Skip to main content
Category: Regulatory Frameworks

OCC Bulletin 2013-29

Also known as: Third-Party Relationships: Risk Management Guidance, OCC Third-Party Risk Management Guidance (2013)
Simply put

OCC Bulletin 2013-29 was guidance issued by the U.S. Office of the Comptroller of the Currency (OCC) on October 30, 2013, that told the national banks and federal savings associations it supervises how to assess and manage the risks of working with outside parties. It set out expectations for overseeing third-party relationships across their full life cycle, from planning and due diligence through ongoing monitoring and termination. It has since been rescinded and replaced, so it no longer represents the OCC's current supervisory position.

Formal definition

OCC Bulletin 2013-29, titled 'Third-Party Relationships: Risk Management Guidance' and issued October 30, 2013, provided supervisory guidance to national banks and federal savings associations for assessing and managing risks arising from third-party relationships. It defined a third-party relationship broadly as any business arrangement between the bank and another entity, by contract or otherwise, and articulated a risk management life cycle spanning planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination, supported by oversight and accountability, documentation, and independent review. As OCC guidance rather than a regulation, it did not carry the force of a rule and did not by itself confer compliance; it also focused on the supervised institution's direct third-party relationships and did not fully address multi-tier supply chain or Nth-party exposure. It was supplemented by FAQ bulletins (OCC Bulletin 2017-21, subsequently rescinded and replaced by OCC Bulletin 2020-10 on March 5, 2020). OCC Bulletin 2013-29 and OCC Bulletin 2020-10 were rescinded on June 6, 2023 by OCC Bulletin 2023-17, which finalized interagency guidance on third-party relationship risk management; practitioners should therefore treat 2013-29 as superseded and consult current interagency guidance for applicable expectations, noting that supervisory frameworks vary by regulator and jurisdiction.

Why it matters

OCC Bulletin 2013-29 shaped how a large segment of the U.S. banking sector approached third-party risk for roughly a decade. Issued on October 30, 2013, it articulated an end-to-end risk management life cycle, planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination, that many institutions, and even non-banks, adopted as a de facto reference model. Its influence extended well beyond the national banks and federal savings associations the OCC directly supervises, informing vendor management program design across industries that borrowed its life-cycle structure.

Its practical importance today is qualified by a critical fact: OCC Bulletin 2013-29 has been rescinded. On June 6, 2023, OCC Bulletin 2023-17 finalized interagency guidance on third-party relationship risk management and rescinded both OCC Bulletin 2013-29 and OCC Bulletin 2020-10. (Separately, the FAQ bulletin 2017-21 had already been rescinded and replaced earlier, by OCC Bulletin 2020-10 on March 5, 2020.) Practitioners who still cite 2013-29 as current supervisory expectation risk building programs against a superseded standard.

Because it was guidance rather than a regulation, 2013-29 never carried the force of a rule and did not by itself confer compliance. It also focused on an institution's direct third-party relationships and did not fully address multi-tier supply chain or Nth-party exposure. Readers should treat it as a historically significant document that informs the lineage of current expectations, but should consult the applicable interagency guidance now in effect, recognizing that supervisory frameworks vary by regulator and jurisdiction.

Who it's relevant to

Bank third-party risk and vendor management teams
Teams at national banks and federal savings associations built programs against 2013-29 for nearly a decade. They now need to understand which elements carried forward into the current interagency guidance and where expectations have shifted, rather than continuing to reference a rescinded bulletin as authoritative.
Compliance and audit functions
Compliance officers and internal auditors reviewing legacy documentation, policies, or control frameworks will encounter references to 2013-29. They should flag such references as pointing to superseded guidance and confirm alignment with the interagency guidance finalized by OCC Bulletin 2023-17 on June 6, 2023.
Non-bank organizations that adopted the life-cycle model
Many organizations outside banking adopted the 2013-29 life-cycle structure as a practical template for vendor oversight. These teams benefit from understanding the guidance's origin and its limits, particularly that it addressed direct third-party relationships and not multi-tier or Nth-party exposure, when deciding how far to rely on it as a reference.
Vendors and service providers to supervised institutions
Third parties serving OCC-supervised banks were often expected to support due diligence, contracting, and monitoring practices shaped by 2013-29. They should track how current interagency guidance affects the expectations their banking clients place on them, since supervisory frameworks vary by regulator and jurisdiction.

Inside OCC Bulletin 2013-29

Purpose and Scope (Historical)
OCC Bulletin 2013-29, 'Third-Party Relationships: Risk Management Guidance,' was issued by the Office of the Comptroller of the Currency on October 30, 2013, to set supervisory expectations for how national banks and federal savings associations manage risks arising from third-party relationships. It should be treated as historical: the bulletin was rescinded on June 6, 2023 by OCC Bulletin 2023-17, which adopted the Interagency Guidance on Third-Party Relationships issued jointly by the OCC, Federal Reserve, and FDIC. Practitioners citing it today should confirm applicability against the current interagency guidance rather than assume 2013-29 remains in effect.
Third-Party Relationship (Broad Definition)
The bulletin defined a third-party relationship broadly as any business arrangement between a bank and another entity, by contract or otherwise. This scope extended beyond conventional vendors to include service providers, affiliates, and other partners, reflecting a TPRM orientation centered on the bank's direct relationships rather than full multi-tier supply chain mapping.
Life Cycle Risk Management Approach
The guidance framed third-party risk management as a life cycle comprising planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination. It emphasized that due diligence at onboarding is not sufficient on its own and must be paired with ongoing monitoring throughout the relationship.
Oversight and Accountability
The bulletin assigned oversight and accountability responsibilities, describing roles for the board of directors and senior management, along with documentation, independent reviews, and reporting. It stressed that a bank cannot outsource ultimate responsibility for risk to a third party even when activities are delegated.
Critical Activities and Risk Tiering
The guidance directed banks to apply more comprehensive and rigorous oversight to third-party relationships involving 'critical activities,' calibrating the intensity of due diligence and monitoring to the risk and criticality of the arrangement rather than applying uniform treatment to all vendors.
FAQ Supplement (2020-10)
The OCC supplemented the bulletin's expectations through frequently asked questions. OCC Bulletin 2017-21 issued FAQs, and OCC Bulletin 2020-10, issued March 5, 2020, rescinded and replaced 2017-21. Bulletin 2020-10 was subsequently rescinded together with 2013-29 by OCC Bulletin 2023-17 on June 6, 2023.

Common questions

Answers to the questions practitioners most commonly ask about OCC Bulletin 2013-29.

Is OCC Bulletin 2013-29 still the current OCC guidance on third-party risk management?
No. OCC Bulletin 2013-29 was rescinded and is no longer in effect. It was superseded by the interagency third-party risk management guidance that consolidated expectations across the federal banking agencies. Practitioners should treat 2013-29 as historical context rather than active guidance, and refer to the current interagency guidance for present supervisory expectations. Note that supervisory expectations can also differ by institution size, risk profile, and activity, so the applicable framework depends on the specific regulator and jurisdiction.
Does compliance with OCC Bulletin 2013-29 constitute a certification or a guarantee that a bank's third-party risk is adequately managed?
No. OCC Bulletin 2013-29 was supervisory guidance describing expectations for a third-party risk management life cycle; it never functioned as a certification, and following it did not eliminate third-party risk or guarantee a favorable examination outcome. Guidance of this type typically sets expectations that examiners weigh in context rather than establishing a pass/fail credential. Adherence to a life-cycle framework addresses process expectations but does not by itself verify a third party's actual controls or resolve financial, operational, or concentration risk.
How did OCC Bulletin 2013-29 describe the third-party risk management life cycle?
The bulletin framed third-party risk management as a life cycle spanning planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination, supported by oversight elements such as governance, documentation and reporting, and independent review. This life-cycle framing distinguishes onboarding activities (planning, due diligence, contracting) from continuous activities (ongoing monitoring), reflecting the expectation that assessment does not end at selection. In practice the depth applied to each stage was expected to scale with the risk and criticality of the relationship.
What did OCC Bulletin 2013-29 say about applying oversight proportionate to risk?
It reflected a risk-based approach in which the rigor of due diligence and ongoing monitoring was expected to correspond to the risk and complexity of the relationship, with heightened attention to arrangements involving critical activities. This means not every third party warranted the same depth of review; higher-risk or critical relationships typically called for more extensive due diligence, contract provisions, and monitoring. The bulletin emphasized that management, not the third party, remained responsible for the risk arising from these relationships.
How did OCC Bulletin 2013-29 address contracts and ongoing monitoring as distinct stages?
The bulletin treated contract negotiation and ongoing monitoring as separate but connected stages. Contract provisions were expected to address matters such as performance measures, reporting, audit and remediation rights, and termination, while ongoing monitoring covered the continued assessment of a third party's performance and control environment over the life of the relationship. This separation reflects that a signed contract is a point-in-time arrangement, whereas monitoring is intended to detect changes in a third party's risk profile after onboarding.
Now that OCC Bulletin 2013-29 has been rescinded, what should institutions reference for third-party risk management expectations?
Institutions should refer to the current interagency third-party risk management guidance that replaced 2013-29, and confirm which supervisory expectations apply to them based on their primary regulator, size, and activities. Because expectations can vary by regulator and by sector, the applicable framework is jurisdiction- and institution-specific rather than uniform. Programs built around the 2013-29 life-cycle concepts may still align broadly with current expectations, but institutions should validate their frameworks against the guidance presently in effect rather than the rescinded bulletin.

Common misconceptions

OCC Bulletin 2013-29 is the current, in-effect guidance for third-party risk management at OCC-supervised institutions.
The bulletin was rescinded on June 6, 2023 by OCC Bulletin 2023-17, which adopted the Interagency Guidance on Third-Party Relationships developed with the Federal Reserve and FDIC. Institutions should reference the current interagency guidance; 2013-29 is now historical.
OCC Bulletin 2017-21 was rescinded on June 6, 2023 alongside 2013-29.
OCC Bulletin 2017-21 was already rescinded earlier, by OCC Bulletin 2020-10 on March 5, 2020. The June 6, 2023 rescission under OCC Bulletin 2023-17 applied to 2013-29 and 2020-10, not to 2017-21.
The guidance was limited to information security or technology vendors.
The bulletin defined third-party relationships broadly to include any business arrangement by contract or otherwise, spanning service providers, affiliates, and partners. Its scope was not confined to information security and addressed risk management across the relationship life cycle.

Best practices

Confirm current applicability: because OCC Bulletin 2013-29 was rescinded on June 6, 2023 by OCC Bulletin 2023-17, map any legacy program controls to the current Interagency Guidance on Third-Party Relationships rather than relying on 2013-29 as the governing standard.
Apply risk management across the full life cycle, planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination, rather than treating onboarding due diligence as a one-time exercise.
Calibrate oversight intensity to criticality by tiering third-party relationships and reserving the most rigorous due diligence and monitoring for those involving critical activities.
Preserve board and senior management accountability, documenting that ultimate responsibility for risk remains with the institution even where activities are delegated to a third party.
Track the version history of supporting FAQs (2017-21 superseded by 2020-10 on March 5, 2020; both 2013-29 and 2020-10 rescinded on June 6, 2023) so program references cite instruments that are actually in effect.
Supplement point-in-time due diligence with ongoing monitoring, recognizing that onboarding assessments become stale and that self-reported information may require independent verification.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps