SR 23-4: Interagency Guidance on Third-Party Relationships: Risk Management
SR 23-4 is guidance issued in 2023 by U.S. federal banking regulators to help banks identify and manage the risks that come from working with outside parties such as vendors and service providers. It sets out principles for a risk-based approach rather than a fixed checklist, and it applies to banks of varying sizes. The guidance is meant to promote a consistent way of overseeing these relationships across the banking agencies.
SR 23-4 is the Federal Reserve's supervisory letter transmitting the final interagency guidance on third-party relationship risk management, issued jointly with the OCC (Bulletin 2023-17) and FDIC (FIL-29-2023) on June 6-7, 2023. The guidance describes sound, principles-based expectations supporting a risk-based approach to the third-party risk management lifecycle for banking organizations, and per the OCC applies to all banks with third-party relationships. It is supervisory guidance intended to promote consistency across the agencies rather than a prescriptive rule; the agencies have indicated the appropriate degree of oversight typically scales with the risk and complexity of a given relationship. Its scope is U.S. banking organizations and does not itself extend to non-bank sectors or non-U.S. regulatory regimes, and as guidance it does not by itself confer certification, safe harbor, or a compliance guarantee. Community bank-specific application is addressed separately in SR 24-2 (May 7, 2024).
Why it matters
SR 23-4 consolidated what had previously been separate and sometimes inconsistent third-party risk management expectations across the three principal U.S. federal banking regulators. By issuing the guidance jointly, the Federal Reserve, OCC, and FDIC signaled an intent to promote consistency in how supervised banking organizations identify and manage the risks arising from their outside relationships. For risk, procurement, and compliance teams inside banks, this means that a single interagency framework now informs supervisory expectations regardless of which of these agencies serves as the primary regulator, though examination practices may still vary in application.
The guidance matters because it is principles-based rather than a prescriptive checklist. It does not prescribe specific controls that, once implemented, guarantee compliance; instead it frames a risk-based lifecycle in which the appropriate degree of oversight typically scales with the risk and complexity of a given relationship. This places responsibility on the institution to justify its own tiering and diligence decisions, which raises the bar for documentation and defensibility but avoids the false comfort of a one-size-fits-all approach. Firms should note that as supervisory guidance, SR 23-4 does not by itself confer certification, a safe harbor, or a compliance guarantee.
Who it's relevant to
Inside SR 23-4
Common questions
Answers to the questions practitioners most commonly ask about SR 23-4.
