FIL-29-2023, issued June 6, 2023, transmits the final Interagency Guidance on Third-Party Relationships: Risk Management from the FDIC, Federal Reserve, and OCC. It replaces the FDIC's 2008 third-party risk guidance (FIL-44-2008) and withdraws the 2016 proposed third-party lending guidance (FIL-50-2016), setting one risk-based framework across the life cycle of a third-party relationship: planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination. It is the document FDIC examiners apply when a bank buys AI models, fraud tools, or chatbots from a vendor.
| Document | FDIC FIL-29-2023 — Interagency Guidance on Third-Party Relationships: Risk Management |
| Issued by | Federal Deposit Insurance Corporation |
| Type | Guidance |
| Status | In force |
| Published | Jun 6, 2023 |
| Effective | Jun 6, 2023 |
| Applies to | All FDIC-supervised banking organizations, alongside OCC- and Federal Reserve-supervised institutions |
| Also issued as | SR 23-4, OCC Bulletin 2023-17 |
| Official source | fdic.gov ↗ |
| Use cases | Third-party & vendor AI · AI governance (general) · Fraud detection · Customer-facing chatbots |
What are the key points of FDIC FIL-29-2023?
- Issued June 6, 2023 jointly with the Federal Reserve and OCC; published in the Federal Register June 9, 2023.
- Replaces FDIC FIL-44-2008 (Guidance for Managing Third-Party Risk) and withdraws the 2016 proposed third-party lending guidance (FIL-50-2016).
- Five life-cycle stages: planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination.
- Using a third party does not diminish a bank's responsibility to operate safely and soundly and to comply with law, including consumer protection and customer-information security.
- Expectations scale to the level of risk, complexity, and size of the banking organization and the criticality of the activity.
- Followed in May 2024 by the interagency 'Third-Party Risk Management: A Guide for Community Banks' to help smaller banks apply it.
What did FDIC FIL-29-2023 change for banks?
Before 2023 each agency had its own third-party guidance; the FDIC's dated from 2008. The interagency guidance gave banks one framework and made explicit that fintech and technology partnerships, including vendor-supplied models, fall inside it. In practice it is the basis on which FDIC examiners ask a community bank to show due diligence, contractual rights, and monitoring for AI tools it did not build.
Does the third-party guidance cover AI vendors?
Yes. It applies to all business arrangements with third parties, so a vendor supplying an AI underwriting, fraud-detection, or chatbot tool is covered. The bank must perform due diligence, negotiate appropriate contract terms, and monitor performance commensurate with the risk and criticality of the activity.
Is there a simpler version for community banks?
Yes. In May 2024 the FDIC, Federal Reserve, and OCC issued 'Third-Party Risk Management: A Guide for Community Banks,' which walks smaller banks through the 2023 guidance without creating new requirements.
| Date | Document | Status |
|---|---|---|
| Jun 4, 2026 | Hill House oversight testimony (Jun 2026) — Statement of Chairman Travis Hill: Oversight of Prudential Regulators | Final |
| Apr 17, 2026 | FDIC FIL-15-2026 — Agencies Revise the Interagency Model Risk Management Guidance | In force |
| Mar 26, 2026 | FDIC House testimony on AI and innovation (Mar 2026) — Innovation at the Speed of Markets: How Regulators Keep Pace with Technology | Final |
| Jul 14, 2025 | FDIC 2025 Report on Cybersecurity and Resilience — 2025 Report on Cybersecurity and Resilience | Final |
| Jan 10, 2025 | Hill 'Charting a New Course' speech — Charting a New Course: Preliminary Thoughts on FDIC Policy Issues | Final |
| May 22, 2024 | FDIC 2024 Risk Review — 2024 Risk Review — Section 5: Operational and Cyber Risks | Final |
Follow every document these regulators publish
6 curated AI stories for banking executives · Every morning · Free
Subscribe to BankingNewsAI →