Summary
The Federal Reserve, FDIC, OCC and NCUA are proposing a risk-based rewrite of third-party vendor oversight while separately increasing scrutiny of core technology providers' contracts, fees and integration restrictions. The proposal could reduce process-heavy vendor reviews for community lenders, but it would not remove banks' responsibility for compliance, consumer protection or operational failures involving mortgage technology vendors.
Federal banking regulators are proposing to replace their existing framework for overseeing third-party relationships with a more explicitly risk-based approach, a change that could reshape how banks and credit unions evaluate mortgage technology vendors, outsourced fulfillment providers and other companies embedded in the lending process.
The proposal is broader than mortgages. But mortgage operations are among the most vendor-dependent functions inside many financial institutions, touching point-of-sale systems, loan origination software, verification, appraisal management, fraud detection, document preparation, closing, servicing and customer communications.
On Sept. 11, the Federal Reserve, Federal Deposit Insurance Corp., Office of the Comptroller of the Currency and National Credit Union Administration jointly requested comment on new third-party risk-management guidance. The agencies say the framework would help institutions tailor oversight to the actual risk of individual vendor relationships rather than applying the same process to every outside provider. If finalized, the regulators plan to rescind and replace existing interagency guidance.
The proposal is nonbinding supervisory guidance, not a final rule. Comments are due 60 days after publication in the Federal Register.
Less box-checking does not mean less responsibility
The central idea is proportionality. Regulators want banks and credit unions to focus resources on relationships capable of producing material financial, operational, legal or compliance harm. For a community lender, that could mean spending less time documenting low-risk vendors while putting more scrutiny on technology and service providers that can affect underwriting, borrower data, disclosures, payments or access to credit.
The OCC described the proposal as a move away from overly broad, process-driven reviews and toward oversight based on the magnitude and likelihood of potential harm. The agencies also say the framework should reflect an institution’s size, complexity and risk profile.
“There is no one-size-fits-all approach to third-party risk management,” the OCC said in describing the proposed framework.
That is likely to appeal to smaller lenders that have complained for years that vendor-management expectations can become an exercise in collecting questionnaires, policies and certifications without necessarily improving risk decisions. Yet the proposal does not transfer responsibility from the financial institution to the vendor. Banks and credit unions remain responsible for operating safely and complying with applicable law when they outsource work.
That distinction matters in mortgage lending. A bank may use a third party to verify income, provide an automated valuation, generate disclosures or communicate with a borrower, but outsourcing the function does not outsource the lender’s exposure when the process fails.
Regulators are also turning their attention to the vendors themselves
The agencies paired the proposal with a separate statement on community banks’ relationships with core service providers. That statement is notable because it shifts part of the regulatory focus from how banks manage vendors to how major technology providers deal with smaller financial institutions.
Regulators said they will consider core-provider contract terms, fees and restrictions that can limit a community bank’s ability to use other financial technology companies. The issue reaches well beyond back-office banking. Core systems can determine how easily a lender integrates mortgage platforms, moves data, changes providers or deploys new digital products.
For community banks with mortgage operations, vendor concentration can be a strategic constraint as much as a compliance problem. Switching a deeply integrated provider can require data migration, retraining, testing and operational risk. Contract terms that make integrations expensive or restrict outside technology can therefore influence which mortgage tools a bank can realistically deploy.
The agencies’ decision to address both sides of the relationship is significant. A lender cannot meaningfully manage third-party risk if it lacks leverage to obtain information, negotiate workable terms or connect competing technology.
The Federal Reserve itself is divided over how far to go
The proposal also exposed a substantive disagreement inside the Fed over whether a more flexible framework could leave gaps.
Fed Governor Lisa Cook supported taking a fresh look at the guidance, particularly as banks manage more complex vendor relationships. She said a principles-based, risk-focused approach could support innovation and competition, but asked whether regulators should provide more specificity around cybersecurity, consumer protection, records management and anti-money-laundering responsibilities in bank-fintech partnerships.
Governor Michael Barr went further and dissented. In his statement, Barr warned that the proposed standard could make supervisors less likely to require corrections before problems become material and could create uncertainty about how regulators will judge a bank’s decisions.
“I am concerned that this proposal will reduce safe and sound operations, increase financial and other risk, create undue confusion, and leave gaps in supervisory coverage,” Barr said.
That disagreement is useful for mortgage executives because it identifies the unresolved issue underneath the proposal. Risk-based supervision sounds straightforward until regulators and institutions have to agree on which relationships are risky enough to justify deeper oversight.
Mortgage technology sits directly in that gray area
A vendor can appear operationally routine while handling functions with major consumer consequences. A document provider, for example, may not control credit policy but can affect whether borrowers receive accurate disclosures. A verification platform can influence underwriting inputs. An artificial-intelligence tool can shape communications or prioritization without formally making a credit decision.
The more lenders automate, the harder it becomes to separate technology risk from compliance risk. That is why Cook’s request for feedback on cybersecurity and consumer-protection responsibilities deserves attention from mortgage companies even though the proposal is aimed at regulated banks and credit unions.
Nonbank mortgage companies are not directly supervised under the same interagency framework. But they operate in the same vendor ecosystem, sell loans to regulated institutions, use many of the same technology providers and face their own state and federal compliance obligations. Changes in bank vendor expectations can therefore influence vendor contracts, diligence practices and product design across the broader mortgage market.
What lenders should watch during the comment period
The most consequential details will be how regulators define risk in practice and whether the final guidance provides enough specificity to keep examinations consistent. A flexible framework can reduce unnecessary work, but flexibility can also create uncertainty if different exam teams reach different conclusions about the same vendor relationship.
Mortgage lenders should also watch the agencies’ treatment of core-provider contracts. If supervisory pressure gives community institutions more leverage over restrictive terms, it could lower barriers to adopting competing mortgage technology. That would make this more than a compliance story; it could become a technology-competition story.
Nothing changes immediately. Existing obligations remain in place while the proposal goes through public comment, and the agencies have not adopted final guidance. But the direction is clear: regulators are reconsidering whether vendor oversight should measure the volume of diligence paperwork or the actual risk a third party creates.
For mortgage operations built on layers of outside technology, that distinction could determine where compliance teams spend their time — and which vendors receive the hardest questions.






















0 Comments