Interagency Guidance on Third-Party Relationships
This is guidance issued jointly by the three U.S. federal banking regulators, the Office of the Comptroller of the Currency (OCC), the Federal Reserve, and the Federal Deposit Insurance Corporation (FDIC), finalized in June 2023 to help banks manage the risks that come from working with outside companies. It sets out principles for how banks should oversee any business arrangement with another entity, rather than prescribing a single required checklist. Because it is principles-based, banks are expected to scale their practices to the nature and risk of each relationship.
The Interagency Guidance on Third-Party Relationships: Risk Management is a final, principles-based supervisory guidance jointly issued by the OCC, the Federal Reserve, and the FDIC, published in the Federal Register on June 9, 2023. It addresses any business arrangement between a banking organization and another entity, whether established by contract or otherwise, and promotes a flexible, risk-based approach to third-party risk management that institutions may adjust to the specific facts and risk profile of each relationship. The guidance applies to banking organizations supervised by the issuing agencies; per the OCC bulletin it applies to all banks with third-party relationships, and the underlying guidance does not impose a consolidated-asset threshold. Note that a separately issued Federal Reserve community-bank resource (SR 24-2 / CA 24-1, dated May 8, 2024) is a voluntary guide oriented toward smaller institutions and should not be conflated with the scope of the underlying interagency guidance itself. As guidance rather than a rule, it establishes supervisory expectations and sound principles that banking organizations may consider, and it does not by itself constitute a certification, an enforceable standard with prescriptive controls, or a substitute for an institution's own governance, due diligence, and ongoing monitoring processes.
Why it matters
For U.S. banking organizations, third-party risk management is not merely a matter of good practice, it is a subject of active supervisory attention. The Interagency Guidance on Third-Party Relationships: Risk Management, finalized jointly by the OCC, the Federal Reserve, and the FDIC and published in the Federal Register on June 9, 2023, consolidated and replaced the individual agencies' prior, sometimes divergent guidance with a single set of principles. This matters because it establishes a common baseline of supervisory expectations that examiners across all three agencies can reference when evaluating how a bank oversees its outside business arrangements.
The guidance is deliberately principles-based rather than prescriptive, which is both its strength and a source of practical difficulty. Because it does not supply a mandatory checklist, banks are expected to exercise judgment and scale their due diligence and monitoring to the nature and risk of each relationship. A relationship that supports a critical activity typically warrants more rigorous oversight than a low-risk, easily substitutable arrangement. This flexibility places the burden on the institution to justify its risk-tiering decisions and to demonstrate that its practices are commensurate with the risk involved.
It is important not to overstate what the guidance is. As supervisory guidance rather than a rule, it does not by itself impose enforceable, prescriptive controls, confer any certification, or substitute for an institution's own governance and ongoing monitoring. Its scope is limited to banking organizations supervised by the issuing agencies; it is not a general-purpose third-party risk framework for non-bank sectors, and it does not resolve every operational, financial, or information-security question a bank must address on its own.
Who it's relevant to
Inside Interagency Guidance on Third-Party Relationships
Common questions
Answers to the questions practitioners most commonly ask about Interagency Guidance on Third-Party Relationships.
