AI Regulation Tracker · OCC · Guidance

What does OCC Bulletin 2023-17 say about AI in banking?

Published Jun 6, 2023 · Last reviewed Aug 26, 2026

OCC Bulletin 2023-17, issued June 6, 2023, transmits the interagency Guidance on Third-Party Relationships: Risk Management from the OCC, Federal Reserve, and FDIC. It replaces the OCC's 2013 third-party guidance (Bulletin 2013-29) and 2020 FAQs (Bulletin 2020-10) and is the framework banks apply to AI vendors, cloud and model providers, and fintech partners. It sets a five-stage lifecycle — planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination — with expectations scaled to the risk and criticality of each relationship.

DocumentOCC Bulletin 2023-17Third-Party Relationships: Interagency Guidance on Risk Management
Issued byOffice of the Comptroller of the Currency
TypeGuidance
StatusIn force
PublishedJun 6, 2023
EffectiveJun 6, 2023
Applies toAll OCC-supervised national banks, federal savings associations, and federal branches and agencies of foreign banks; issued jointly with the Federal Reserve and FDIC for all banking organizations
Also issued asSR 23-4, FDIC FIL-29-2023
Official sourceocc.gov
Use casesThird-party & vendor AI · Generative & agentic AI · Model risk management · AI governance (general) · Cybersecurity

What are the key points of OCC Bulletin 2023-17?

  • Joint OCC/Fed/FDIC guidance; the OCC rescinded Bulletin 2013-29 and Bulletin 2020-10 (third-party FAQs).
  • Applies to all business arrangements with third parties, including fintech partnerships, technology service providers, and vendors of models and AI tools.
  • Risk management lifecycle: planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination, plus governance (oversight, documentation, independent review).
  • Not all relationships carry the same risk: banks should identify 'critical activities' and apply more rigorous oversight there.
  • Due diligence expectations cover information security, business resilience, subcontractors, and the third party's own risk management — the basis for questions banks ask AI and cloud providers.
  • Non-compliance is not itself a basis for enforcement; it is supervisory guidance, applied through examinations.

What did OCC Bulletin 2023-17 change for banks?

It unified three agencies' third-party regimes and, for AI, became the operative document: most bank AI is bought rather than built, and examiners assess model and AI vendors through this lifecycle. Bulletin 2026-13 refers to vendor and third-party models and expects model-risk and third-party programs to work together; the Spring 2026 risk report also emphasises support for community banks that rely on third-party technology.

Does the 2023 third-party guidance cover AI vendors?

Yes. It applies to all third-party business arrangements, including providers of AI models, cloud platforms, and fintech partners, with due diligence and ongoing monitoring scaled to the criticality of the activity.

What did OCC Bulletin 2023-17 replace?

OCC Bulletin 2013-29 (Third-Party Relationships: Risk Management Guidance) and OCC Bulletin 2020-10 (the 2020 FAQs supplementing it).

DateDocumentStatus
May 7, 2026OCC Semiannual Risk Perspective, Spring 2026Semiannual Risk Perspective from the National Risk Committee, Spring 2026Final
Apr 17, 2026OCC Bulletin 2026-13Model Risk Management: Revised GuidanceIn force
Apr 29, 2025Acting Comptroller Hood, 'AI in Financial Services' (Apr 2025)Remarks by Acting Comptroller Rodney E. Hood at the National Fair Housing Alliance's Responsible AI Symposium: 'AI in Financial Services'Final
Apr 9, 2021OCC Bulletin 2021-19Bank Secrecy Act/Anti-Money Laundering: Interagency Statement on Model Risk Management for Bank Systems Supporting BSA/AML Compliance and Request for InformationSuperseded
Mar 31, 20212021 Interagency AI RFI (OCC Bulletin 2021-17)Request for Information and Comment on Financial Institutions' Use of Artificial Intelligence, Including Machine LearningFinal
Apr 4, 2011OCC Bulletin 2011-12Sound Practices for Model Risk Management: Supervisory Guidance on Model Risk ManagementSuperseded

Follow every document these regulators publish

6 curated AI stories for banking executives · Every morning · Free

Subscribe to BankingNewsAI →