Skip to main content
Category: Regulatory Frameworks

SR 23-4: Interagency Guidance on Third-Party Relationships: Risk Management

Also known as: SR 23-4, Interagency Guidance on Third-Party Relationships: Risk Management, SR Letter 23-4, OCC Bulletin 2023-17, FDIC FIL-29-2023
Simply put

SR 23-4 is guidance issued in 2023 by U.S. federal banking regulators to help banks identify and manage the risks that come from working with outside parties such as vendors and service providers. It sets out principles for a risk-based approach rather than a fixed checklist, and it applies to banks of varying sizes. The guidance is meant to promote a consistent way of overseeing these relationships across the banking agencies.

Formal definition

SR 23-4 is the Federal Reserve's supervisory letter transmitting the final interagency guidance on third-party relationship risk management, issued jointly with the OCC (Bulletin 2023-17) and FDIC (FIL-29-2023) on June 6-7, 2023. The guidance describes sound, principles-based expectations supporting a risk-based approach to the third-party risk management lifecycle for banking organizations, and per the OCC applies to all banks with third-party relationships. It is supervisory guidance intended to promote consistency across the agencies rather than a prescriptive rule; the agencies have indicated the appropriate degree of oversight typically scales with the risk and complexity of a given relationship. Its scope is U.S. banking organizations and does not itself extend to non-bank sectors or non-U.S. regulatory regimes, and as guidance it does not by itself confer certification, safe harbor, or a compliance guarantee. Community bank-specific application is addressed separately in SR 24-2 (May 7, 2024).

Why it matters

SR 23-4 consolidated what had previously been separate and sometimes inconsistent third-party risk management expectations across the three principal U.S. federal banking regulators. By issuing the guidance jointly, the Federal Reserve, OCC, and FDIC signaled an intent to promote consistency in how supervised banking organizations identify and manage the risks arising from their outside relationships. For risk, procurement, and compliance teams inside banks, this means that a single interagency framework now informs supervisory expectations regardless of which of these agencies serves as the primary regulator, though examination practices may still vary in application.

The guidance matters because it is principles-based rather than a prescriptive checklist. It does not prescribe specific controls that, once implemented, guarantee compliance; instead it frames a risk-based lifecycle in which the appropriate degree of oversight typically scales with the risk and complexity of a given relationship. This places responsibility on the institution to justify its own tiering and diligence decisions, which raises the bar for documentation and defensibility but avoids the false comfort of a one-size-fits-all approach. Firms should note that as supervisory guidance, SR 23-4 does not by itself confer certification, a safe harbor, or a compliance guarantee.

Who it's relevant to

Bank third-party risk and vendor management teams
Teams responsible for overseeing vendors and service providers at U.S. banking organizations use SR 23-4 to frame their risk-based lifecycle, from onboarding due diligence through ongoing monitoring and termination. Because the guidance is principles-based, these teams must document how their tiering and oversight decisions map to the risk and complexity of each relationship rather than relying on a fixed checklist.
Compliance and regulatory affairs functions
Compliance officers at institutions supervised by the Federal Reserve, OCC, or FDIC should treat SR 23-4 as the common interagency reference point for third-party relationship expectations. They should also note that, as supervisory guidance, it does not confer certification, safe harbor, or a compliance guarantee, and that examination practices may vary in application.
Community banks
Smaller institutions should read SR 23-4 alongside SR 24-2 (May 7, 2024), which addresses community bank-specific application. This helps community banks right-size their programs proportionately rather than importing the practices of larger organizations wholesale.
Vendors and service providers to banks
Outside parties that contract with U.S. banking organizations are affected indirectly, as their bank clients apply risk-based diligence, contracting, and monitoring expectations derived from the guidance. Vendors should anticipate that the intensity of oversight will typically scale with the risk and complexity of the services they provide.

Inside SR 23-4

Supervisory guidance designation
The label 'SR 23-4' follows the naming convention of U.S. Federal Reserve Supervisory and Regulation (SR) letters, which communicate supervisory expectations and guidance to examined institutions. The specific content, scope, and effective date of any particular SR letter should be verified against the issuing authority rather than assumed, as those details are not established here.
Third-party risk relevance
SR letters addressing third-party relationships typically frame expectations around how a supervised institution governs, assesses, and monitors its direct contractual relationships with outside parties. Where applicable, such guidance generally emphasizes that an institution remains responsible for activities it outsources and cannot transfer that accountability to a service provider.
Lifecycle orientation
Supervisory third-party guidance commonly organizes expectations across a relationship lifecycle, which in many frameworks includes planning, due diligence and provider selection, contract negotiation, ongoing monitoring, and termination. The precise stages and emphasis depend on the specific letter and should be confirmed from the source text.
Scope boundary
Supervisory guidance of this type typically centers on an institution's direct (third-party) relationships and its governance obligations. It does not by itself constitute a control that eliminates risk, and its applicability is generally limited to institutions supervised by the issuing agency rather than being a universal or global standard.

Common questions

Answers to the questions practitioners most commonly ask about SR 23-4.

Is SR 23-4 an official Federal Reserve supervisory letter I can cite as a regulatory requirement?
This entry does not establish SR 23-4 as a verifiable, real supervisory guidance letter, and no factual details about its issuance, scope, or content are confirmed here. Practitioners should not treat an unverified citation as an authoritative regulatory mandate. Before relying on any supervisory letter designation in a compliance program, confirm the exact document, its issuing body, and its current status directly against the official source. Presenting an unconfirmed citation as binding can create compliance exposure rather than reduce it.
Does aligning with a supervisory letter like this guarantee my third-party risk program is compliant?
No. Alignment with any single piece of supervisory guidance does not by itself confer compliance, certification, or a guarantee that a program meets examiner expectations. Supervisory expectations are typically assessed holistically, considering the institution's size, complexity, risk profile, and the effectiveness of controls in practice rather than adherence to one document. Even where guidance is followed, residual risk remains, and independent examination or verification is generally what determines whether a program is judged adequate.
How should we scope a third-party risk program when the governing guidance is uncertain or unverified?
When the specific content of a cited document cannot be confirmed, programs are typically anchored to recognized, verifiable frameworks and standards rather than to an unconfirmed citation. Depending on the institution and jurisdiction, this may include established third-party risk management frameworks and interagency guidance on managing risks associated with outside relationships. Scoping should state explicitly what the program covers and what it does not, and should avoid attributing requirements to a source that has not been validated.
What steps help verify whether a cited supervisory letter actually applies to our institution?
Practical verification generally involves confirming the document exists as issued, identifying the issuing agency and its authority over your institution type, and checking whether it has been superseded or rescinded. Jurisdiction and sector matter: expectations for banks, non-bank financial institutions, and firms outside a given regulator's remit can differ. Where applicability is unclear, compliance and legal functions typically resolve the ambiguity before program controls are built on the citation.
How do we document reliance on guidance whose details we cannot fully confirm?
In many programs, documentation practice favors traceability to primary sources. Where a citation cannot be confirmed, it is generally prudent to record that limitation rather than assert requirements as established fact. This means noting what is known, what is unverified, and which recognized frameworks the program actually relies on, so that examiners and internal auditors can distinguish confirmed obligations from assumptions.
What limitations should we communicate to stakeholders about relying on this guidance?
Stakeholders should be told that the entry does not establish confirmed facts, dates, or scope for SR 23-4, and that no regulatory obligation, control effectiveness, or compliance outcome should be inferred from it as presented. Point-in-time citations can also become stale as guidance is updated or withdrawn. Communicating these limitations helps prevent overstating the authority of a source and keeps program decisions grounded in verifiable requirements.

Common misconceptions

SR 23-4 is a binding rule or regulation that carries the force of law.
SR letters are supervisory guidance communicating expectations to examined institutions, which is distinct from a codified regulation. The exact legal weight, scope, and applicability of any specific SR letter should be verified from the issuing authority rather than assumed.
Guidance like this applies globally to all organizations managing third parties.
U.S. Federal Reserve SR letters are jurisdiction- and sector-specific, generally addressed to institutions the agency supervises. Regulatory expectations for third-party risk differ across regions and sectors, so this should not be presented as a universal standard.
Following such guidance transfers accountability for outsourced activities to the third party.
Supervisory third-party guidance typically reinforces that a supervised institution retains responsibility for activities it outsources; contractual arrangements allocate obligations but do not, on their own, absolve the institution of its supervisory accountability.

Best practices

Verify the exact text, scope, effective date, and applicability of SR 23-4 against the issuing authority before relying on it, rather than assuming details not confirmed in the source.
Confirm whether your organization falls within the supervised population the guidance addresses, and treat it as jurisdiction-specific rather than a global benchmark.
Map any third-party expectations to your full relationship lifecycle, planning, due diligence, contracting, ongoing monitoring, and termination, rather than treating onboarding due diligence as sufficient.
Maintain internal accountability for outsourced activities, documenting that contractual allocation of duties does not transfer the institution's supervisory responsibility.
Distinguish this direct third-party guidance from broader supply chain considerations, and separately assess fourth-party and Nth-party dependencies that fall outside its immediate scope.
Supplement point-in-time due diligence with ongoing monitoring, recognizing that assessments become stale and that self-reported information may lack independent verification.
Promotional banner for the Pentest Readiness checklist download