Puntos clave
- NCUA’s 2026 supervisory priorities fold third-party oversight into the lending and payment systems reviews, and cybersecurity now appears only as a footnote instead of its own category. (NCUA, Letter 26-CU-01)
- The FFIEC retired its Cybersecurity Assessment Tool on August 31, 2025, and pointed institutions toward NIST CSF 2.0 instead. (FFIEC, CAT Sunset Statement)
- Compliance team involvement in third-party risk management rose from 42% in 2023 to 88% in 2025, yet fewer than one in four programs call themselves highly coordinated. (Mitratech, 2025 TPRM Study)
- Federal banking regulators built proportionality into community bank guidance, but the underlying obligation to manage third-party risk does not scale down with asset size. (Fed, FDIC, OCC, TPRM Guide for Community Banks, May 2024)
- A vendor record split across lending, compliance, and IT risks three teams giving three different answers about the same vendor in the same exam cycle.
In This Article
- Why Vendor Risk Left Its Own Exam Section
- The FFIEC Retired the CAT for NIST CSF 2.0
- What a Split Vendor Record Costs You Now
- Where Examiners Are Concentrating Attention in 2026
- Does Being a Community Institution Lower the Bar?
- What to Fix Before Your Next Exam
- Ask Henry: Questions I Get About Vendor Risk Exams
An NCUA examiner opens the file on a credit union's indirect lending program. 15 minutes later, she is asking who services those loans after origination, not just who originated them. It is a third-party risk management question that used to wait for its own exam.
That is not a hypothetical exchange. It is where third-party risk management is heading for community banks and credit unions in 2026, and it changes who inside your institution needs a ready answer, and when.
Third-party risk used to have its own lane in an exam: one list, one set of assessments, one monitoring cadence, reviewed together, once a year. NCUA’s 2026 supervisory priorities no longer treat it that way. Vendor oversight now shows up inside the lending review and the payment systems review, and when outsourced functions touch monitoring or reporting, it is starting to surface inside the BSA review too.
The oversight did not get heavier. It got everywhere.
Third-party risk management (TPRM) covers how a bank or credit union identifies, assesses, and monitors the risk a vendor or servicer relationship introduces to lending, payments, and compliance. For community institutions, that management no longer happens once a year in a dedicated review. It happens continuously, inside whichever exam touches the outsourced function.
Why Vendor Risk Left Its Own Exam Section
NCUA’s January 2026 supervisory priorities letter (26-CU-01) tells examiners to assess third-party risk wherever a credit union outsources lending, servicing, or collection functions. The same letter folds vendor management into payment systems oversight too, naming governance, risk assessments, and security frameworks as review areas for the vendors behind a credit union’s payment operations, not just the core processor.
Cybersecurity tells a similar story. It carried its own heading in NCUA’s 2024 and 2025 priorities letters. In the 2026 letter, it drops to a single footnote reference. Cybersecurity did not get less important. NCUA folded it into the baseline expectation for every review area instead of calling it out as a separate one.
Credit unions have run on a version of this principle since 2007. NCUA Letter 07-CU-13 on evaluating third-party relationships still trains field examiners today, and the 2026 priorities letter cites it directly under its lending section.
Community banks answer to a newer, parallel track: the 2023 interagency guidance from the Federal Reserve, FDIC, and OCC, plus the May 2024 guide built to help community banks apply it. Different regulators, same direction. Third-party risk stopped being a single question and became a thread running through most of the others.
| Exam Type | What Draws In Vendor Risk | What Examiners Ask For |
| Lending | Indirect lending, servicing, collection functions | Governance, risk assessments, monitoring cadence, NIST CSF 2.0 alignment |
| Payment Systems | Core processor, ACH/RTP providers, subprocessors | Governance, risk assessments, security frameworks, NIST CSF 2.0 alignment |
| BSA | Vendors touching monitoring or reporting | The same vendor record, consistently current, NIST CSF 2.0 alignment |
The FFIEC Retired the CAT for NIST CSF 2.0
That footnote treatment traces back to one decision. The FFIEC retired its Cybersecurity Assessment Tool on August 31, 2025, and pointed institutions toward NIST CSF 2.0 instead, which builds governance and third-party risk into six functions banks and credit unions already work through: govern, identify, protect, detect, respond, and recover.
CAT had a narrow job. It measured cyber maturity on its own, once a year, the same way third-party risk used to get measured on its own, once a year. Regulators retired it for close to the same reason they folded vendor oversight into lending and payments exams. A single annual snapshot cannot keep pace with a risk that touches the business continuously.
NIST CSF 2.0 does not ask “how is your cybersecurity” as one question. It asks whether governance, vendor oversight, and incident response show up consistently across everything the institution does. I have sat in enough exit meetings to know that is a materially different standard to prepare for, not just a different form to fill out.
What a Split Vendor Record Costs You Now
The shift in this standard already changes who is in the room for third-party risk. Mitratech’s 2025 Third-Party Risk Management Study found compliance team involvement in vendor oversight jumped from 42% in 2023 to 88% in 2025, while fewer than one in four programs describe themselves as highly coordinated.
Close to half point to departmental silos as the reason, with infosec and risk owning strategy, procurement owning the vendor database, and business units managing the relationship day to day.
That split used to cost you one uncomfortable afternoon a year, during the TPRM review. It costs more now. If a lending examiner asks about your indirect auto servicer in March and a payments examiner asks about that same servicer’s subprocessor in September, both questions draw from the same underlying vendor file.
When lending’s answer and compliance’s answer do not match, you have not failed one exam question. You have raised a question about whether the institution knows its own vendor list at all.
Three teams holding three versions of the same vendor relationship was survivable when only one of them had to answer for it each year. It stops being survivable once two of those teams answer for the same vendor to two different examiners in the same year.
Where Examiners Are Concentrating Attention in 2026
That risk concentrates hardest in payment systems. NCUA’s 2026 priorities single out payment systems for direct examiner review, pointing to growing complexity across applications, interfaces, and security controls as consumer expectations shift toward instant access to funds. Examiners will assess governance, risk assessments, vendor management, and security frameworks for the vendors behind those payment rails, not only the core processor.
Real-time payments and ACH providers sit downstream of the core processing relationship most institutions already track closely. They get overlooked precisely because the core processor gets the attention. A vendor list that stops at the obvious names misses the providers examiners are now naming specifically.
The same logic extends past your direct vendors. A payments provider’s own subprocessors, and a servicer’s own vendors, carry risk your institution never directly assessed. The 2026 KPMG Global Third-Party Risk Management Survey has flagged Nth-party visibility as a priority precisely because most programs stop looking one layer too early.
Does Being a Community Institution Lower the Bar?
No. The underlying third-party risk obligation set by the 2023 interagency guidance those same agencies issued the year before does not scale down, even though the Federal Reserve, FDIC, and OCC built their May 2024 Third-Party Risk Management Guide, voluntary and scaled to size and complexity, specifically for banking organizations with $10 billion or less in consolidated assets.
Proportionality shapes how you build a program. It does not decide whether you need one. Whether an institution holds $400 million or $40 billion in assets, both answer to the same interagency guidance.
A larger regional bank usually has a dedicated TPRM function to point to when the question comes up mid-exam. Most community institutions do not, which is exactly why a vendor question showing up inside three exams instead of one matters more here than almost anywhere else in the industry.
What to Fix Before Your Next Exam
Institutions heading into a cycle where vendor questions can surface almost anywhere need one vendor record that every team touching those relationships already draws from. Tier it by risk, so the highest-exposure relationships get watched continuously rather than once a year. That record needs evidence current enough to answer the same question the same way twice, no matter which exam asks it first.
None of this requires a new department. It requires the three teams already touching vendor relationships to work from one file instead of three. That is a smaller lift than most institutions assume, and considerably smaller than the conversation that follows when a second examiner gets a different answer than the first one did.
Give Every Exam the Same Current Answer
Mitratech Prevalent keeps vendor evidence current through continuous monitoring, so lending, compliance, and IT are never working from three different files.
Explore Continuous MonitoringAsk Henry Questions I Get About Vendor Risk Exams
GRC Answers from Henry Umney, Managing Director of GRC Strategy at Mitratech
Why is vendor risk showing up in exams that aren't about vendors?
Does the FFIEC retiring the CAT tool actually change anything for credit unions, since NCUA runs its own cybersecurity program?
Do smaller institutions get more time or a lighter standard because they have fewer resources?
What's the fastest way to know if our vendor program would hold up across three different exam areas?
Should we be worried about vendors we don't directly manage, like our processor's subprocessors?
How much manual work does producing that evidence actually take?
What's the one thing you would tell a CRO or head of TPRM at a community bank to fix first?
What does NCUA's 2026 supervisory letter require for third-party risk?
What replaced the FFIEC's Cybersecurity Assessment Tool?
Cómo puede ayudar Mitratech
Most of what examiners are asking for now assumes an institution can already produce one current vendor record. Most community banks and credit unions cannot, not because the teams aren’t capable, but because the record itself has never been unified. Mitratech Prevalent builds that record once. Its Framework Mapping capability runs a single assessment against a library of standard questionnaires and maps the results to NIST CSF 2.0, the interagency guidance, and dozens of other frameworks examiners recognize. Continuous monitoring keeps the evidence behind the highest-risk vendors current instead of letting it age for a year between reviews, and the same visibility extends to the vendors those vendors depend on. Lending, compliance, and IT end up working from the same file, so the answer does not change depending on which exam asks first. Explore Mitratech Prevalent.
