On September 11, the FDIC, the Federal Reserve, the NCUA and the OCC asked for comment on proposed guidance for how banks manage their third-party relationships. When it's finalized, the agencies plan to rescind the existing guidance and replace it with the new version. The agencies describe the proposal as principles-based and, like all supervisory guidance, non-binding (OCC joint release). Comments are due November 16, 2026 (Federal Register).
Nothing here is final, and the text may change. Still, it's worth reading if you're building a financial product on a partner bank, because it describes, in some detail, what your bank is expected to check about you.
A checklist, in everything but name
According to analysis from Ballard Spahr, the proposal is "more prescriptive than its emphasis on a 'risk-based' approach might suggest." It identifies specific elements banks should address across the life of a relationship: due diligence, contracting, ongoing monitoring, documentation, remediation and termination. It also keeps the core principle that a bank can't outsource its responsibility for compliance (Consumer Finance Monitor).
Analysts note that the guidance is relevant to fintechs, banking-as-a-service partners and compliance vendors, not just traditional bank vendors (Stinson LLP).
Read from the partner's side, each stage of that life cycle becomes a question the bank will ask you. Your answers are the diligence packet.
The packet, stage by stage
-
1. Due diligence: before you sign. Expect questions about your financial condition, experience, compliance program, information security, resilience and the vendors you rely on. The analysis notes that a bank shouldn't simply take a partner's word for it when the relationship carries real risk. Have evidence, not just answers.
-
2. Contracting: what you're committing to. Know which obligations you own (complaints, disclosures, monitoring, reporting) and which the bank keeps. Ambiguity here becomes a problem later.
-
3. Ongoing monitoring: after launch.
"The packet that impressed me most wasn't the longest," says Tyler Ferguson, Chisel co-founder and a 25-year commercial banker. "It was the one where every answer had an owner and a date, and the fintech could show me last month's monitoring without scrambling."
-
4. Documentation and reporting: evidence that keeps itself current.
"If monitoring evidence comes straight out of your systems instead of being assembled for each request, the second and third bank relationships get much cheaper," says Matt Anderton, Chisel co-founder.
-
5. Remediation: when something goes wrong. Decide in advance how issues get found, escalated, fixed and reported to the bank. Find out what the bank expects to hear, and when.
-
6. Termination: the exit plan. Banks are asked to plan for the end of a relationship. You should too: how customers, data and funds would move if the partnership ends.
The cost nobody budgets for
The same analysis points out that providers serving many banks can receive "essentially the same due-diligence requests from dozens of institutions." It also describes a reported FDIC idea, still under consideration, for an industry standard-setting body that could certify third-party providers (Consumer Finance Monitor; Aug 17 report).
"Budget for it like infrastructure, not paperwork," says Darin Petty, Chisel co-founder. "Who owns the diligence answers, how many hours a quarter does it take, and what happens to that cost when you add a second bank?"
What to do before November 16
- Skim the lifecycle sections of the proposal and assign each stage an owner on your team.
- Put your packet in one place: policies, vendor list, monitoring evidence, complaint handling, and the exit plan.
- Fill the gaps you find now, while it's a planning exercise rather than a bank request with a deadline.
Being ready for a bank's questions has never been a wasted week. Chisel works with companies that have earned the right to launch a financial product, helping them get ready for those conversations with people who have done it before.