OCC Bulletin 2023-17: Third-Party Risk for Community Banks
In June 2023, the OCC, Federal Reserve, and FDIC jointly issued the Interagency Guidance on Third-Party Relationships: Risk Management — published by the OCC as Bulletin 2023-17. It replaced each agency's separate legacy guidance (including OCC Bulletin 2013-29, which was rescinded) and gave all federally supervised banks a single framework. If your vendor management policy still cites the pre-2023 documents, that citation is itself a gap.
The core principle: risk-based, bank-owned
The guidance's central idea is that a bank's use of third parties does not diminish its responsibility to operate safely and in compliance with law. Oversight should be commensurate with the risk of each relationship — a core processor and a landscaping vendor do not deserve the same file — but the bank, and ultimately its board, owns the risk either way.
The lifecycle examiners walk
Planning
Before engaging a third party: what activity is being outsourced, what risks does it carry, and can the bank oversee it? For relationships supporting critical activities, examiners expect this analysis to be documented, not remembered.
Due diligence and selection
Depth scales with risk: financial condition, operational resilience, information security, subcontractor reliance, and legal and compliance posture. The guidance acknowledges community banks may have limited negotiating leverage with large vendors — what it does not excuse is skipping the assessment.
Contract negotiation
Contracts for higher-risk relationships should address performance measures, audit and information rights, data security and breach notification, business continuity, subcontracting limits, and termination. A contract the bank cannot exit is a finding waiting for its exam.
Ongoing monitoring
The stage where most community bank programs are thinnest. Due diligence performed once at onboarding and never refreshed is one of the most common third-party findings in public enforcement history. Monitoring cadence, metrics, and escalation paths should exist in writing and leave evidence they ran.
Termination
Planned exits — data return and destruction, transition services, customer impact — documented before they are needed.
Governance expectations
The board is expected to oversee the third-party risk program and receive reporting on critical relationships; management maintains the inventory, the risk assessments, and the monitoring evidence. For a community bank, the entire framework can be lean — the guidance is explicit that sound programs scale to size and complexity. What it must not be is undocumented.
Where policies fall short
The recurring gaps: policies still citing rescinded 2013-era guidance; no documented criticality tiering, so every vendor gets identical (usually minimal) oversight; monitoring described in policy with no artifacts proving it happens; and subcontractor (fourth-party) risk ignored entirely. Each is checkable against your written policy before an examiner checks it for you.
The free RegentForge diagnostic analyzes a bank's published documents — no account, no internal uploads — and returns findings with CFR citations for your counsel to review.
Start the free diagnostic
RegentForge