti-money laundering system trained elsewhere.
The September 11, 2026 statement announces uniform principles for all such relationships. A dedicated category for models is absent from the released text.
This choice has two legitimate readings. First: principles age better than technical categories, and a closed list of systems would become obsolete in eighteen months. Second: the absence of a dedicated class leaves the bank with the burden of proving that the vendor's model is truly governed.
For the Chief Risk Officer, the consequence is operational. The contract register and model inventory, usually maintained by different functions, must communicate before the next examination cycle.
Non-binding status, concrete supervisory effects
Non-binding guidance still produces measurable consequences. Examiners use it as a benchmark in the control cycle, and identified deficiencies end up in findings, remediation plans, and in serious cases, formal agreements.
The issue extends beyond the United States. In September 2026, the Financial Stability Board hosted a roundtable on public-private sector collaboration to strengthen operational resilience (FSB, September 2026[2]). Third-party dependency now occupies international forums.
Monetary authorities speak to the market through statements and interviews, a tool different from regulation with articles and penalties. The Bank of England announced in this register a Governor's interview in September 2026 (Bank of England[3]).
The result is a framework made of expectations, statements, and examination practices. Effective dates and penalties, typical of European law, remain outside this perimeter.
The governance signal: a name, in writing, before deployment
The governance signal is clear: US supervision entrusts banks with choosing internal roles and designing controls.
The question the General Counsel must answer remains, in substance, one. Which named role inside the organization is accountable for the behavior of a model provided by a third party, by name, in writing, before deployment?
The European Union chose a different path. Regulation (EU) 2024/1689 distinguishes provider and deployer, imposes transparency obligations in Article 50, and classifies high-risk systems in Annex III. The proposal known as the Digital Omnibus, still in negotiation, shifts the application of high-risk obligations to December 2027.
A bank active on both sides of the Atlantic thus operates under two regimes. Accountability with a name, audit trails, and risk classifications built now provide a competitive advantage when enforcement becomes serious.
Three decisions for the board
The September 11, 2026 package opens a sixty-day window from publication in the Federal Register. The audit and risk committee has material for three resolutions.
- Participation in the consultation: decide to submit a formal comment before the deadline, with explicit position on models provided by third parties.
- Map of critical vendors: approve a review of the contract register that identifies relationships comparable to core service providers and models embedded in those contracts.
- Named owner: assign in writing to an existing role the lifecycle management of third-party models, with periodic reporting to the committee.
Each resolution leaves a trace in the minutes. The minutes are the first proof that the examiner asks for, and the distance between governance and documentation passes through there.
The Chief Compliance Officer finds the perimeter of their work here: audit rights, exit clauses, operational continuity, and service levels for concentrated vendors. The CEO finds the strategic constraint: the choice of model vendor becomes a risk decision, discussed in the boardroom.
Regulatory horizon
Current status: proposal in public consultation, non-binding, open to comments for sixty days from publication in the Federal Register.
Jurisdiction: United States, banks and credit unions supervised by FDIC, Federal Reserve Board, NCUA, and OCC. The revocation of existing guidance will take effect upon finalization of the new text, on a date still to be determined.
On the European front, the relevant deadline for high-risk systems falls in December 2027 in the proposal under negotiation. Article 50 transparency obligations remain the reference for systems directed at the public. The American state framework, meanwhile, continues to shift by political position.
The question about the existence of vendor rules now has an answer. A second question has opened: which category will house models when the final guidance replaces the current one.
This article was written by an editorial AI author with human supervision, in compliance with transparency obligations under Regulation (EU) 2024/1689 (AI Act, Art. 50). Sources are linked in the text.
Article by ATLAS
Sources
- The joint statement 11 Sep 2026 (federalreserve.gov)
- FSB, September 2026 (fsb.org)
- Bank of England (bankofengland.co.uk)