Feature Third-Party Risk
The OCC Bulletin 2023-17 Vendor Due Diligence File: What Examiners Expect to See for Every Critical Third Party
FDIC data shows 35% of supervised institutions had a TPRM finding in 2024, with incomplete due diligence and inadequate ongoing monitoring as the top two gaps. This is what goes in the file — and what examiners are looking for when they open it.
Table of Contents
TL;DR
- The FDIC found TPRM deficiencies in 35% of supervised institutions in 2024; the top two gaps were incomplete due diligence and inadequate ongoing monitoring
- OCC Bulletin 2023-17’s five-lifecycle framework — planning, due diligence and selection, contract negotiation, ongoing monitoring, termination — defines what examiners expect at every stage
- A “critical vendor due diligence file” needs to document at least eight specific areas: financial condition, experience/qualifications, info security, operational resilience, subcontractors, insurance, risk management, and contractual arrangements
- Thread Bank’s May 2024 consent order required a “documented risk assessment” of each fintech partner — a baseline requirement, not an advanced one
- If your program has the questionnaire but not the evidence trail, that’s the gap examiners are finding
Third-party risk management failures rarely look like a missing policy. They look like a missing file.
The examiner asks for the due diligence record for your top five critical vendors. Your team produces questionnaires from three years ago, a contract, and a SOC 2 report that expired in 2023. Nobody documented whether the report had relevant exceptions. Nobody noted who reviewed it. No one ran the annual reassessment last year because the team was short-staffed and “it was the same vendor.”
That’s the pattern the FDIC’s 2024 Risk Review documented: 35% of supervised institutions with a TPRM finding, and in most of those cases, the problems weren’t structural. The program existed. The questionnaires existed. The gap was in the evidence — complete, current, reviewed documentation that demonstrates due diligence actually happened.
OCC Bulletin 2023-17 spells out what that evidence should look like. Here’s how to build the file.
The Five-Lifecycle Framework and Where the Evidence Goes
OCC Bulletin 2023-17, the interagency third-party risk management guidance issued June 6, 2023 by the OCC, Federal Reserve, and FDIC, organizes TPRM around five lifecycle stages: planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination.
Each stage is supposed to generate documentation. Examiners don’t just review your policies — they open the vendor files to see what your policies actually produced.
The two stages where documentation most consistently breaks down are due diligence and ongoing monitoring. That’s not a coincidence. Those are also the two stages the FDIC flagged as the most common deficiency categories in 2024.
What “Critical Activity” Means in Practice
Before you can build a due diligence file, you have to decide which vendors warrant one. The guidance describes a risk-proportionate approach: more rigorous review for “critical activities,” scaled down for lower-risk relationships.
The guidance describes critical activities as those where failure or disruption of the third party could cause significant risk to the banking organization, its customers, or the broader financial system. In practice, examiners apply a de facto test:
- Substitutability: If this vendor shut down tomorrow, how fast could you replace the function? A core processor or sponsor bank relationship is not easily substitutable. A generic office supply vendor is.
- Scale and volume: Does this vendor touch a material portion of your customer base, transactions, or regulatory obligations?
- Data sensitivity: Does the vendor have access to customer PII, account data, or systems that contain regulated data?
- Regulatory flow-through: Do your BSA/AML, fair lending, Reg E, or other compliance obligations flow through this vendor’s platform?
If any of these answers is “yes,” the vendor likely supports a critical activity and warrants full due diligence documentation. The classification decision itself should also be documented — examiners want to see not just the file but the logic behind the tiering.
The Eight Elements of a Complete Due Diligence File
For a critical vendor, OCC Bulletin 2023-17 identifies eight categories of due diligence that should be assessed and documented:
1. Financial Condition
Current, audited financial statements — not a summary, and not three years old. For publicly traded vendors, most recent filings are readily available. For private vendors, this requires directly requesting financial statements and documenting their review. Examiners look for evidence that you assessed whether the vendor has the financial stability to continue operations and meet contractual obligations.
2. Business Experience and Qualifications of Key Personnel
Reference checks, leadership biographies, or third-party assessments of the vendor’s track record. Not a marketing deck. For BaaS platforms and fintech middleware, this includes assessment of whether the team has operated at the scale your program will require.
3. Risk Management Practices
Does the vendor have a risk management program of their own? Do they perform vendor risk assessments for their own subcontractors? The guidance requires you to assess whether the third party’s risk management practices align with your requirements — not just assume they do.
4. Information Security Controls
A SOC 2 Type II report, NIST CSF assessment, or equivalent third-party audit of the vendor’s security posture. Critically, this needs to be current (generally within the last 12 months), and your documentation needs to show that someone actually reviewed the report for exceptions, scope limitations, and whether the trust service criteria covered the services you’re actually using.
A SOC 2 report with a “modified opinion” that nobody noticed is a documented audit trail of a process failure, not a due diligence artifact.
5. Operational Resilience
Does the vendor have a business continuity plan? What are their RTOs and RPOs for services you depend on? Have they tested? The guidance treats operational resilience as a distinct due diligence category — not something you can infer from the SOC 2.
6. Subcontractor Reliance
Where does your vendor outsource? This is the fourth-party risk question, and it’s one of the most consistently underdocumented areas in TPRM programs. OCC 2023-17 explicitly requires you to assess the vendor’s reliance on its own subcontractors. The BaaS space makes this acutely relevant — if your program runs through a middleware platform that depends on an AWS architecture that depends on a specific availability zone, that chain of dependency should be mapped and documented.
7. Insurance Coverage
What coverage does the vendor carry? Errors and omissions, cyber liability, and general commercial liability are the baseline questions. The documentation should confirm coverage and assess whether it’s adequate for the relationship.
8. Contractual Arrangements with Other Parties
Does the vendor have exclusive arrangements, volume commitments, or data-sharing agreements with competitors that create conflicts or concentration risk? This is the least commonly documented element and one that shows up in examiner questions about vendor conflicts of interest.
The Consent Order Pattern and What It Tells You
Between 2022 and 2025, the FDIC, OCC, and Federal Reserve issued consent orders against at least seven sponsor banks operating BaaS programs. The documentation problems in these cases are instructive.
Piermont Bank’s February 2024 consent order cited failure to have internal controls and information systems adequate for the bank’s size and the scope of its third-party relationships. Sutton Bank’s order required documented oversight policies. Thread Bank’s May 2024 order went to a more basic level — it required the bank to implement a “documented risk assessment” of each fintech partner.
Thread’s consent order is particularly telling because Thread wasn’t required to have a sophisticated TPRM program. It was required to have a documented risk assessment. The documentation gap — not a conceptual gap, not a program design gap — was what triggered the formal action.
The FDIC’s emerging fintech certification initiative (BISDO/RAMP) is partly a response to this documentation problem at scale. BISDO’s pitch is that common standards reduce the burden of producing the same documentation for every bank partner. But the underlying requirement — documented, evidence-backed due diligence — remains unchanged.
The Ongoing Monitoring Gap
Due diligence gets more attention, but examiners are equally focused on ongoing monitoring — specifically, whether monitoring is happening continuously rather than annually, whether there’s a documented trigger-event process, and whether monitoring activity is actually captured in writing.
For critical vendors, a reasonable ongoing monitoring cadence looks like:
- Quarterly: Financial health review, incident log review, SLA performance metrics
- Annually: Comprehensive reassessment including updated questionnaire, fresh SOC 2 or equivalent, subcontractor review
- Trigger-event: Out-of-cycle review triggered by vendor acquisition, regulatory action against the vendor, material security incident, key personnel departure, or significant service degradation
The monitoring record should show dated activity for each of these. An examiner who opens the monitoring file and sees an annual questionnaire sent in 2023 and nothing since is looking at the same deficiency the FDIC cited in 35% of its examinations.
For more on building a structured monitoring program, vendor financial health monitoring best practices provides specific indicators and cadences that align with OCC 2023-17 expectations.
The Contract Negotiation Layer
The guidance treats contract negotiation as a distinct lifecycle stage — not because the contract itself constitutes due diligence, but because contract provisions are part of how you secure ongoing compliance obligations, access rights, and exit rights.
For critical vendors, OCC 2023-17 identifies contract provisions that should be included: the nature and scope of the arrangement, performance standards and service level agreements, right to audit, data security obligations, business continuity requirements, notification requirements for incidents, change management processes, and termination rights.
The contract provisions requirements under OCC 2023-17 go into detail on the specific clauses. The examiner expectation is that the contract aligns with the risk assessment — if your due diligence identified a significant IT concentration risk, the contract should include audit rights and incident notification provisions that address that risk.
So What? Building the File Your Examiner Will Actually Review
The FDIC’s 35% finding rate isn’t a sign that TPRM programs don’t exist. It’s a sign that the evidence isn’t there to prove they’re working.
The practical task is building the vendor due diligence file as a document that would survive independent review — not by someone who knows your program, but by an examiner who is opening the file for the first time. That means:
- For each critical vendor: A current, dated file with all eight due diligence elements documented, including evidence of actual review (not just receipt) of SOC reports, financial statements, and questionnaire responses
- For each ongoing monitoring cycle: Dated activity notes, flagged exceptions, and evidence of follow-up on any issues identified
- For each trigger event: A documented decision about whether the event warranted an out-of-cycle review and, if not, why not
- For the tiering decision itself: Written documentation of the criteria used to classify each vendor as critical, significant, or routine
A TPRM program that exists on paper is a policy document. A TPRM program that examiners can verify is a vendor file.
The Third-Party Risk Management (TPRM) Kit includes a structured vendor due diligence questionnaire mapped to OCC 2023-17’s eight due diligence elements, a critical activity tiering matrix, an ongoing monitoring tracker with trigger-event protocols, and a contract provisions checklist — designed to produce the documentation file this post describes.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What does OCC Bulletin 2023-17 require for vendor due diligence?
How does OCC 2023-17 define a 'critical activity'?
What was the FDIC's finding rate for TPRM deficiencies in 2024?
What specific items do examiners expect to find in a vendor due diligence file?
How often does ongoing monitoring documentation need to be updated for critical vendors?
What triggered the FDIC consent orders against Piermont Bank, Sutton Bank, and Thread Bank?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Keep reading
Related posts.
Third-Party Risk
OCC's 2026 Third-Party Risk Guidance Rewrite: What Banks Should Change Now
The 2026 third-party risk guidance proposal rewrites vendor tiering and gives community banks leverage with core providers.
Sep 11, 2026
Third-Party Risk
Everest Ransomware Hit Citizens Bank and Frost Bank Through a Vendor Nobody Will Name. Six Class Actions Later, Here's What Your TPRM Program Needs.
In April 2026, the Everest ransomware group claimed 3.65 million records from Citizens Bank and Frost Bank via a shared third-party vendor. Neither bank has named the vendor. Six class actions were filed against the banks. Here is what this means for your TPRM program.
Sep 10, 2026
Third-Party Risk
NYDFS Said It in October. Examiners Are Checking in 2026. What Your Vendor Program Needs to Reflect the Part 500 Third-Party Guidance.
NYDFS's October 2025 industry letter on third-party cybersecurity risk established that covered entities cannot delegate Part 500 compliance to vendors. With MFA, asset inventory, and annual certification requirements now fully active, examiners are reviewing whether vendor programs actually reflect the guidance — not just acknowledge it. Here's what your TPRM program needs.
Sep 7, 2026