Regulators Propose Risk-Based Vendor Oversight For Community Lenders – NMP Skip to main content

Regulators Propose Risk-Based Vendor Oversight For Community Lenders

Sep 14, 2026
Regulators Propose Risk-Based Vendor Oversight For Community Lenders
Managing Editor

Plan could ease reviews of lower-risk mortgage technology while preserving lender responsibility for vendor failures

Federal regulators are proposing a revised approach to third-party oversight that could reduce process-heavy vendor reviews for community banks and credit unions, including those operating mortgage businesses.

The proposal is not mortgage-specific, but it would apply to the mortgage operations of federally supervised banks and credit unions that rely on outside technology and service providers.

The Federal Reserve, Federal Deposit Insurance Corp., Office of the Comptroller of the Currency, and National Credit Union Administration proposed directing institutions to tailor their oversight to the risks presented by each third-party relationship.

For mortgage lenders, that could mean reviewing a limited-use software provider differently from a loan-origination system, income-verification tool, automated underwriting platform, or servicer that handles borrower data, credit decisions, or payments.

The agencies said the proposed framework would help institutions focus their resources on relationships presenting the greatest potential harm while avoiding “overly process-driven strategies” that treat every third party as inherently high risk.

If finalized, the proposal would replace the third-party-risk guidance issued by the OCC, Fed, and FDIC in 2023 and establish a common framework that also includes the NCUA.

The proposal would be nonbinding. The OCC said failure to follow the guidance would not, by itself, result in supervisory action.

What It Could Mean For Mortgage Operations

Banks and credit unions use third parties throughout the mortgage process, including for applications, pricing, credit reports, income and employment verification, appraisals, closing services, document preparation, and servicing.

The 2023 guidance already called for a flexible, risk-based approach. The new proposal would further emphasize tailoring and discourage institutions from applying broadly uniform processes to vendors with different levels of risk.

If examiners apply the framework as intended, community lenders could spend less time documenting lower-risk relationships and concentrate their resources on vendors handling borrower data, credit decisions, payments, or critical operations.

The agencies would consider an institution’s size, complexity, and risk profile, along with the nature of each third-party relationship.

The framework would not relieve a lender of responsibility for consumer harm, legal violations, data breaches, or operational failures involving its vendors. Existing fair-lending, privacy, information-security, and consumer-protection requirements would continue to apply.

Independent mortgage banks are not directly supervised by the four agencies and are not the proposal’s primary audience. They could still experience indirect effects through warehouse banks, depository partners, service providers, and increased technology competition from banks and credit unions.

Regulators Address Core-Provider Leverage

The Fed, FDIC, and OCC also issued a separate statement addressing community banks’ relationships with core service providers. The NCUA did not join that statement.

The three banking regulators acknowledged that community institutions may struggle to obtain information from core providers, monitor their performance, negotiate contract protections, or replace critical systems.

Those limitations can be significant in mortgage lending, where changing a core banking, loan-origination, or servicing platform can be costly and disruptive. Smaller lenders may also lack the leverage to secure audit rights, data access, liability protections, and favorable termination provisions.

Regulators said they would consider those circumstances when determining the appropriate level of supervisory oversight. They also retained their authority to act when a core provider causes a community bank to engage in unsafe or unsound practices or violate the law.

The statement could shift some supervisory attention toward a core provider’s conduct when a community bank lacks the leverage or information needed to control the resulting risk.

Barr Warns Of Compliance Gaps

The proposal did not receive unanimous support at the Federal Reserve.

Fed Gov. Michael Barr dissented, warning that the proposal could create confusion and leave gaps in supervisory coverage.

Barr objected to its use of a “material financial risk” standard, arguing that it could make supervisors less likely to require corrective action before a vendor problem becomes serious.

He also raised concerns about the proposals’ exclusion of consumer-compliance matters. Barr said the approach could leave banks without clear guidance or require them to operate under overlapping frameworks.

That concern has direct implications for mortgage vendors whose products affect underwriting, fair lending, disclosures, privacy, servicing communications, and loss mitigation.

Barr also noted that a separate guide proposed for traditional community banks would not cover institutions with complex business models or third-party profiles, including complex bank-fintech partnerships.

Fed Gov. Lisa Cook supported reconsidering the existing framework but called for public feedback on whether regulators should provide greater detail about cybersecurity, consumer protection, record management, and anti-money-laundering responsibilities in bank-fintech relationships.

The agencies released the proposal and supporting documents Sept. 11. Comments will be due 60 days after publication in the Federal Register. A fixed deadline had not been posted as of Sept. 14.

For community mortgage lenders, the proposal could reduce unnecessary vendor-review work. It would not change their underlying responsibility to understand what their technology does, monitor the risks it creates, and protect borrowers when problems occur.

About the author
Managing Editor
Czarinna Andres leads editorial coverage for NMP, focusing on the trends, policies, and business strategies shaping today’s mortgage and housing finance landscape. She brings a background in journalism and media, with experience…
Published
Sep 14, 2026
Regulators Propose Risk-Based Vendor Oversight For Community Lenders

Plan could ease reviews of lower-risk mortgage technology while preserving lender responsibility for vendor failures

FHA Sets Jan. 1 Start For FICO 10T And VantageScore 4.0

Lenders will gain competing modern scoring options, but borrowers may not see both offered everywhere

Sep 11, 2026
FHFA Studies Credit-Report Changes To Cut Mortgage Costs

Pulte’s comments could signal either fewer bureau reports or a portable report borrowers could share among lenders, but FHFA has not clarified which approach it is studying

AI Errors Leave Mortgage Trustee Without Brief In Foreclosure Appeal

Outside counsel’s fabricated citations expose a third-party oversight risk for mortgage servicers, trustees, and investors

Sep 10, 2026
CHLA Wants Ginnie Mae Liquidity Backstop Ready Before Next Crisis

Proposed G-TALF facility could help prevent a servicing cash crunch from constraining FHA, VA, and USDA lending

FHFA Opens VantageScore To All GSE Lenders, Eyes Credit Report Overhaul

Pulte removes 50-lender cap while considering bi-merge and single-bureau reports as additional ways to reduce mortgage costs