The Interagency Guidance on Third-Party Relationships: Risk Management is the single document a US bank examiner works from when reviewing how a banking organisation manages its third parties. Issued jointly by the Federal Reserve Board, the FDIC and the OCC, final as of 6 June 2023 and published in the Federal Register on 9 June 2023, it replaced three agencies’ separate guidance with one text. This guide explains what the Interagency Guidance covers, what it rescinded, the lifecycle it describes, and the specific factors an examiner will expect to see considered.
What this guide covers
- What the Interagency Guidance is, and what it replaced
- Scope: what counts as a third-party relationship
- The lifecycle in the Interagency Guidance
- The fourteen due diligence factors
- The seventeen contract considerations
- Monitoring, termination and governance in the Interagency Guidance
- Applying the Interagency Guidance outside US banking
- Frequently asked questions about the Interagency Guidance

What the Interagency Guidance is, and what it replaced
Before June 2023, each agency had its own view. The OCC’s Bulletin 2013-29 and its 2020 frequently asked questions, the Federal Reserve’s 2013 guidance and the FDIC’s 2008 guidance said similar things in different structures, and a banking organisation supervised by more than one of them had to reconcile them. The final Interagency Guidance rescinds and replaces all of them. One earlier document survives: OCC Bulletin 2002-16 on foreign-based third-party service providers is not rescinded and supplements the new text.
The Guidance applies to all banking organisations supervised by the three agencies, and it is principles-based. Almost every list in it is introduced with the words “typically considers the following factors, among others”. That phrasing matters when reading it: the Guidance does not impose a checklist, it describes what sound risk management looks like, commensurate with the risk and complexity of each relationship. An examiner applies it in that spirit, and a programme that treats every factor as mandatory for every vendor has misread it as badly as one that ignores it.
Scope: what counts as a third-party relationship
The Interagency Guidance addresses “any business arrangement between a banking organization and another entity, by contract or otherwise”, and it says plainly that a relationship may exist despite a lack of a contract or remuneration. The examples it gives run from outsourced services and independent consultants to referral arrangements, merchant payment processing, services provided by affiliates and subsidiaries, joint ventures and the use of third parties to provide products to customers. The breadth is deliberate. A programme that only inventories the vendors accounts payable can see will miss the affiliates, partners and referral sources the Guidance explicitly includes.
Within that population the Guidance singles out higher-risk activities, including critical activities, for more comprehensive oversight. Critical activities are those that could cause the organisation significant risk if the third party fails to meet expectations, have significant customer impacts, or have a significant impact on the organisation’s financial condition or operations. The determination is the organisation’s to make, and to document.
The lifecycle in the Interagency Guidance
The core of the text is the third-party relationship lifecycle: planning, due diligence and third-party selection, contract negotiation, ongoing monitoring and termination, with governance running throughout. Our guide to the TPRM lifecycle walks the stages and their records; here the focus is what the Interagency Guidance actually enumerates at each one.
| Stage | What the Guidance enumerates | Count |
|---|---|---|
| Planning | Considerations from strategic purpose and cost through customer impact, security implications, oversight capacity and contingency | 11 |
| Due diligence and selection | Factors (a) to (n), from strategies and goals to contractual arrangements with other parties | 14 |
| Contract negotiation | Considerations (a) to (q), from nature and scope to regulatory supervision | 17 |
| Ongoing monitoring | Considerations from overall effectiveness to customer complaints, plus three typical monitoring activities | 14 |
| Termination | Considerations from transition options to the risks of a failure-driven exit | 6 |
| Governance | Board considerations (3), management activities (10), independent review factors (5), documentation practices (10) | 28 |
The fourteen due diligence factors
Due diligence is where the Interagency Guidance is most specific. The factors, lettered (a) to (n) in the text, are: strategies and goals; legal and regulatory compliance; financial condition; business experience; qualifications and backgrounds of principals; risk management; information security; management of information systems; operational resilience; incident reporting and management; physical security; reliance on subcontractors; insurance coverage; and contractual arrangements with other parties. Each is expanded in the text with what an organisation typically looks for, and each applies with a depth that matches the relationship’s risk.
Two of the fourteen deserve particular attention. Reliance on subcontractors asks not just whether the provider subcontracts but how it oversees those subcontractors and where they are, which is the beginning of fourth-party risk management. Contractual arrangements with other parties asks whether the provider’s other commitments, exclusivities or dependence on other customers could affect its ability to serve you.
The seventeen contract considerations
The contract section lists seventeen considerations, (a) to (q): nature and scope of the arrangement; performance measures or benchmarks; responsibilities for providing, receiving and retaining information; the right to audit and require remediation; responsibility for compliance with applicable laws and regulations; costs and compensation; ownership and licence; confidentiality and integrity; operational resilience and business continuity; indemnification and limits on liability; insurance; dispute resolution; customer complaints; subcontracting; foreign-based third parties; default and termination; and regulatory supervision.
Three of them decide whether the later stages of the lifecycle can be run at all. Without the right to audit and require remediation, monitoring has no teeth. Without subcontracting provisions, fourth parties are invisible. Without default and termination provisions, including transition, exit is on the provider’s terms. The Interagency Guidance also expects contracts to be reviewed, approved and executed appropriately, and executed contracts to be retained, which is a governance point as much as a legal one.
Monitoring, termination and governance in the Interagency Guidance
Ongoing monitoring, the Guidance says, enables an organisation to confirm the quality and sustainability of a third party’s controls, to escalate significant issues, and to respond. It names three typical activities: review of the third party’s reports, periodic visits and meetings, and regular testing of the organisation’s own controls over the relationship. Its fourteen monitoring considerations range from changes in the third party’s strategy, financial condition, insurance and key personnel to its response to threats and incidents, its reliance on subcontractors, external conditions, and the volume and trend of customer complaints.
Termination is short but pointed: transition options, the capabilities and time frame to transition, costs and fees, data retention and destruction and system access after the relationship ends, joint intellectual property, and the risks where termination follows the third party’s failure. Governance places ultimate responsibility with the board, which sets appetite, approves policy and holds management accountable; management integrates third-party risk with overall risk management, directs each stage, reports to the board, staffs the function and escalates. Periodic independent reviews test whether risks are identified, measured, monitored and controlled and whether conflicts of interest are avoided.
The documentation practices the Interagency Guidance lists are the most useful passage for anyone building a programme, because they are the records an examiner asks for: a current inventory flagging higher-risk and critical activities; planning and risk assessments; due diligence results; executed contracts; remediation plans; risk and performance reports from the third party; complaint monitoring; the third party’s reports of disruptions and breaches; results of independent reviews; and periodic board reporting, including dependency on a single provider for multiple activities.
Applying the Interagency Guidance outside US banking
Although written for banking organisations, the Interagency Guidance is the most granular statement of the third-party lifecycle any regulator has published, and its structure is shared by DORA, the EBA outsourcing guidelines and the FSB toolkit. That makes it a sound spine for any organisation’s programme, with the other regimes mapped onto it. The TPRM Toolkit is built exactly that way: its 86 templates are organised on the Guidance’s lifecycle, its gap assessment tool lists all 90 of the Guidance’s enumerated considerations with the document that closes each, and its crosswalk maps the same documents to DORA, NIST CSF 2.0, ISO/IEC 27001, SOC 2, PCI DSS, GDPR, HIPAA and NYDFS.
For the wider picture, start with what TPRM is and our guide to third-party risk management across four regimes. The third-party risk management framework guide shows how the Guidance maps to the other eleven regimes, the vendor due diligence checklist turns its fourteen factors into a working review, and the TPRM policy guide covers the governance it expects the board to approve.
Frequently asked questions about the Interagency Guidance
Is the Interagency Guidance a regulation?
No. It is supervisory guidance, and it says so. It does not create new legal obligations; it describes the risk management practices the agencies expect to see and examine against under existing safety-and-soundness standards.
Does it apply to fintech partnerships?
Yes. The scope language, “any business arrangement, by contract or otherwise”, and the examples including joint ventures and third parties providing products to customers, bring bank-fintech arrangements squarely inside it.
What happened to OCC Bulletin 2013-29?
It was rescinded and replaced by the Interagency Guidance, along with the OCC’s 2020 FAQs, the Federal Reserve’s 2013 guidance and the FDIC’s 2008 guidance. Only OCC Bulletin 2002-16 on foreign-based providers remains, as a supplement.
Does the Interagency Guidance set deadlines or thresholds?
Very few. It sets no notification clocks, no dollar thresholds and no fixed review frequencies; it leaves proportionality to the organisation and expects the reasoning to be documented. Where a programme needs hard numbers, they come from the other regimes the organisation is subject to, such as DORA’s register reporting or NYDFS’s periodic assessment requirement.
How often should a programme be reviewed against it?
The Guidance expects periodic independent reviews of the third-party risk management process itself, testing design and operation, staffing and expertise, and conflicts of interest. Annually is the usual cadence, with the results reported to the board.