★ TPRM Insights
OCC Third-Party Risk Guidance for US Banks in 2026
7 min read · Vendor Risk · July 2026
OCC third-party risk management guidance sets the baseline that every national bank and federal savings association must meet when working with vendors, fintech partners, and other external providers. For risk and compliance teams, aligning internal programs with this guidance isn’t optional — it’s the standard examiners test against during every safety-and-soundness review, and increasingly the standard boards ask about directly. This article breaks down what the guidance actually requires, how it has evolved, and how to operationalise it before your next exam cycle.
★ Key Takeaways
OCC guidance now aligns closely with FDIC and Federal Reserve expectations under the 2023 interagency guidance
Continuous, evidence-based monitoring is replacing annual point-in-time reviews as the examiner standard
Critical activity vendors require documented risk tiering and board-level oversight
Non-compliance risk includes MRAs, consent orders, and direct impact on CAMELS ratings
What Is OCC Third-Party Risk Management Guidance?
OCC third-party risk management guidance is the supervisory framework the Office of the Comptroller of the Currency uses to hold national banks and federal savings associations accountable for risks introduced by vendors, subcontractors, and other external parties across the full relationship lifecycle. It was first codified in OCC Bulletin 2013-29 and has since been harmonised with guidance from the FDIC and Federal Reserve.
The framework organises third-party oversight into five stages: planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination. Rather than prescribing a single checklist, the OCC expects banks to apply a risk-based approach — relationships classified as “critical activities” receive materially deeper scrutiny than low-risk, low-impact vendors.
Critical activities typically include core banking platforms, payment processing, cloud infrastructure, and any vendor whose failure would disrupt customer-facing services or expose sensitive data at scale. Banks are expected to maintain a current, complete inventory that distinguishes these relationships from lower-impact vendors such as office suppliers or marketing agencies.
- ● Planning and risk assessment before engagement
- ● Due diligence and third-party selection
- ● Contract structuring and negotiation
- ● Ongoing monitoring throughout the relationship
- ● Termination and exit planning
How Does OCC Guidance Differ From FDIC and Federal Reserve Expectations?
OCC guidance is now closely aligned with FDIC and Federal Reserve third-party risk expectations following the 2023 interagency guidance the three agencies issued jointly. Before that update, each regulator maintained its own bulletin, which created inconsistent expectations for banks operating under multiple charters or holding company structures.
The 2023 guidance replaced OCC Bulletin 2013-29 and its companion documents with a single, principles-based framework shared across all three agencies. In practice this means a bank’s third-party risk program can now be built once and mapped consistently regardless of which agency conducts the exam, though OCC examiners still apply supplemental procedures specific to national bank charters and larger, more complex institutions.
For compliance teams managing relationships across a bank holding company with multiple regulated subsidiaries, this convergence removes much of the ambiguity that previously forced teams to maintain parallel documentation sets for different examiners.
What Do Examiners Look For During a Third-Party Risk Review?
Examiners look for documented evidence that a bank identifies its critical third parties, applies risk-tiered due diligence, and maintains active board and senior management oversight of vendor relationships. A vendor inventory alone is not sufficient — examiners expect to see how risk tiering decisions were made and how they drive the depth of ongoing monitoring.
During a review, examiners typically request the third-party inventory, risk assessments for critical relationships, monitoring reports and escalation logs, concentration risk analysis, and minutes or reports showing board-level visibility into third-party risk. Gaps in any of these areas are a common source of matters requiring attention.
Examiners also probe how quickly a bank can answer basic questions on demand: which vendors touch customer data, which relationships lack a current contract review, and which critical vendors have no documented exit plan. Programs that can answer these questions from a live system, rather than reconstructing them from spreadsheets, consistently perform better in exams.
- ● Complete third-party inventory with risk tiering
- ● Evidence of an ongoing monitoring cadence
- ● Board and senior management reporting
- ● Concentration risk analysis across critical vendors
- ● Documented exit strategies for critical relationships
How Should Banks Structure a Compliant Vendor Risk Program?
A compliant vendor risk program assigns clear ownership for third-party risk, tiers vendors by criticality rather than treating all relationships the same, and embeds continuous monitoring instead of relying on point-in-time annual reviews. Ownership typically sits with a dedicated third-party risk function that reports into enterprise risk management, with clear escalation paths to the board for critical activities.
Risk tiering should weigh factors such as data access, system integration depth, substitutability, and the potential impact of a service disruption on customers or safety and soundness. Static assessments performed once a year increasingly fall short of what examiners expect for critical relationships — the direction of travel across all three agencies is toward continuous, evidence-based monitoring throughout the life of the contract.
Many programs still rely on manual questionnaires and email-based tracking, which makes it difficult to demonstrate the kind of always-on oversight examiners now expect. Programs built around a live, centralised system of record for vendor risk data tend to close this gap far faster than programs that layer new controls onto spreadsheet-based processes.
What Happens When a Bank Fails to Meet OCC Third-Party Risk Expectations?
Failing to meet OCC third-party risk expectations can result in a Matter Requiring Attention (MRA), and in more serious or repeated cases, a formal enforcement action such as a consent order or civil money penalty tied specifically to vendor oversight failures. These findings also feed directly into a bank’s CAMELS rating through the management component.
Beyond formal supervisory consequences, gaps in third-party oversight expose banks to operational and reputational risk when a vendor failure disrupts customer-facing services or results in a data incident. Regulators have made clear that outsourcing an activity does not outsource accountability — the bank remains fully responsible for the outcome regardless of which party caused the failure.
Remediation after an MRA is rarely quick: banks typically must rebuild vendor inventories, backfill risk assessments, and demonstrate a sustained monitoring cadence over multiple quarters before an examiner will consider a finding closed. Getting the program right proactively is significantly less costly than remediating it under supervisory pressure.
Conclusion
OCC third-party risk management guidance is no longer a static compliance checklist — it is a continuously evolving standard that increasingly rewards banks able to demonstrate real-time visibility into vendor risk, not just point-in-time assessments filed away for the next exam. Institutions that treat third-party oversight as an ongoing discipline, backed by clear ownership and risk-tiered monitoring, consistently fare better with examiners and avoid the costly remediation cycles that follow an MRA.
Crest helps risk, compliance, and audit teams operationalise exactly this kind of continuous third-party oversight, replacing static spreadsheets and annual questionnaires with always-on monitoring and board-ready reporting. If your team is preparing for its next OCC exam cycle, schedule a demo to see how Crest can strengthen your third-party risk program.
★ Frequently Asked Questions
Does OCC third-party risk guidance apply to community banks or only large national banks?
It applies to every OCC-regulated institution regardless of size, though examination intensity scales with the complexity and criticality of a bank’s third-party relationships. Community banks with simpler vendor portfolios face proportionally lighter scrutiny than large, multi-charter institutions with numerous critical activities.
What counts as a \"critical activity\" under OCC guidance?
A critical activity is a third-party relationship that could have a significant impact on a bank’s operations, expose it to significant risk, or affect a large number of customers if the relationship fails. Core banking platforms, payment processors, and cloud infrastructure providers typically fall into this category.
How often should banks reassess third-party risk under OCC guidance?
Reassessment frequency should be risk-based: critical activity vendors typically warrant at least annual formal reassessment alongside continuous monitoring, while lower-risk vendors can be reviewed less frequently. Regulators increasingly expect continuous, evidence-based monitoring rather than a purely calendar-driven review cycle for the most critical relationships.
What changed between OCC Bulletin 2013-29 and the 2023 interagency guidance?
OCC Bulletin 2013-29 was an OCC-specific document; the 2023 interagency guidance replaced it with a single, principles-based framework issued jointly by the OCC, FDIC, and Federal Reserve. This harmonisation gives banks operating under multiple charters or holding structures one consistent standard to build their program against.
Can a vendor SOC 2 report satisfy OCC due diligence requirements on its own?
No. A SOC 2 report is useful supporting evidence, but examiners expect the bank to perform its own independent risk assessment rather than relying solely on a vendor-provided attestation. The bank remains responsible for corroborating the report’s scope against its own risk exposure.
★ See Crest in Action
Ready to Modernise Your TPRM?
Intelligence over information. Control over chaos. Insight over effort.
Published by the Crest Editorial Team · crest.digital