OCC Third Party Guidance
Definition
OCC Third Party Guidance
OCC third party guidance refers to the Office of the Comptroller of the Currency’s expectations for national banks that manage outside relationships. It is now interagency rather than agency specific, replacing the bulletin most vendor programmes were built on.
For a decade the reference document was OCC Bulletin 2013-29, and the industry built its vocabulary around it.
A 2020 set of frequently asked questions extended that guidance and became almost as widely cited.
Both are gone — and any programme still citing them by number is describing a framework the agency has formally withdrawn.
Key takeaways
- Bulletin 2023-17 issues the interagency guidance developed with the Federal Reserve and the FDIC.
- It rescinds both Bulletin 2013-29 and the 2020 third party frequently asked questions.
- The guidance is organised around the life cycle of a third party relationship.
- One standard now applies across all three federal banking agencies.
How it works
The bulletin does two things at once. It issues the Interagency Guidance on Third-Party Relationships: Risk Management developed jointly with the Federal Reserve Board and the Federal Deposit Insurance Corporation.
It also clears the ground behind it — the bulletin rescinds Bulletin 2013-29 and Bulletin 2020-10, the third party frequently asked questions that supplemented it.
The framework is life cycle based. Planning, due diligence and selection, contract negotiation, ongoing monitoring and termination each carry their own expectations rather than being treated as one event.
That structure is what catches thin programmes. A bank can be strong at contracting and weak at monitoring, and the life cycle framing makes the imbalance visible.
| Life cycle stage | What the bank has to be able to show |
|---|---|
| Planning | Why the activity is being outsourced and what risk it carries |
| Due diligence | Evidence gathered before selection, proportionate to risk |
| Contracting | Terms covering performance, access, reporting and exit |
| Ongoing monitoring | Continuing assessment rather than annual attestation |
| Termination | An orderly path out that does not disrupt customers |
The interagency character is the practical change — a national bank with an insured depository subsidiary once mapped its programme against several documents, and now maps it against one.
The accountability principle is unchanged from the FDIC’s statement of it. A banking organisation’s use of third parties does not diminish or remove its responsibility to perform all activities in a safe and sound manner and in compliance with applicable laws.
Examples
National banks run large and layered supplier estates, and the life cycle framing exposes where they thin out. What follows are decisions somebody had to defend rather than options somebody presented.
A national bank’s vendor policy still cites Bulletin 2013-29 throughout. The substance is close to current expectations, but the citation signals a programme that has not been reviewed.
A bank onboards a fintech partner quickly to meet a product deadline. Planning and due diligence were compressed, and the life cycle framing makes that visible rather than hidden.
A large institution monitors providers through annual questionnaires. Ongoing monitoring means continuing assessment, and a once-a-year form is a weak version of it.
A bank terminates a provider without a tested exit path. Customers feel the gap, which turns a supplier decision into a supervisory conversation.
Related terms
Third party risk terminology sits across several agencies and several industries at once. The definitions below help you pick the right obligation rather than the loudest one.
- Banking outsourcing: the underlying practice this guidance addresses.
- Vendor management outsourcing: the operating programme that implements the life cycle.
- Multi vendor outsourcing: several providers at once, which complicates monitoring.
- Regulated outsourcing: supervised sector outsourcing across industries.
- SOC 2 outsourcing: the assurance report used as diligence evidence.
- Risk outsourcing: moving risk activity out without moving responsibility.
- Compliance outsourcing: contracting the compliance function rather than an operational one.
FAQ
Is Bulletin 2013-29 still current?
No. Bulletin 2023-17 rescinded it along with the 2020 third party frequently asked questions.
Does the guidance differ between agencies?
No. That is the point of it. The Comptroller, the Federal Reserve and the FDIC issued the same document.
What are the life cycle stages?
Planning, due diligence and selection, contract negotiation, ongoing monitoring and termination. Each stage carries expectations of its own.
Does the guidance cover fintech partnerships?
Yes. Relationships with financial technology companies were a stated reason for developing the joint guidance, and they receive specific attention in it.
Is annual review enough for monitoring?
Ongoing monitoring means continuing assessment. An annual questionnaire is usually treated as insufficient on its own.
Do we need to rewrite our programme?
Usually not the substance, but the references and the life cycle mapping should both be updated.
Compare verified partners in the Outsource Accelerator directory and shortlist firms that already sit inside a supervised relationship.







Independent




