Feature Third-Party Risk
What TPRM Examiners Are Actually Finding Three Years Into the Interagency Guidance
OCC Bulletin 2023-17 and FDIC FIL-29-2023 turned three in June. Third-party risk programs that looked solid at launch are showing cracks under examination — incomplete due diligence, weak ongoing monitoring, critical activity designations that don't hold up, and subcontractor gaps that no one mapped. Here's what's getting flagged and what to fix.
Table of Contents
When the interagency TPRM guidance dropped in June 2023, most institutions filed it under “done.” They built a vendor inventory, added tiers, updated their due diligence questionnaire, and moved on. Examiners who reviewed programs a year later mostly agreed the new framework had been adopted.
Three years in, the picture is different. Examiners aren’t checking whether institutions adopted the guidance anymore. They’re checking whether the programs it produced actually work.
The gaps they’re finding aren’t about missing the framework. They’re about the distance between what’s documented and what’s operational — incomplete due diligence that was proportional on paper but not in practice, monitoring that generates reports nobody acts on, critical activity designations that don’t hold up when an examiner asks why a particular vendor was classified that way, and subcontractor maps that stop at the first tier.
TL;DR
- OCC Bulletin 2023-17 / FDIC FIL-29-2023 / Federal Reserve SR 23-4 are three years old — examiners have shifted from checking adoption to checking whether programs actually function
- The most common findings: under-resourced due diligence for critical activities, ongoing monitoring that’s annual at best, written agreements missing required elements, and subcontractor risk that was never assessed
- The July 2024 bank-fintech joint statement added BaaS-specific examination expectations that many sponsor banks haven’t fully incorporated
- Industry trade associations raised concerns in May 2026 about inconsistent guidance application — but inconsistency doesn’t eliminate your compliance risk
The Critical Activity Problem: Too Much or Too Little
The interagency guidance structures most of its requirements around the “critical activity” designation. Get the designation right and the rest of your TPRM program follows. Get it wrong — in either direction — and everything downstream is miscalibrated.
Under OCC Bulletin 2023-17 and FDIC FIL-29-2023, a critical activity is one that could cause a bank to face significant risk if the third party fails, could have significant customer impact, or requires significant resource investment to implement. The regulation is intentionally principle-based — it doesn’t provide a checklist.
Examiners in 2026 are finding two failure modes:
Under-designation: Institutions classified core banking technology, payment processors, and cloud infrastructure as non-critical to avoid the associated documentation burden. When examiners ask why a vendor processing 80% of the institution’s transaction volume wasn’t designated critical, the answer is often circular: “it wasn’t designated critical, so it didn’t get the critical activity review.”
Over-designation: Some institutions responded by designating nearly everything critical, creating administrative overload and diluting the depth of review for vendors that actually warrant it. A vendor list where 40% of vendors are critical is almost certainly wrong — and it creates the appearance of rigor without the substance.
The fix requires documented criticality criteria applied consistently: revenue exposure, customer impact if disrupted, data sensitivity, regulatory dependency, and concentration. If your criteria can’t produce a defensible list that an examiner could review and understand, the designation process needs work.
Due Diligence Depth: The Right Questions, Wrong Documentation
The guidance is clear that due diligence should be proportional to risk. For critical activities, that means comprehensive review of:
- Financial condition (audited financials, going-concern indicators)
- Information security and cybersecurity controls
- Operational resilience and business continuity
- Compliance and legal background
- Subcontracting practices (who the vendor uses for critical functions)
- Insurance coverage
- Human capital and management depth
The common failure mode isn’t asking the wrong questions on a questionnaire. It’s accepting vendor responses without validation — taking a “yes, we have a SOC 2” answer without reviewing the actual report, or accepting a vendor’s assertion that they have a business continuity plan without asking for evidence of testing.
The Federal Reserve’s May 2024 report on third-party risk management specifically noted the gap between due diligence process and due diligence substance — institutions going through the motions of sending questionnaires but not actually building risk-informed assessments from the responses.
Examiners pull due diligence workpapers. They look at whether the bank read the SOC 2 report, noted any exceptions, and followed up. They look at whether the financial review was a one-paragraph summary or an actual analysis of vendor financial health. Work product that looks like a completed form rather than evidence of analysis will generate findings.
For institutions that haven’t built out their ongoing vendor financial monitoring process, our vendor financial health monitoring guide covers the specific indicators and monitoring cadence that examiners expect.
Ongoing Monitoring: Annual Isn’t Continuous
The interagency guidance’s language on ongoing monitoring is clear: risk management processes should adapt as the relationship evolves and as the bank’s risk profile changes. For critical activities, the guidance describes monitoring as a continuous process, not a point-in-time event.
In practice, many institutions translated this as “we’ll check in annually.” That’s a finding waiting to happen.
Examiners in 2026 are looking for evidence of monitoring activity between formal annual reviews: newsroom monitoring for vendor financial distress or breach announcements, automated review of performance metrics in vendor contracts, periodic check-ins on subcontractor changes, and escalation of any material changes to appropriate oversight functions.
The specific monitoring signals that matter most for critical vendors:
- Credit rating changes or public financial reporting anomalies
- Contract terminations with other clients or industry news suggesting financial stress
- Security incidents or breach disclosures at the vendor or its subcontractors
- Regulatory actions against the vendor
- Key personnel changes in the vendor’s risk, security, or compliance functions
- Material changes to the vendor’s subcontracting relationships
This doesn’t require daily manual review of every vendor. It requires a monitoring protocol that assigns specific signals to automated tracking and flags material changes for human review. The program’s output needs to be documented — examiners look for evidence that monitoring actually happened, not just a process description that says it does.
Written Agreement Completeness: Fourteen Elements, Not Eight
The interagency guidance specifies what written agreements for critical activities should contain. Examiners reviewing vendor contracts are pulling them against this list. The most common gaps are at the back half of the list — the provisions that institutions negotiate away or simply forget.
| Required Element | Commonly Missing? |
|---|---|
| Scope of arrangement and activities | Rarely missing |
| Performance standards and metrics | Often too vague |
| Pricing and payment terms | Rarely missing |
| Ownership and confidentiality of data | Often missing clauses on data return/deletion |
| Audit and access rights for bank and regulators | Frequently narrowed by vendor negotiation |
| Business continuity and disaster recovery requirements | Often absent or aspirational |
| Indemnification and liability limits | Present, often negotiated unfavorably |
| Default and termination triggers | Present but often lack detail on transition assistance |
| Dispute resolution procedures | Often missing |
| Subcontracting limitations and notification requirements | Frequently missing |
| Cybersecurity and data security requirements | Often vague or vendor-templated |
| Regulator access rights | Critical gap — vendors often resist |
| Compliance with applicable laws | Present but generic |
| Termination and transition assistance | Often missing practical detail |
The regulator access provision is the most contested. Vendors — particularly large technology providers and cloud platforms — resist giving banks contractual rights to share contracts and information with regulators, to have regulators conduct onsite reviews, or to have third-party auditors perform work on the bank’s behalf. Examiners check for this provision, and its absence is a finding for critical activity relationships.
Our vendor exit planning analysis covers how to build transition assistance requirements into vendor agreements that actually support operationalizable exits.
The BaaS and Fintech Arrangement Layer: July 2024 Joint Statement
If your institution has bank-fintech partnerships — sponsor banking, banking-as-a-service, embedded finance, or fintech program management arrangements — the July 2024 joint statement on banks’ arrangements with third parties added examination expectations that go beyond the standard interagency TPRM guidance.
The joint statement addressed a specific failure pattern the agencies observed: sponsor banks relying entirely on fintech partners’ representations about their BSA/AML compliance, consumer protection practices, and operational controls — without independent oversight capability. The statement made clear that banks cannot delegate compliance to fintech partners. Banks must have:
- Direct oversight capability, including ability to independently assess fintech activity
- Termination rights that are actually exercisable, with documented ability to execute them
- Concentration risk monitoring when a significant portion of revenue comes from a small number of fintech programs
- Board-level awareness of the bank’s fintech-related risk profile
Examiners reviewing BaaS programs in 2026 are specifically checking whether banks can demonstrate independent oversight — not just contractual rights to oversight. A contract that gives the bank audit rights isn’t meaningful if the bank has never exercised them or doesn’t have the internal capability to do so.
For institutions managing cloud provider concentration risk within their fintech partnerships, our cloud concentration risk examination guide covers what examiners are specifically looking for on sub-provider dependencies.
Subcontractor Risk: The Tier That Examiners Are Now Reaching
The May 2026 joint trade TPRM roundtable — published by the Consumer Bankers Association, American Fintech Council, Coalition for Financial Ecosystem Standards, and ICBA — identified subcontractor risk as one of the most challenging areas of guidance implementation. The roundtable, conducted under Chatham House rules, drew on input from banks, technology providers, and current and former regulatory representatives.
The core challenge: the guidance asks banks to understand their critical vendors’ subcontracting practices. But most institutions don’t have contractual rights to directly examine their vendors’ subcontractors — they can only request information through the vendor. Vendors, particularly large cloud providers and technology platforms, resist disclosing their full subcontractor footprints or accepting liability for subcontractor failures.
The practical minimum examiners expect:
- For each critical activity vendor, documentation of who that vendor’s critical subcontractors are
- Understanding of what the subcontractor does in the service delivery chain
- Any known risk indicators about the subcontractor
- Whether the bank’s contract with the vendor provides notification rights if critical subcontractors change
This is a minimum floor — it doesn’t require a full due diligence workup on every subcontractor. But examiners want to see that institutions have mapped the dependency and thought through what happens if a critical subcontractor fails.
What to Fix Before Your Next Exam
| Area | Common Gap | Fix |
|---|---|---|
| Critical activity designation | Criteria undocumented or inconsistently applied | Build written criteria; document the designation decision for each vendor |
| Due diligence depth | Questionnaire responses accepted without validation | Add evidence review requirement: SOC 2 exceptions, audited financials analysis, BCP test results |
| Ongoing monitoring | Annual questionnaire only | Add automated news monitoring, periodic financial check-ins, escalation protocol |
| Written agreements | Missing elements, especially regulator access | Contract review against the guidance’s 14 elements; negotiate missing provisions at renewal |
| Subcontractor mapping | Not started | Request critical subcontractor lists from critical activity vendors; document what you know and don’t know |
| BaaS oversight | Contractual rights only, no demonstrated exercise | Schedule and execute at least one independent review of a fintech partner’s compliance activity |
So What?
Three years in, the examination expectation has shifted. Examiners aren’t checking whether you have a TPRM program anymore. They’re checking whether it actually functions as a risk management tool or whether it’s administrative theater that produces binders and vendor questionnaires that nobody uses.
The institutions that will have clean TPRM examinations in 2026 and 2027 are the ones that can show substantive due diligence work, monitoring that generated actual escalations, critical activity designations with documented rationale, and written agreements with all required provisions — not just most of them.
If you’re building out or refreshing your TPRM program and need documentation templates aligned to the interagency guidance requirements, the Third-Party Risk Management Kit includes vendor tiering criteria, due diligence workpaper templates, ongoing monitoring protocols, and a written agreement checklist mapped to the guidance’s required elements.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What does OCC Bulletin 2023-17 require for third-party due diligence?
What does 'critical activity' mean under the interagency TPRM guidance?
What are the most common TPRM exam findings from OCC and FDIC examiners in 2026?
How does the July 2024 joint statement on bank-fintech arrangements add to TPRM obligations?
What is fourth-party risk and how are examiners evaluating it in 2026?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Keep reading
Related posts.
Third-Party Risk
Third-Party Risk Management Lifecycle RACI: Fix the Handoffs Between Procurement, Security, Legal, Business Owners, and Risk
A TPRM lifecycle RACI that assigns clear ownership at each stage — planning, due diligence, contracting, onboarding, monitoring, and offboarding — so findings don't fall between functions.
Jul 24, 2026
Third-Party Risk
Vendor Due Diligence Without a SOC 2: What Evidence Can Actually Substitute
A vendor due diligence checklist for evaluating security evidence when a vendor has no SOC 2 report, with a risk-based substitution matrix.
Jul 23, 2026
Third-Party Risk
Three Vendors, One Existential Risk: What the OCC's Community Bank Core Provider RFI Actually Asked
The OCC published Bulletin 2025-39 asking community banks hard questions about their relationships with Fiserv, FIS, and Jack Henry. The questions reveal exactly what examiners are now checking — and what most TPRM programs haven't addressed.
Jul 23, 2026