Feature Third-Party Risk
OCC 2023-17 Vendor Contract Provisions: What Goes in Every Critical Vendor Agreement — and What Examiners Flag First
OCC Bulletin 2023-17 specifies exactly what should be in every critical vendor contract — from right-to-audit to subcontracting controls to exit planning. Here's the complete list, where most agreements fall short, and what to do when a large vendor won't accept the terms the guidance requires.
Table of Contents
TL;DR:
- OCC Bulletin 2023-17 (joint interagency guidance from the OCC, Federal Reserve, and FDIC) specifies over a dozen contract provisions that banking organizations should include in agreements with critical vendors — covering audit rights, subcontracting, data handling, BCP/DR, and exit planning.
- The contract negotiation stage is phase three of the five-stage TPRM lifecycle. Provisions locked in here determine what leverage you actually have during ongoing monitoring and at termination.
- Vendor oversight deficiencies appear in over 40% of community bank examinations; missing or inadequate contract provisions are among the most commonly cited specific gaps.
- When you can’t negotiate a provision with a large vendor, the guidance provides a documented compensating-control path — but only if you write it down at the time of contracting.
An examiner sits down with your TPRM program documentation. She doesn’t start with your vendor list or your due diligence checklist. She pulls three critical vendor contracts at random.
She’s not checking whether you negotiated a competitive price. She’s checking whether you can audit the vendor without the vendor’s prior consent, whether your data handling clause covers what the vendor actually does with customer NPI, and whether you have explicit termination rights if the vendor is acquired or if a regulator directs you to exit the relationship.
Those provisions should be in every critical vendor contract under OCC Bulletin 2023-17 — the joint interagency guidance issued by the OCC, Federal Reserve, and FDIC on June 6, 2023. Most practitioners know the guidance exists. Fewer know exactly which contract terms it specifies, and fewer still have a systematic process to verify that existing contracts include them.
This post covers what the guidance actually says about contracts, where most agreements fall short, and what to do when a vendor won’t accept the provisions the guidance requires.
Where Contracts Fit in the TPRM Lifecycle
The 2023 interagency guidance structures third-party risk management as a five-stage lifecycle:
- Planning — define the business need; conduct a risk assessment before selecting any vendor
- Due Diligence and Third-Party Selection — evaluate vendor capabilities, financial condition, and compliance posture
- Contract Negotiation — establish the formal terms of the relationship
- Ongoing Monitoring — continuous oversight proportional to risk
- Termination — managed exit or wind-down
The contract negotiation stage is where risk assessment and due diligence findings get codified into enforceable obligations. If due diligence reveals that a vendor handles sensitive customer data, the contract must require protection of it. If due diligence reveals a single point of failure in a critical service, the contract must establish BCP and DR requirements.
That’s why examiners pull contracts. A rigorous risk assessment paired with a weak contract signals the bank assessed the risk but didn’t actually manage it.
What the Guidance Says Should Be in Every Critical Vendor Contract
The interagency guidance addresses contract negotiation content in detail across several categories. For critical third-party relationships, examiners expect all of the following.
Nature and Scope of the Arrangement
The contract should clearly define what the vendor is — and is not — authorized to do. This includes the specific services covered, the geographic scope of those services, which personnel or systems are authorized to access the bank’s data or infrastructure, and any explicit restrictions on how the vendor may use bank data for its own purposes.
A scope clause that allows the vendor to “use data to improve services” without defining what that means creates compliance risk under GLBA and gives examiners reason to question whether customer data controls extend to the vendor.
Performance Standards and Service Level Agreements
The guidance expects measurable performance benchmarks — uptime, processing speed, error rates, response times — with explicit remediation rights when a vendor misses them. A well-drafted SLA specifies:
- The measurement period and methodology
- Notification timelines when performance degrades
- Cure periods before the bank may exercise remediation rights
- Available remedies: fee credits, required remediation plans, enhanced reporting, or exit triggers
SLAs that specify performance metrics without any consequence for missing them are common in community bank contracts and a reliable exam finding.
Security and Confidentiality
This is often the most negotiated section. The guidance expects provisions addressing:
- Data encryption requirements at rest and in transit
- Access control standards and authentication requirements for vendor personnel accessing bank systems or data
- Incident notification — how quickly the vendor must notify the bank of a security event affecting bank data or systems
- Restrictions on vendor use of bank data for any purpose beyond the contracted service
- Obligations to return or destroy bank data at contract termination
The incident notification timeline in the vendor contract should align with the bank’s own regulatory notification obligations. If the bank has a 36-hour notification obligation to its primary federal regulator under the Computer-Security Incident Notification rule (12 CFR Part 53), the vendor contract should require vendor notification to the bank with sufficient lead time to permit the bank to make its own notification.
Audit and Report Requirements
The right to audit is one of the provisions that most frequently falls short in practice — particularly in contracts with cloud providers, core banking platforms, and large SaaS vendors.
The guidance expects banks to have the right to examine vendor books and records relevant to the contracted services, including the ability to conduct or commission independent assessments. When banks cannot negotiate direct audit rights — most commonly with hyperscalers and dominant platform vendors — the guidance’s risk-based framework accepts compensating controls:
| Compensating Control | What to Require |
|---|---|
| SOC 2 Type II reports | Annual report provided on request; scope covers the specific services used |
| ISO 27001 certification | Current certificate and most recent surveillance audit report |
| Penetration testing results | Third-party test of the environment hosting bank data, annually |
| Regulatory exam results | For vendors that are themselves regulated entities |
If you’re relying on compensating controls rather than direct audit rights, document in writing at the time of contracting: (1) why direct rights weren’t obtained, (2) what compensating controls you’re accepting, and (3) who approved the exception. Examiners will ask, and the documentation should be in the contract file, not reconstructed after the fact.
Regulatory Compliance
The vendor must agree to comply with all laws and regulations applicable to the services it provides. For bank-critical vendors, this typically encompasses BSA/AML obligations where applicable, consumer protection requirements where the vendor’s activities touch bank customers, and privacy and data protection requirements under GLBA and applicable state laws.
This clause should also specify which party bears responsibility for monitoring regulatory changes — and what process applies when a regulatory change requires modifications to the service or to the contract itself.
Dispute Resolution
A defined escalation and dispute resolution process, including the governing law and jurisdiction for contract disputes. This provision matters more than it seems: disputes over data ownership, indemnification scope, or liability for regulatory penalties can take years to resolve without a clear contractual framework establishing who decides and under what law.
Liability and Indemnification
The guidance expects provisions that address each party’s liability for their own acts and omissions, indemnification for third-party claims arising from vendor failure, insurance requirements (cyber liability, errors and omissions), and caps on liability.
Liability caps that apply without exception to data breach scenarios are a specific area of examiner attention. A $50,000 liability cap in a contract with a vendor processing millions of customer records creates a risk management gap the bank should have identified in due diligence and addressed in contracting.
Subcontracting
This is where fourth-party risk becomes a contract requirement rather than just a policy consideration. OCC 2023-17 expects the primary vendor contract to address subcontracting explicitly:
| Provision | What It Requires |
|---|---|
| Prior bank consent | Bank must approve before vendor subcontracts critical services |
| Flow-down obligations | Subcontractors must be held to equivalent security, privacy, and performance standards |
| Primary vendor liability | Primary vendor remains fully responsible for subcontractor performance |
| Bank oversight rights | Bank retains audit rights over subcontractors or right to require evidence of subcontractor oversight |
| Change notification | Vendor must notify bank before changing subcontractors for critical services |
The interagency guidance’s treatment of subcontracting directly connects to fourth-party and nth-party risk — see our guide to nth-party risk under OCC 2023-17 for how to map and manage the full subcontracting chain.
Business Continuity and Disaster Recovery
The guidance expects vendor BCP/DR obligations to be spelled out contractually: recovery time and recovery point objectives for services the bank depends on, the vendor’s obligation to test its plans, and an obligation to provide testing results on request. The vendor should also be required to notify the bank of disruptions that affect service delivery within defined timeframes.
Community banks whose vendors provide core banking services are particularly exposed here. A vendor BCP failure can quickly become a bank operational risk event — and without contractual BCP requirements and testing evidence, the bank has no visibility into whether the vendor can recover within the bank’s own RTO expectations.
Termination Rights
Termination provisions define what the bank can actually do when things go wrong. The guidance expects:
- For-cause termination: specific triggering events — material breach, vendor insolvency, regulatory action against the vendor, a security incident exceeding a defined threshold
- Termination for convenience: the bank’s right to exit for business reasons, with reasonable notice
- Regulatory direction: the right to terminate if a regulator specifically directs the bank to exit the relationship
- Change of control: the right to exit or renegotiate if the vendor is acquired by another entity, particularly a competitor
- Cure periods: defined timeframes for the vendor to remedy a breach before termination becomes effective
Vendor contracts that include for-cause termination but exclude termination-for-convenience and regulatory-direction rights are a recurring exam finding. The absence of a regulatory-direction exit right creates a particular problem in BaaS environments, where consent orders against sponsor banks have sometimes required rapid exits from fintech partnerships.
Exit Planning
Contract-level exit planning provisions address what happens when the relationship ends — whether at natural term, by early termination, or through a vendor insolvency scenario.
The guidance expects:
- The vendor’s obligation to maintain bank data in a portable, usable format throughout the term
- Transition assistance requirements — how long the vendor will support a migration, what tasks are included
- Data return or destruction timelines and certifications
- Restrictions on vendor use of bank data post-termination
Exit planning provisions have received heightened examiner attention following the 2024 Synapse bankruptcy, which demonstrated what happens when a middleware vendor’s collapse occurs without adequate data portability and transition provisions — approximately $160 million in customer deposits were frozen as trustees tried to reconcile ledgers with no clear process for returning customer funds. See also our critical vendor exit planning guide for the full wind-down process.
When the Vendor Won’t Accept the Provisions
The Federal Register notice accompanying OCC 2023-17 acknowledged directly what every TPRM practitioner knows: banking organizations “may lack sufficient leverage in negotiations with larger third parties and may struggle to get certain ‘typical’ provisions into contracts.”
The guidance’s response is risk-based, not prescriptive. For provisions you can’t negotiate:
- Document the attempt — record in the contract file that you sought the provision and the vendor declined
- Document the compensating control — specify what alternative evidence or protection you’re accepting in lieu of the provision
- Document the approval — confirm who reviewed and approved the exception, at what level of authority
- Build it into ongoing monitoring — if you’re relying on SOC reports in lieu of audit rights, build an annual review of those reports into your monitoring calendar
What examiners don’t accept is a missing provision with no documented rationale. An undocumented gap looks like something you missed. A documented gap with a compensating control looks like something you managed.
A Contract Review Calendar
The guidance doesn’t prescribe a fixed review interval, but exam expectations favor:
| Event | Required Action |
|---|---|
| New vendor contract | Full provision review before execution |
| Contract renewal (≥3 years) | Treat as new — full provision review |
| Significant scope change | Triggered review of affected provisions |
| Material vendor incident | Triggered review of security and termination provisions |
| Vendor change of control | Triggered review of all provisions |
| Annual cycle (critical vendors) | Verify key provisions remain adequate; update exception log |
So What?
The contract is not a formality at the end of due diligence. It is the mechanism through which risk assessment findings become enforceable obligations — and the document an examiner uses to verify that your TPRM program functions in practice, not just on paper.
If your vendor list is well-organized and your due diligence process is solid but your contracts predate OCC 2023-17 and were negotiated without attention to its provisions, you have a program gap. The path forward: targeted provision review at each renewal, documented exceptions with compensating controls for provisions you can’t negotiate, and a file structure that makes the review visible and auditable.
The BaaS Consent Order Playbook illustrates what contract gaps look like at scale — the 2022-2025 enforcement wave against BaaS banks surfaced TPRM deficiencies across BSA/AML coverage, ongoing monitoring, and contractual documentation that were consistent enough across agencies and institutions to define a minimum standard. Contract provisions were a recurring gap in virtually every order.
The Third-Party Risk Management (TPRM) Kit includes a vendor contract review checklist mapped to OCC 2023-17’s contract negotiation requirements, a provision exception log template, and a critical vendor tiering methodology you can apply to your existing vendor inventory starting this week.
Sources:
- OCC Bulletin 2023-17: Third-Party Relationships: Interagency Guidance on Risk Management
- Federal Register: Interagency Guidance on Third-Party Relationships: Risk Management (June 9, 2023)
- FDIC Financial Institution Letter FIL-29-2023
- Crowell & Moring: New Interagency Guidance on Third-Party Relationships — Points to Consider for Banks and Their Counterparties
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Does OCC 2023-17 apply to fintechs directly?
What makes a vendor 'critical' under OCC 2023-17?
What if a large cloud vendor won't accept our right-to-audit clause?
How often do examiners actually pull vendor contracts?
What provisions do I need if my vendor subcontracts part of the service?
When should I review existing vendor contracts against OCC 2023-17?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Keep reading
Related posts.
Third-Party Risk
Third-Party Risk Management Lifecycle RACI: Fix the Handoffs Between Procurement, Security, Legal, Business Owners, and Risk
A TPRM lifecycle RACI that assigns clear ownership at each stage — planning, due diligence, contracting, onboarding, monitoring, and offboarding — so findings don't fall between functions.
Jul 24, 2026
Third-Party Risk
Vendor Due Diligence Without a SOC 2: What Evidence Can Actually Substitute
A vendor due diligence checklist for evaluating security evidence when a vendor has no SOC 2 report, with a risk-based substitution matrix.
Jul 23, 2026
Third-Party Risk
Three Vendors, One Existential Risk: What the OCC's Community Bank Core Provider RFI Actually Asked
The OCC published Bulletin 2025-39 asking community banks hard questions about their relationships with Fiserv, FIS, and Jack Henry. The questions reveal exactly what examiners are now checking — and what most TPRM programs haven't addressed.
Jul 23, 2026