Skip to main content
Category: Regulatory Frameworks

Interagency Guidance on Third-Party Relationships

Also known as: Interagency Guidance on Third-Party Relationships: Risk Management, Third-Party Relationships: Interagency Guidance on Risk Management
Simply put

This is guidance issued jointly by the three U.S. federal banking regulators, the Office of the Comptroller of the Currency (OCC), the Federal Reserve, and the Federal Deposit Insurance Corporation (FDIC), finalized in June 2023 to help banks manage the risks that come from working with outside companies. It sets out principles for how banks should oversee any business arrangement with another entity, rather than prescribing a single required checklist. Because it is principles-based, banks are expected to scale their practices to the nature and risk of each relationship.

Formal definition

The Interagency Guidance on Third-Party Relationships: Risk Management is a final, principles-based supervisory guidance jointly issued by the OCC, the Federal Reserve, and the FDIC, published in the Federal Register on June 9, 2023. It addresses any business arrangement between a banking organization and another entity, whether established by contract or otherwise, and promotes a flexible, risk-based approach to third-party risk management that institutions may adjust to the specific facts and risk profile of each relationship. The guidance applies to banking organizations supervised by the issuing agencies; per the OCC bulletin it applies to all banks with third-party relationships, and the underlying guidance does not impose a consolidated-asset threshold. Note that a separately issued Federal Reserve community-bank resource (SR 24-2 / CA 24-1, dated May 8, 2024) is a voluntary guide oriented toward smaller institutions and should not be conflated with the scope of the underlying interagency guidance itself. As guidance rather than a rule, it establishes supervisory expectations and sound principles that banking organizations may consider, and it does not by itself constitute a certification, an enforceable standard with prescriptive controls, or a substitute for an institution's own governance, due diligence, and ongoing monitoring processes.

Why it matters

For U.S. banking organizations, third-party risk management is not merely a matter of good practice, it is a subject of active supervisory attention. The Interagency Guidance on Third-Party Relationships: Risk Management, finalized jointly by the OCC, the Federal Reserve, and the FDIC and published in the Federal Register on June 9, 2023, consolidated and replaced the individual agencies' prior, sometimes divergent guidance with a single set of principles. This matters because it establishes a common baseline of supervisory expectations that examiners across all three agencies can reference when evaluating how a bank oversees its outside business arrangements.

The guidance is deliberately principles-based rather than prescriptive, which is both its strength and a source of practical difficulty. Because it does not supply a mandatory checklist, banks are expected to exercise judgment and scale their due diligence and monitoring to the nature and risk of each relationship. A relationship that supports a critical activity typically warrants more rigorous oversight than a low-risk, easily substitutable arrangement. This flexibility places the burden on the institution to justify its risk-tiering decisions and to demonstrate that its practices are commensurate with the risk involved.

It is important not to overstate what the guidance is. As supervisory guidance rather than a rule, it does not by itself impose enforceable, prescriptive controls, confer any certification, or substitute for an institution's own governance and ongoing monitoring. Its scope is limited to banking organizations supervised by the issuing agencies; it is not a general-purpose third-party risk framework for non-bank sectors, and it does not resolve every operational, financial, or information-security question a bank must address on its own.

Who it's relevant to

Bank third-party risk and vendor management teams
These teams are the primary audience. They must translate the guidance's principles into risk-tiering criteria, due diligence procedures, and ongoing monitoring practices that scale to the nature and risk of each relationship, and be prepared to justify those choices to examiners rather than point to a mandated checklist.
Bank compliance and risk governance functions
Because the guidance sets supervisory expectations rather than an enforceable standard with prescriptive controls, compliance and governance functions are responsible for ensuring board and management oversight, documentation, and internal accountability align with the principles across the relationship life cycle.
Community and smaller banking organizations
Smaller institutions remain within the scope of the underlying guidance, which imposes no asset threshold. They may also draw on the voluntary Federal Reserve community-bank resource (SR 24-2 / CA 24-1) for illustrative application, but should treat it as a supplementary aid rather than a substitute for the interagency guidance itself.
Service providers and fintechs serving banks
Outside entities that contract with banks are indirectly affected, as banks will apply risk-based due diligence and ongoing monitoring expectations to them. Such providers may face requests for documentation and contractual terms, though the guidance addresses the bank's obligations and does not by itself impose enforceable requirements on the third party.
Examiners and supervisory staff
Staff at the OCC, Federal Reserve, and FDIC use the guidance as a common reference point when assessing how a supervised institution manages third-party risk, applying it as a set of sound principles rather than a rigid rule.

Inside Interagency Guidance on Third-Party Relationships

Joint Interagency Issuance
The guidance was issued jointly by the three U.S. federal banking agencies, the Federal Reserve, the FDIC, and the OCC, to replace their previously separate and inconsistent third-party risk guidance with a common framework. It applies to banking organizations supervised by these agencies and does not, by itself, extend to non-bank entities outside their supervisory scope.
Risk-Based, Tailored Approach
The guidance does not prescribe a one-size-fits-all program. It contemplates that the level of due diligence and oversight should be commensurate with the risk and complexity of each third-party relationship, so a banking organization's practices are expected to scale with the criticality of the activity rather than treating every relationship identically.
Third-Party Relationship Definition
The guidance frames a third-party relationship broadly as any business arrangement between a banking organization and another entity, by contract or otherwise. This scope is wider than traditional vendor management and can encompass service providers, partnerships, and other arrangements, but it addresses the bank's direct relationships and does not by its own terms map the full multi-tier supply chain.
Critical Activities
The guidance directs heightened attention to relationships that support critical activities, those that could cause significant harm if the third party fails to perform. Identifying which activities are critical is a program-level judgment the banking organization must make; the guidance describes the concept rather than supplying a fixed list.
Risk Management Life Cycle
The guidance describes stages spanning planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination. It emphasizes that oversight is continuous across the relationship and not limited to onboarding due diligence, though the depth of activity at each stage is expected to vary with risk.
Governance and Oversight Expectations
The guidance addresses the roles of the board and management, documentation, and independent reviews, positioning third-party risk management as part of the banking organization's overall risk governance. It sets supervisory expectations rather than a mandatory checklist and leaves implementation details to each institution.

Common questions

Answers to the questions practitioners most commonly ask about Interagency Guidance on Third-Party Relationships.

Does the Interagency Guidance on Third-Party Relationships establish a mandatory checklist or set of controls that banks must implement?
No. The guidance is supervisory guidance rather than a rule, and it does not create binding requirements or a prescriptive checklist. It describes principles and sound risk-management practices that the agencies expect banking organizations to apply in a manner commensurate with the risk and complexity of each third-party relationship. Because it is principles-based, two institutions may implement it differently and both remain consistent with the guidance. Institutions should not treat it as a compliance safe harbor; examiners assess whether a program is appropriate to the organization's specific risk profile, not whether it matches a fixed template.
Does the guidance apply only to large banks, or is there an asset-size threshold that exempts smaller institutions?
The guidance itself applies to banking organizations supervised by the Federal Reserve, FDIC, and OCC without an asset-size threshold, so smaller institutions are within its scope. What varies is how the principles are applied: the guidance contemplates that practices should be scaled to the size, complexity, and risk profile of the institution and its third-party relationships. Separately, the agencies have issued a resource guide intended to help community banks apply the guidance; that supplemental material is directed at smaller institutions but does not narrow the underlying guidance to only large banks.
How should an institution scope which third-party relationships fall under the guidance?
The guidance frames a third-party relationship broadly as any business arrangement between the banking organization and another entity, by contract or otherwise, which can extend well beyond traditional vendors to include arrangements such as service providers and other partners. In practice, institutions typically inventory these relationships and then assess which are more significant based on the risk they present, rather than applying uniform treatment. Scoping decisions should be documented, and the depth of oversight is generally calibrated to the criticality and risk of the activity being supported rather than to the label attached to the counterparty.
What does the guidance expect across the life cycle of a third-party relationship?
The guidance describes a life cycle that typically spans planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination, supported by governance elements such as oversight, documentation, and reporting. A common implementation gap is treating due diligence at onboarding as sufficient; the guidance emphasizes that monitoring should continue throughout the relationship because a third party's risk profile can change over time. Institutions should align the intensity of activity at each stage with the risk of the relationship rather than applying the same effort uniformly.
How does the guidance address risks arising from a third party's own subcontractors?
The guidance recognizes that third parties may rely on subcontractors and other parties to perform activities, and it indicates that a banking organization's risk-management practices should account for these arrangements where they are relevant to the services provided. Institutions typically address this through contract provisions and monitoring that seek visibility into significant subcontracting. It is important to note that visibility beyond the direct third party is often limited in practice, and the guidance does not resolve that limitation; it places responsibility on the institution to understand and manage the risks that subcontracting may introduce.
Does relying on a third party's assessments or certifications satisfy the guidance's expectations?
Not on its own. The guidance contemplates that institutions may use information provided by a third party, but it also emphasizes that the banking organization remains responsible for its own risk management and cannot outsource that responsibility. Depending on the criticality of the relationship, an institution may need to corroborate self-reported information or reports and consider their scope, timing, and any limitations. A report or attestation provided by a third party is one input into due diligence and ongoing monitoring, not a substitute for the institution's independent judgment about whether the relationship is being managed appropriately.

Common misconceptions

The interagency guidance is a rule or regulation that carries specific mandatory requirements and prescribes exactly how to manage third parties.
It is supervisory guidance describing principles and sound practices, not a regulation imposing binding, uniform requirements. It articulates supervisory expectations and leaves the specific implementation to each banking organization based on its risk profile.
The companion 2024 Federal Reserve community bank resource changes who the guidance applies to or creates a $10 billion asset threshold for the guidance itself.
The underlying interagency guidance applies to supervised banking organizations without an asset-size threshold. The separately issued Federal Reserve community-bank guide is a voluntary resource intended to help smaller institutions (generally those with $10 billion or less in consolidated assets) apply the guidance; it does not restrict the guidance's overall scope.
Following the guidance is equivalent to third-party risk management and covers the organization's entire supply chain.
The guidance centers on a banking organization's direct third-party relationships. It does not by itself provide full visibility into fourth-party or Nth-party dependencies or the multi-tier physical and logistical flows that broader supply chain risk management addresses.

Best practices

Calibrate due diligence and ongoing monitoring to the risk and criticality of each relationship rather than applying identical procedures to all third parties, reserving the deepest scrutiny for relationships supporting critical activities.
Treat oversight as a continuous life-cycle activity, covering planning, due diligence, contracting, ongoing monitoring, and termination, rather than a one-time onboarding assessment that can become stale.
Document how the organization identifies which activities are critical, since that determination drives the level of oversight the guidance expects.
Distinguish the underlying interagency guidance from the voluntary Federal Reserve community-bank resource, and confirm which supervisory agency's expectations apply to the institution before designing controls.
Extend inquiry beyond direct third parties where warranted, recognizing that the guidance's focus on direct relationships does not automatically surface fourth-party or Nth-party dependencies.
Engage the board and management in governance of the program and use independent reviews to test whether third-party risk practices are functioning as intended.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide