Compliance Guide · 2026 · 08 · 8 min read

OCC Bulletin 2023-17: Third-Party Risk for Community Banks

In June 2023, the OCC, Federal Reserve, and FDIC jointly issued the Interagency Guidance on Third-Party Relationships: Risk Management — published by the OCC as Bulletin 2023-17. It replaced each agency's separate legacy guidance (including OCC Bulletin 2013-29, which was rescinded) and gave all federally supervised banks a single framework. If your vendor management policy still cites the pre-2023 documents, that citation is itself a gap.

The core principle: risk-based, bank-owned

The guidance's central idea is that a bank's use of third parties does not diminish its responsibility to operate safely and in compliance with law. Oversight should be commensurate with the risk of each relationship — a core processor and a landscaping vendor do not deserve the same file — but the bank, and ultimately its board, owns the risk either way.

The lifecycle examiners walk

Planning

Before engaging a third party: what activity is being outsourced, what risks does it carry, and can the bank oversee it? For relationships supporting critical activities, examiners expect this analysis to be documented, not remembered.

Due diligence and selection

Depth scales with risk: financial condition, operational resilience, information security, subcontractor reliance, and legal and compliance posture. The guidance acknowledges community banks may have limited negotiating leverage with large vendors — what it does not excuse is skipping the assessment.

Contract negotiation

Contracts for higher-risk relationships should address performance measures, audit and information rights, data security and breach notification, business continuity, subcontracting limits, and termination. A contract the bank cannot exit is a finding waiting for its exam.

Ongoing monitoring

The stage where most community bank programs are thinnest. Due diligence performed once at onboarding and never refreshed is one of the most common third-party findings in public enforcement history. Monitoring cadence, metrics, and escalation paths should exist in writing and leave evidence they ran.

Termination

Planned exits — data return and destruction, transition services, customer impact — documented before they are needed.

Governance expectations

The board is expected to oversee the third-party risk program and receive reporting on critical relationships; management maintains the inventory, the risk assessments, and the monitoring evidence. For a community bank, the entire framework can be lean — the guidance is explicit that sound programs scale to size and complexity. What it must not be is undocumented.

Where policies fall short

The recurring gaps: policies still citing rescinded 2013-era guidance; no documented criticality tiering, so every vendor gets identical (usually minimal) oversight; monitoring described in policy with no artifacts proving it happens; and subcontractor (fourth-party) risk ignored entirely. Each is checkable against your written policy before an examiner checks it for you.

See how your own public documents read.

The free RegentForge diagnostic analyzes a bank's published documents — no account, no internal uploads — and returns findings with CFR citations for your counsel to review.

Start the free diagnostic