AI Regulation Tracker · FDIC · Guidance

What does FDIC FIL-29-2023 say about AI in banking?

Published Jun 6, 2023 · Last reviewed Aug 26, 2026

FIL-29-2023, issued June 6, 2023, transmits the final Interagency Guidance on Third-Party Relationships: Risk Management from the FDIC, Federal Reserve, and OCC. It replaces the FDIC's 2008 third-party risk guidance (FIL-44-2008) and withdraws the 2016 proposed third-party lending guidance (FIL-50-2016), setting one risk-based framework across the life cycle of a third-party relationship: planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination. It is the document FDIC examiners apply when a bank buys AI models, fraud tools, or chatbots from a vendor.

DocumentFDIC FIL-29-2023Interagency Guidance on Third-Party Relationships: Risk Management
Issued byFederal Deposit Insurance Corporation
TypeGuidance
StatusIn force
PublishedJun 6, 2023
EffectiveJun 6, 2023
Applies toAll FDIC-supervised banking organizations, alongside OCC- and Federal Reserve-supervised institutions
Also issued asSR 23-4, OCC Bulletin 2023-17
Official sourcefdic.gov
Use casesThird-party & vendor AI · AI governance (general) · Fraud detection · Customer-facing chatbots

What are the key points of FDIC FIL-29-2023?

  • Issued June 6, 2023 jointly with the Federal Reserve and OCC; published in the Federal Register June 9, 2023.
  • Replaces FDIC FIL-44-2008 (Guidance for Managing Third-Party Risk) and withdraws the 2016 proposed third-party lending guidance (FIL-50-2016).
  • Five life-cycle stages: planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination.
  • Using a third party does not diminish a bank's responsibility to operate safely and soundly and to comply with law, including consumer protection and customer-information security.
  • Expectations scale to the level of risk, complexity, and size of the banking organization and the criticality of the activity.
  • Followed in May 2024 by the interagency 'Third-Party Risk Management: A Guide for Community Banks' to help smaller banks apply it.

What did FDIC FIL-29-2023 change for banks?

Before 2023 each agency had its own third-party guidance; the FDIC's dated from 2008. The interagency guidance gave banks one framework and made explicit that fintech and technology partnerships, including vendor-supplied models, fall inside it. In practice it is the basis on which FDIC examiners ask a community bank to show due diligence, contractual rights, and monitoring for AI tools it did not build.

Does the third-party guidance cover AI vendors?

Yes. It applies to all business arrangements with third parties, so a vendor supplying an AI underwriting, fraud-detection, or chatbot tool is covered. The bank must perform due diligence, negotiate appropriate contract terms, and monitor performance commensurate with the risk and criticality of the activity.

Is there a simpler version for community banks?

Yes. In May 2024 the FDIC, Federal Reserve, and OCC issued 'Third-Party Risk Management: A Guide for Community Banks,' which walks smaller banks through the 2023 guidance without creating new requirements.

DateDocumentStatus
Jun 4, 2026Hill House oversight testimony (Jun 2026)Statement of Chairman Travis Hill: Oversight of Prudential RegulatorsFinal
Apr 17, 2026FDIC FIL-15-2026Agencies Revise the Interagency Model Risk Management GuidanceIn force
Mar 26, 2026FDIC House testimony on AI and innovation (Mar 2026)Innovation at the Speed of Markets: How Regulators Keep Pace with TechnologyFinal
Jul 14, 2025FDIC 2025 Report on Cybersecurity and Resilience2025 Report on Cybersecurity and ResilienceFinal
Jan 10, 2025Hill 'Charting a New Course' speechCharting a New Course: Preliminary Thoughts on FDIC Policy IssuesFinal
May 22, 2024FDIC 2024 Risk Review2024 Risk Review — Section 5: Operational and Cyber RisksFinal

Follow every document these regulators publish

6 curated AI stories for banking executives · Every morning · Free

Subscribe to BankingNewsAI →