In June 2023, the way the Office of the Comptroller of the Currency evaluates vendor relationships changed. The OCC third-party risk management expectation set that many banks had followed for a decade was rescinded and replaced with a single interagency framework shared by the OCC, the Federal Reserve, and the FDIC.
The guidance your examiners now reference is principles-based, scales to the risk of each relationship, and treats third-party oversight as part of safety and soundness rather than a standalone checklist.
This guide explains how the OCC supervises third-party risk today, including who the rules apply to, what changed in 2023, and the five-stage lifecycle the guidance expects banks to run.

From OCC Bulletin 2013-29 to the 2023 interagency guidance
On June 6, 2023, the OCC, the Federal Reserve, and the FDIC jointly issued the Interagency Guidance on Third-Party Relationships: Risk Management. The OCC adopted it through OCC Bulletin 2023-17, and the guidance rescinded and replaced both Bulletin 2013-29 and the 2020 FAQs.
The other agencies adopted the same text under their own numbering. The Federal Reserve issued it as SR 23-4, and the FDIC issued it as FIL-29-2023. It was published in the Federal Register on June 9, 2023. The purpose of the joint release was to replace three separate agency approaches with one consistent framework.
The current guidance scales oversight to the risk and complexity of each relationship and to the size of the bank. A community bank with a handful of vendors and a large national bank with hundreds of fintech arrangements are held to the same principles, applied at very different scales.
The third-party risk management lifecycle the OCC expects
The interagency guidance organizes third-party risk management around a lifecycle. It describes five stages that run from before a relationship begins through its end, supported by governance that spans all of them:
- Oversight and accountability
- Independent reviews
- Documentation and reporting
The lifecycle is where most examination attention lands, because it shows whether a bank managed a relationship deliberately or reacted to problems after they surfaced. Each lifecycle stage below maps to what the guidance expects and the kind of evidence examiners look for when they test it.
| Lifecycle stage | What the OCC expects | Example evidence examiners look for |
|---|---|---|
| Planning | The bank assesses the risks and benefits of the relationship before committing, and aligns it to strategy and risk appetite | Documented risk assessment, business case, and criticality determination |
| Due diligence and selection | Vendor due diligence scaled to the relationship's risk, covering financial condition, controls, security, and compliance history | Completed due diligence questionnaires, financial reviews, control reports, and selection rationale |
| Contract negotiation | Contracts set clear expectations for performance, security, audit rights, subcontracting, and termination | Executed contracts with defined SLAs, right-to-audit clauses, and exit provisions |
| Ongoing monitoring | Continuous monitoring of performance and risk proportional to the relationship's criticality | Monitoring reports, SOC reports, issue logs, and reassessment records |
| Termination | Orderly exit that protects data, continuity, and the bank's obligations | Termination plans, data return or destruction evidence, and transition records |
Critical Activities and Heightened Due Diligence
The guidance singles out relationships that involve critical activities for more comprehensive oversight. Critical activities are those that, if disrupted, could cause significant harm to the bank, customers, or operations. This includes activities central to core banking operations, or with significant customer-facing exposure.
When a relationship supports a critical activity, the expectations at each lifecycle stage rise:
- Vendor due diligence goes deeper into financial stability, control environments, cybersecurity, subcontractor risk, and resilience.
- Contracts carry stronger performance, audit, and continuity terms.
- Monitoring becomes more frequent and more granular.
The bank concentrates its resources where a failure would hurt most, rather than spreading the same effort across every vendor regardless of risk.
How the OCC examines third-party risk
The OCC examines third-party risk through risk-based supervision inside the safety-and-soundness process. Examiners assess whether the third-party program fits the bank's risk profile, whether the bank identified and managed the risks each relationship introduces, and whether governance and documentation support the decisions made.
When examiners find gaps, they communicate them through supervisory findings. Deficiencies in third-party risk management can result in Matters Requiring Attention, or MRAs, which are practices that deviate from sound risk management and that the OCC expects the bank to correct.
An MRA is not a fine, but it is a formal supervisory concern that the board and management must address. A small bank with simple relationships and a large bank with complex fintech partnerships can both satisfy the OCC, provided each manages its relationships in proportion to the risk they carry.
The 2024 Community Bank TPRM Guide
In May 2024, the OCC, the Federal Reserve, and the FDIC released Third-Party Risk Management: A Guide for Community Banks. The document is a resource designed to help community banks apply the 2023 interagency guidance to their own operations. It offers considerations, questions, and practices community banks can use as they plan, conduct due diligence, negotiate contracts, monitor relationships, and manage exits.
The community bank guide is a resource, not a new rule. It translates the principles into examples and prompts that smaller institutions, which often have leaner staff and fewer vendors, can work with directly. Community banks remain subject to the same principles-based framework as larger institutions.
Building an OCC-Aligned TPRM framework
Building a third-party risk management framework that aligns with OCC expectations starts with knowing what you have.
Maintain a complete inventory of third-party relationships
From here, tier each one by criticality so the depth of due diligence, contracting, and monitoring tracks the risk. A relationship supporting a critical activity should draw far more scrutiny than a low-risk, easily replaced vendor.
Run each relationship through the lifecycle
Make sure to document this as you go. Scale vendor due diligence to risk, write contracts that secure performance and audit and exit rights, and embed ongoing monitoring proportional to criticality.
Keep governance visible
Assign clear ownership, subject the program to independent review, and report to the board on the relationships that matter most.
Platforms like Predict360 include a third-party risk management module that centralizes third-party inventories, tiers vendors by criticality, and generates monitoring reports that support the documentation examiners expect. These tools make a risk program easier to run and evidence consistently.
The next step is to map your own program against the five lifecycle stages and confirm that the depth of work at each stage matches the risk of the relationship. From there, a deeper look at how to build a third-party risk management program and how continuous monitoring supports it will help you turn these expectations into a repeatable process.
Frequently Asked Questions
Does the 2023 interagency guidance apply to fintech partnerships?
Yes. The guidance defines third-party relationships broadly enough to cover fintech arrangements, technology vendors, and other service providers. A fintech partnership is subject to the same lifecycle expectations as any other relationship, with oversight scaled to the risk and complexity involved.
What happens if an OCC examiner finds a third-party risk deficiency?
Examiners communicate deficiencies through supervisory findings, and third-party risk gaps can result in Matters Requiring Attention, or MRAs. An MRA is a formal supervisory concern the board and management must correct, though it is not a monetary penalty.
Do community banks follow different third-party risk rules?
No. Community banks follow the same principles-based 2023 interagency guidance as larger institutions. The May 2024 Third-Party Risk Management: A Guide for Community Banks is a resource. It helps smaller banks apply the guidance at their scale, with examples and questions suited to leaner teams and smaller vendor populations.
The Predict360 Enterprise Risk Management Software ensures managers have complete visibility of enterprise risk on a single dashboard.
Request Demo- Cloud-Based
- Risk Repository
- Assess Risks
- Real-time Monitoring
- 1From OCC Bulletin 2013-29 to the 2023 interagency guidance
- 2The third-party risk management lifecycle the OCC expects
- 3Critical Activities and Heightened Due Diligence
- 4How the OCC examines third-party risk
- 5The 2024 Community Bank TPRM Guide
- 6Building an OCC-Aligned TPRM framework
- 7Frequently Asked Questions