Financial Services Regulation
DETAIL

Interagency Guidance on Third-Party Relationships: Risk Management (Board, FDIC, OCC, June 2023)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

The Interagency Guidance on Third-Party Relationships: Risk Management is the joint supervisory guidance of the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, and the Office of the Comptroller of the Currency on managing the risks of third-party relationships. It sets out sound risk management principles for banking organizations to consider when developing and implementing risk management practices for all stages in the life cycle of third-party relationships, organized around planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination, together with governance expectations for oversight and accountability, independent reviews, and documentation and reporting.

The three agencies issued the final guidance on June 6, 2023, and it was published in the Federal Register on June 9, 2023 (88 FR 37920). It applies to all banking organizations the agencies supervise and replaced each agency's earlier guidance: the Federal Reserve's SR letter 13-19 / CA letter 13-21, the FDIC's FIL-44-2008, and OCC Bulletins 2013-29 and 2020-10. As supervisory guidance it does not have the force and effect of law and does not impose new requirements, but examiners use it to assess whether a banking organization's practices are commensurate with the level of risk and complexity of its third-party relationships.

Banking organizations implement the guidance by identifying every business arrangement that constitutes a third-party relationship, determining which involve critical activities, and scaling planning, due diligence, contract terms, monitoring, and termination practices to the risk of each. The board of directors oversees the program, management operates it, independent reviews test it, and documentation and reporting give the board and examiners visibility into the organization's third-party risk.

Why it Matters

Banks now depend on third parties for core processing, cloud infrastructure, payments, lending partnerships, and fintech products, and the agencies are clear that using a third party does not diminish a banking organization's responsibility to operate in a safe and sound manner and in compliance with applicable laws. The 2023 guidance is the single supervisory reference examiners apply to that responsibility, replacing three different agency documents.

Key benefits include:

  • One standard across three regulators

The guidance promotes consistency in the agencies' supervisory approach, so a banking organization supervised by more than one agency builds one program rather than three.

  • A life cycle to organize the program

Planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination give third-party risk management a structure that maps directly to policies, workflows, and evidence.

  • Risk-based tailoring

The guidance recognizes that not all relationships carry the same risk and directs more rigorous practices to those supporting critical activities.

  • Clear governance expectations

Oversight and accountability, independent reviews, and documentation and reporting are named as the governance elements the board and examiners look for.

  • Coverage of fintech and non-contractual arrangements

The definition of a business arrangement is intentionally broad and includes relationships without a written contract or remuneration, closing a gap in earlier guidance.

How it Works

The guidance describes third-party risk management in stages. In planning, a banking organization evaluates the risks of a prospective activity and how it will manage them. In due diligence and third-party selection, it assesses the third party's ability to perform the activity as expected, comply with laws, and operate in a safe and sound manner, with the depth of review scaled to the risk. In contract negotiation, it addresses matters such as the nature and scope of the arrangement, performance measures, responsibilities for compliance, information security, audit and remediation rights, subcontracting, business resumption, and termination. In ongoing monitoring, it tracks the third party's performance, condition, and changes over the life of the relationship. In termination, it manages the transition of the activity to another provider, in-house, or discontinuation.

Governance runs across all stages. The board of directors is responsible for oversight and holds management accountable; management establishes the policies, processes, and staffing; independent reviews, typically by internal audit, assess whether the program achieves its objectives; and documentation and reporting record the program's decisions and give the board a view of the risks. The agencies note that banking organizations may use collaborative arrangements, external experts, and shared assessments, and that examiners review third-party risk management as part of supervisory reviews, focusing on relationships that support critical activities.

Within SmartSuite, banking organizations run the life cycle as a managed workflow: each third party carries its inherent and residual risk rating and its critical-activity flag, planning and due diligence records hold the assessments and evidence, contract records hold the negotiated terms and their review dates, monitoring records capture performance, condition, and issues, and termination plans are tracked to completion, with board and examiner reporting drawn from the same records.

Key Elements

  • Broad definition of a third-party relationship

Any business arrangement between a banking organization and another entity, by contract or otherwise, including fintech partnerships and relationships without remuneration.

  • Critical activities

Activities that could cause significant risk if the third party fails to meet expectations, have significant customer impacts, or have a significant impact on the banking organization's financial condition or operations receive more comprehensive oversight.

  • Planning

Assessment of the risks of a prospective activity and how the organization will manage them before selecting a third party.

  • Due diligence and third-party selection

Evaluation of the third party's strategies, financial condition, legal and regulatory compliance, risk management, information security, operational resilience, subcontracting, and other factors scaled to risk.

  • Contract negotiation

Contract terms covering scope, performance, compliance, security, audit rights, subcontracting, business resumption, and termination.

  • Ongoing monitoring

Continued review of the third party's performance and condition and of changes in the relationship's risk.

  • Governance

Board oversight and accountability, independent reviews, and documentation and reporting.

Framework Scope

The guidance applies to all banking organizations supervised by the Federal Reserve Board, the FDIC, and the OCC, including national banks, federal savings associations, federal branches and agencies, state member and nonmember banks, and bank holding companies, and to every business arrangement they have with another entity. It does not address direct relationships with customers for traditional banking products, though third-party lending, payment, and deposit arrangements fall within it. It is supervisory guidance, not a rule, and each organization tailors its practices to its size, complexity, risk profile, and the criticality of the activity.

Framework Objectives

The agencies issued the guidance so that banking organizations manage third-party risk consistently and in proportion to the risk each relationship presents.

Promote consistency in the agencies' supervisory approach to third-party risk management.

Set sound risk management principles for every stage of the third-party relationship life cycle.

Direct the most rigorous practices to relationships that support critical activities.

Make clear that responsibility for safety, soundness, and compliance stays with the banking organization.

Establish board oversight, independent review, and documentation as the governance backbone of the program.

Replace the agencies' separate 2008, 2013, and 2020 guidance with one document.

Framework in Context

The 2023 guidance sits alongside the FFIEC IT Examination Handbook, whose Outsourcing Technology Services booklet examiners use for technology relationships, the OCC's Cybersecurity Supervision Work Program, and the interagency paper on sound practices to strengthen operational resilience. Its life cycle parallels the supply chain requirements of NIST SP 800-161 Rev. 1 and ISO/IEC 27036, and its due diligence expectations are commonly satisfied with SOC 2 reports and the Shared Assessments SIG questionnaire. Internationally it is the U.S. counterpart of the EBA guidelines on outsourcing and third-party risk and the ICT third-party provisions of the EU Digital Operational Resilience Act.

Common Framework Mappings

The guidance is commonly mapped to the U.S. supervisory materials examiners apply with it and to the supply chain and assurance frameworks used to satisfy its due diligence and monitoring expectations.

Mapped frameworks include:

FFIEC IT Handbook

OCC CSWP

GLBA Safeguards Rule (16 CFR Part 314)

NIST SP 800-161 Rev.1

ISO/IEC 27036

NIST CSF 2.0

SOC 2

SIG v2024

EU DORA

EBA GL/2019/02

BCBS Operational Resilience Principles

At a Glance
Interagency Guidance on Third-Party Relationships: Risk Management (Board, FDIC, OCC, June 2023)
  • Classification
    Category
    Financial Services Regulation
    Domain
    Financial Services Regulation
    Framework Family
    Other
  • Regulatory Context
    Type
    Guidance
    Legal Instrument
    Guidance
    Sector
    Financial Sector
    Industry
    Financial Services
  • Region / Publisher
    Region
    North America
    Region Detail
    United States
    Publisher
    Board of Governors of the Federal Reserve System, Federal Deposit Insurance Corporation (FDIC), and Office of the Comptroller of the Currency (OCC)
  • Versioning
    Version
    Final guidance, June 2023 (88 FR 37920)
    Effective Date
    June 6, 2023
    Issue Date
    June 6, 2023 (Federal Register June 9, 2023)
  • Adoption
    Adoption Model
    Regulatory Compliance
    Implementation Complexity
    High
  • Official Reference
License Information

License included / downloadable: Yes

The guidance is a U.S. government publication available free of charge from the three agencies and the Federal Register, and its life cycle structure is included with the platform.

Framework text is licensed by its publisher and is included only where stated above.

Official Resources
Federal Reserve SR 23-4
The Federal Reserve's supervisory letter transmitting the guidance, with the attached text and the guidance it supersedes.
OCC Bulletin 2023-17
The OCC's bulletin on the guidance, its applicability, highlights, and the OCC bulletins it rescinds.
FDIC FIL-29-2023
The FDIC's financial institution letter on the guidance and the FDIC guidance it replaces.
Federal Register notice (88 FR 37920)
The full text of the final guidance as published in the Federal Register on June 9, 2023.
SMARTSUITE

How SmartSuite Supports Interagency Third-Party Guidance

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.

For the Interagency Guidance, SmartSuite runs planning, due diligence, contracting, monitoring, and termination as one workflow per third party, with critical-activity flags, risk ratings, evidence, and board reporting drawn from the same records.

Third-Party Inventory and Risk Tiering

Hold every business arrangement with its inherent and residual risk rating, critical-activity flag, and business owner in one inventory.

Ownership, Cadence, and Accountability

Assign relationship owners, set due diligence and monitoring cycles by risk tier, and route approvals to management and the board.

Evidence Collection and Audit Trail

Attach due diligence reports, SOC reports, financial statements, and contract terms to each relationship with timestamps and reviewers.

Due Diligence and Ongoing Monitoring

Run risk-scaled assessments at selection and on schedule, and track performance issues, incidents, and remediation.

Contract and Termination Management

Record negotiated terms, audit and termination rights, and subcontracting conditions, and manage exit plans to completion.

Board and Examiner Reporting

Report third-party risk posture, critical relationships, open issues, and independent review results for the board and supervisory reviews.

Related frameworks

FFIEC IT Handbook

The FFIEC IT Examination Handbook is the set of booklets U.S. examiners use to assess technology risk management at financial institutions and their service providers.

OCC CSWP

The OCC Cybersecurity Supervision Work Program guides examiners in assessing banks' cybersecurity risk management, controls, and incident response.

GLBA Safeguards Rule (16 CFR Part 314)

The GLBA Safeguards Rule requires financial institutions to implement security programs to protect consumer financial information.

NIST SP 800-161 Rev.1

NIST SP 800-161 Rev. 1 guides organizations to identify, assess, and mitigate cybersecurity risks across their supply chains.

SOC 2

SOC 2 assesses and reports on a service organization's controls for security, availability, processing integrity, confidentiality, and privacy.

SIG v2024

SIG 2024 Standardized Information Gathering standardizes collection of vendors' security, privacy, and compliance information for third-party risk assessments.

EU DORA

DORA is an EU regulation requiring financial firms to manage ICT risks, report incidents, test security, and oversee third-party providers.

BCBS Operational Resilience Principles

The Basel Committee's seven Principles for Operational Resilience set the international baseline for how banks deliver critical operations through disruption.

ONBOARDING FAQS

Frequently Asked Questions For Interagency Third-Party Guidance

What is the Interagency Guidance on Third-Party Relationships?

It is the joint guidance of the Federal Reserve Board, FDIC, and OCC, issued June 6, 2023, on managing the risks of third-party relationships. It sets sound risk management principles for every stage of the relationship life cycle and the governance that surrounds it.

Which organizations does the guidance apply to?

It applies to all banking organizations supervised by the three agencies and to any business arrangement they have with another entity, by contract or otherwise. It does not address direct customer relationships for traditional banking products.

What are the stages of the third-party risk management life cycle?

Planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination, supported by governance through oversight and accountability, independent reviews, and documentation and reporting.

What guidance did it replace?

It replaced the Federal Reserve's SR letter 13-19 / CA letter 13-21, the FDIC's FIL-44-2008, and OCC Bulletins 2013-29 and 2020-10, giving the three agencies one common document.

Is the guidance legally binding?

No. As supervisory guidance it does not have the force and effect of law and does not impose new requirements on banking organizations, but examiners use it to evaluate whether third-party risk management is commensurate with the organization's risk and complexity.

What are critical activities?

Activities that could cause a banking organization to face significant risk if the third party fails to meet expectations, that could have significant customer impacts, or that could have a significant impact on the organization's financial condition or operations. Relationships supporting them warrant more comprehensive oversight.

How does SmartSuite support the guidance?

SmartSuite holds the third-party inventory with risk ratings and critical-activity flags and runs planning, due diligence, contracting, monitoring, and termination as one workflow per relationship, with evidence, issues, and board and examiner reporting in the same system.

Operationalize Interagency TPRM Guidance (2023) with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.