CeFPro Connect

News
US Regulators Target Core Providers Over Community Bank Risks
US banking regulators are intensifying scrutiny of third-party core providers amid concerns that market concentration is restricting community banks’ ability to negotiate contracts, conduct due diligence and manage vendor risk. New proposals would also encourage financial institutions to tailor third-party oversight according to individual relationships.
Sep 21, 2026
Tags: Vendor and Third Party Risk Industry News
US Regulators Target Core Providers Over Community Bank Risks
The views and opinions expressed in this content are those of the thought leader as an individual and are not attributed to CeFPro or any other organization



  • US regulators are stepping up scrutiny of third-party core technology providers serving community banks
  • Market concentration is raising concerns that smaller banks lack sufficient negotiating power with major vendors
  • Regulators will examine provider transparency, contract restrictions, technology investment, cybersecurity and operational resilience
  • Agencies could take action against providers or banks when safety, soundness or legal issues emerge
  • Proposed guidance encourages institutions to tailor vendor oversight to the risk presented by individual relationships
  • The Federal Reserve has proposed additional guidance specifically for community banks

US banking regulators are stepping up scrutiny of third-party core technology providers amid concerns that dominant vendors are restricting community banks’ ability to conduct due diligence, negotiate contracts and effectively manage operational risks.

The Federal Deposit Insurance Corporation, Federal Reserve and Office of the Comptroller of the Currency issued a joint statement outlining how they will supervise services provided to community banking organizations, with particular attention on business practices that may “unreasonably limit” banks’ ability to manage relationships with core providers.

The agencies acknowledged that a significant proportion of the core provider market is controlled by a relatively small number of large companies – potentially weakening the negotiating position of smaller financial institutions.

“Given these constraints, CBOs report they often experience challenges obtaining reasonable due diligence information, negotiating contract terms, or conducting effective ongoing monitoring,” the regulators said.

“These challenges may make it difficult for CBOs to hold core providers accountable for delivering quality services.”

Regulators will focus on three broad areas when assessing services delivered by core providers, including the level of transparency offered to community banks.

That could involve examining contractual provisions that restrict a bank’s ability to compare a provider’s products and services with competing offerings, as well as contract terms that make it more difficult for institutions to manage vendor relationships in accordance with their individual business requirements.

Technology resilience will also face scrutiny. Regulators said they will consider whether providers are investing sufficiently to maintain and modernize their technology, while strengthening cybersecurity and reducing the risk of outages and service disruptions.

The agencies warned that they have powers to intervene when problems create safety and soundness concerns or result in violations of the law.

“When such issues are identified, the agencies may bring the appropriate actions against core providers and/or the CBO pursuant to their statutory authorities,” they said.

The regulatory intervention comes alongside proposed joint guidance from the FDIC, Fed and OCC, together with the National Credit Union Administration, designed to help financial institutions tailor third-party risk management practices more closely to the risks presented by individual vendor relationships.

Rather than applying identical oversight requirements across every third party, institutions would be encouraged to align their controls with the “reasonably assessed” risk of each relationship.

The proposals would also provide strategies for adjusting third-party risk management according to an institution’s size, complexity and overall risk profile, together with the nature and significance of the service being provided.

Separately, the Federal Reserve has requested feedback on a proposed third-party risk management guide specifically for community banks under its supervision. The document is intended to complement the broader interagency guidance.

The proposals highlight growing regulatory attention on the risks created by financial institutions’ dependence on external technology companies – particularly where market concentration leaves smaller banks with limited bargaining power.

For community banks, the measures could strengthen their position when dealing with critical technology providers.

For vendors, however, they signal that contractual practices, transparency, cybersecurity investment and operational resilience are increasingly becoming matters of direct regulatory interest.

The proposed third-party risk management guidance will replace existing guidance, with comments due within 60 days of its publication in the Federal Register.

Sign in to view comments
You may also like...
ad
Related insights