On September 15, 2026, the OCC, Federal Reserve Board, FDIC, and NCUA published proposed guidance for how banks and credit unions manage third-party relationships. The document is non-enforceable guidance rather than a rule, and comments remain open through November 16. One sentence matters outside the compliance office: using a third party does not diminish a financial institution's responsibility for sound risk management and compliance with applicable law. A vendor may run the app, payment processor, fraud tool, or another part of the service. Its system may be the technical cause of a delay or error. The bank or credit union still has the customer relationship and the case that needs a next step.
That responsibility can outlast a slow repair. The proposal recognizes that some risk remains after safeguards are added, especially when an institution has limited bargaining power or few alternatives. It does not create a new customer right or promise an immediate fix, and consumer-compliance issues sit outside its direct scope.
Leave with four answers
Before ending a support call or chat, ask:
- What is the case or reference number for this problem?
- Which team or named owner has the case now?
- When is the next update due, and where will it arrive?
- What record will confirm that the problem was corrected?
So write down the date, the official support channel you used, and what the representative promised. Keep passwords, verification codes, and full account numbers out of unsecured notes, screenshots, and messages. Start from a phone number on your statement, the official app, or the institution's verified website.
That four-part record turns a vague handoff into a traceable case. It does not guarantee a fast repair. It gives you something specific to refer to if the next representative starts from the beginning.
This is general orientation, not legal, financial, regulatory, or cybersecurity advice.
A vendor name may explain the handoff. It should not end the bank's conversation with its customer.
