OCC Bulletin 2023-17, issued June 6, 2023, transmits the interagency Guidance on Third-Party Relationships: Risk Management from the OCC, Federal Reserve, and FDIC. It replaces the OCC's 2013 third-party guidance (Bulletin 2013-29) and 2020 FAQs (Bulletin 2020-10) and is the framework banks apply to AI vendors, cloud and model providers, and fintech partners. It sets a five-stage lifecycle — planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination — with expectations scaled to the risk and criticality of each relationship.
| Document | OCC Bulletin 2023-17 — Third-Party Relationships: Interagency Guidance on Risk Management |
| Issued by | Office of the Comptroller of the Currency |
| Type | Guidance |
| Status | In force |
| Published | Jun 6, 2023 |
| Effective | Jun 6, 2023 |
| Applies to | All OCC-supervised national banks, federal savings associations, and federal branches and agencies of foreign banks; issued jointly with the Federal Reserve and FDIC for all banking organizations |
| Also issued as | SR 23-4, FDIC FIL-29-2023 |
| Official source | occ.gov ↗ |
| Use cases | Third-party & vendor AI · Generative & agentic AI · Model risk management · AI governance (general) · Cybersecurity |
What are the key points of OCC Bulletin 2023-17?
- Joint OCC/Fed/FDIC guidance; the OCC rescinded Bulletin 2013-29 and Bulletin 2020-10 (third-party FAQs).
- Applies to all business arrangements with third parties, including fintech partnerships, technology service providers, and vendors of models and AI tools.
- Risk management lifecycle: planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination, plus governance (oversight, documentation, independent review).
- Not all relationships carry the same risk: banks should identify 'critical activities' and apply more rigorous oversight there.
- Due diligence expectations cover information security, business resilience, subcontractors, and the third party's own risk management — the basis for questions banks ask AI and cloud providers.
- Non-compliance is not itself a basis for enforcement; it is supervisory guidance, applied through examinations.
What did OCC Bulletin 2023-17 change for banks?
It unified three agencies' third-party regimes and, for AI, became the operative document: most bank AI is bought rather than built, and examiners assess model and AI vendors through this lifecycle. Bulletin 2026-13 refers to vendor and third-party models and expects model-risk and third-party programs to work together; the Spring 2026 risk report also emphasises support for community banks that rely on third-party technology.
Does the 2023 third-party guidance cover AI vendors?
Yes. It applies to all third-party business arrangements, including providers of AI models, cloud platforms, and fintech partners, with due diligence and ongoing monitoring scaled to the criticality of the activity.
What did OCC Bulletin 2023-17 replace?
OCC Bulletin 2013-29 (Third-Party Relationships: Risk Management Guidance) and OCC Bulletin 2020-10 (the 2020 FAQs supplementing it).
| Date | Document | Status |
|---|---|---|
| May 7, 2026 | OCC Semiannual Risk Perspective, Spring 2026 — Semiannual Risk Perspective from the National Risk Committee, Spring 2026 | Final |
| Apr 17, 2026 | OCC Bulletin 2026-13 — Model Risk Management: Revised Guidance | In force |
| Apr 29, 2025 | Acting Comptroller Hood, 'AI in Financial Services' (Apr 2025) — Remarks by Acting Comptroller Rodney E. Hood at the National Fair Housing Alliance's Responsible AI Symposium: 'AI in Financial Services' | Final |
| Apr 9, 2021 | OCC Bulletin 2021-19 — Bank Secrecy Act/Anti-Money Laundering: Interagency Statement on Model Risk Management for Bank Systems Supporting BSA/AML Compliance and Request for Information | Superseded |
| Mar 31, 2021 | 2021 Interagency AI RFI (OCC Bulletin 2021-17) — Request for Information and Comment on Financial Institutions' Use of Artificial Intelligence, Including Machine Learning | Final |
| Apr 4, 2011 | OCC Bulletin 2011-12 — Sound Practices for Model Risk Management: Supervisory Guidance on Model Risk Management | Superseded |
Follow every document these regulators publish
6 curated AI stories for banking executives · Every morning · Free
Subscribe to BankingNewsAI →