Skip to content
RiskTemplates · The Daily Brief Friday, September 11, 2026
Wire SEC's $3.02M Doximity Insider Trading Judgment: The MNPI Control Test SEP 10

Feature Third-Party Risk

The OCC Bulletin 2023-17 Vendor Due Diligence File: What Examiners Expect to See for Every Critical Third Party

FDIC data shows 35% of supervised institutions had a TPRM finding in 2024, with incomplete due diligence and inadequate ongoing monitoring as the top two gaps. This is what goes in the file — and what examiners are looking for when they open it.

By Rebecca Leung · September 2, 2026 ·
Table of Contents

TL;DR

  • The FDIC found TPRM deficiencies in 35% of supervised institutions in 2024; the top two gaps were incomplete due diligence and inadequate ongoing monitoring
  • OCC Bulletin 2023-17’s five-lifecycle framework — planning, due diligence and selection, contract negotiation, ongoing monitoring, termination — defines what examiners expect at every stage
  • A “critical vendor due diligence file” needs to document at least eight specific areas: financial condition, experience/qualifications, info security, operational resilience, subcontractors, insurance, risk management, and contractual arrangements
  • Thread Bank’s May 2024 consent order required a “documented risk assessment” of each fintech partner — a baseline requirement, not an advanced one
  • If your program has the questionnaire but not the evidence trail, that’s the gap examiners are finding

Third-party risk management failures rarely look like a missing policy. They look like a missing file.

The examiner asks for the due diligence record for your top five critical vendors. Your team produces questionnaires from three years ago, a contract, and a SOC 2 report that expired in 2023. Nobody documented whether the report had relevant exceptions. Nobody noted who reviewed it. No one ran the annual reassessment last year because the team was short-staffed and “it was the same vendor.”

That’s the pattern the FDIC’s 2024 Risk Review documented: 35% of supervised institutions with a TPRM finding, and in most of those cases, the problems weren’t structural. The program existed. The questionnaires existed. The gap was in the evidence — complete, current, reviewed documentation that demonstrates due diligence actually happened.

OCC Bulletin 2023-17 spells out what that evidence should look like. Here’s how to build the file.


The Five-Lifecycle Framework and Where the Evidence Goes

OCC Bulletin 2023-17, the interagency third-party risk management guidance issued June 6, 2023 by the OCC, Federal Reserve, and FDIC, organizes TPRM around five lifecycle stages: planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination.

Each stage is supposed to generate documentation. Examiners don’t just review your policies — they open the vendor files to see what your policies actually produced.

The two stages where documentation most consistently breaks down are due diligence and ongoing monitoring. That’s not a coincidence. Those are also the two stages the FDIC flagged as the most common deficiency categories in 2024.


What “Critical Activity” Means in Practice

Before you can build a due diligence file, you have to decide which vendors warrant one. The guidance describes a risk-proportionate approach: more rigorous review for “critical activities,” scaled down for lower-risk relationships.

The guidance describes critical activities as those where failure or disruption of the third party could cause significant risk to the banking organization, its customers, or the broader financial system. In practice, examiners apply a de facto test:

  • Substitutability: If this vendor shut down tomorrow, how fast could you replace the function? A core processor or sponsor bank relationship is not easily substitutable. A generic office supply vendor is.
  • Scale and volume: Does this vendor touch a material portion of your customer base, transactions, or regulatory obligations?
  • Data sensitivity: Does the vendor have access to customer PII, account data, or systems that contain regulated data?
  • Regulatory flow-through: Do your BSA/AML, fair lending, Reg E, or other compliance obligations flow through this vendor’s platform?

If any of these answers is “yes,” the vendor likely supports a critical activity and warrants full due diligence documentation. The classification decision itself should also be documented — examiners want to see not just the file but the logic behind the tiering.


The Eight Elements of a Complete Due Diligence File

For a critical vendor, OCC Bulletin 2023-17 identifies eight categories of due diligence that should be assessed and documented:

1. Financial Condition

Current, audited financial statements — not a summary, and not three years old. For publicly traded vendors, most recent filings are readily available. For private vendors, this requires directly requesting financial statements and documenting their review. Examiners look for evidence that you assessed whether the vendor has the financial stability to continue operations and meet contractual obligations.

2. Business Experience and Qualifications of Key Personnel

Reference checks, leadership biographies, or third-party assessments of the vendor’s track record. Not a marketing deck. For BaaS platforms and fintech middleware, this includes assessment of whether the team has operated at the scale your program will require.

3. Risk Management Practices

Does the vendor have a risk management program of their own? Do they perform vendor risk assessments for their own subcontractors? The guidance requires you to assess whether the third party’s risk management practices align with your requirements — not just assume they do.

4. Information Security Controls

A SOC 2 Type II report, NIST CSF assessment, or equivalent third-party audit of the vendor’s security posture. Critically, this needs to be current (generally within the last 12 months), and your documentation needs to show that someone actually reviewed the report for exceptions, scope limitations, and whether the trust service criteria covered the services you’re actually using.

A SOC 2 report with a “modified opinion” that nobody noticed is a documented audit trail of a process failure, not a due diligence artifact.

5. Operational Resilience

Does the vendor have a business continuity plan? What are their RTOs and RPOs for services you depend on? Have they tested? The guidance treats operational resilience as a distinct due diligence category — not something you can infer from the SOC 2.

6. Subcontractor Reliance

Where does your vendor outsource? This is the fourth-party risk question, and it’s one of the most consistently underdocumented areas in TPRM programs. OCC 2023-17 explicitly requires you to assess the vendor’s reliance on its own subcontractors. The BaaS space makes this acutely relevant — if your program runs through a middleware platform that depends on an AWS architecture that depends on a specific availability zone, that chain of dependency should be mapped and documented.

7. Insurance Coverage

What coverage does the vendor carry? Errors and omissions, cyber liability, and general commercial liability are the baseline questions. The documentation should confirm coverage and assess whether it’s adequate for the relationship.

8. Contractual Arrangements with Other Parties

Does the vendor have exclusive arrangements, volume commitments, or data-sharing agreements with competitors that create conflicts or concentration risk? This is the least commonly documented element and one that shows up in examiner questions about vendor conflicts of interest.


Between 2022 and 2025, the FDIC, OCC, and Federal Reserve issued consent orders against at least seven sponsor banks operating BaaS programs. The documentation problems in these cases are instructive.

Piermont Bank’s February 2024 consent order cited failure to have internal controls and information systems adequate for the bank’s size and the scope of its third-party relationships. Sutton Bank’s order required documented oversight policies. Thread Bank’s May 2024 order went to a more basic level — it required the bank to implement a “documented risk assessment” of each fintech partner.

Thread’s consent order is particularly telling because Thread wasn’t required to have a sophisticated TPRM program. It was required to have a documented risk assessment. The documentation gap — not a conceptual gap, not a program design gap — was what triggered the formal action.

The FDIC’s emerging fintech certification initiative (BISDO/RAMP) is partly a response to this documentation problem at scale. BISDO’s pitch is that common standards reduce the burden of producing the same documentation for every bank partner. But the underlying requirement — documented, evidence-backed due diligence — remains unchanged.


The Ongoing Monitoring Gap

Due diligence gets more attention, but examiners are equally focused on ongoing monitoring — specifically, whether monitoring is happening continuously rather than annually, whether there’s a documented trigger-event process, and whether monitoring activity is actually captured in writing.

For critical vendors, a reasonable ongoing monitoring cadence looks like:

  • Quarterly: Financial health review, incident log review, SLA performance metrics
  • Annually: Comprehensive reassessment including updated questionnaire, fresh SOC 2 or equivalent, subcontractor review
  • Trigger-event: Out-of-cycle review triggered by vendor acquisition, regulatory action against the vendor, material security incident, key personnel departure, or significant service degradation

The monitoring record should show dated activity for each of these. An examiner who opens the monitoring file and sees an annual questionnaire sent in 2023 and nothing since is looking at the same deficiency the FDIC cited in 35% of its examinations.

For more on building a structured monitoring program, vendor financial health monitoring best practices provides specific indicators and cadences that align with OCC 2023-17 expectations.


The Contract Negotiation Layer

The guidance treats contract negotiation as a distinct lifecycle stage — not because the contract itself constitutes due diligence, but because contract provisions are part of how you secure ongoing compliance obligations, access rights, and exit rights.

For critical vendors, OCC 2023-17 identifies contract provisions that should be included: the nature and scope of the arrangement, performance standards and service level agreements, right to audit, data security obligations, business continuity requirements, notification requirements for incidents, change management processes, and termination rights.

The contract provisions requirements under OCC 2023-17 go into detail on the specific clauses. The examiner expectation is that the contract aligns with the risk assessment — if your due diligence identified a significant IT concentration risk, the contract should include audit rights and incident notification provisions that address that risk.


So What? Building the File Your Examiner Will Actually Review

The FDIC’s 35% finding rate isn’t a sign that TPRM programs don’t exist. It’s a sign that the evidence isn’t there to prove they’re working.

The practical task is building the vendor due diligence file as a document that would survive independent review — not by someone who knows your program, but by an examiner who is opening the file for the first time. That means:

  • For each critical vendor: A current, dated file with all eight due diligence elements documented, including evidence of actual review (not just receipt) of SOC reports, financial statements, and questionnaire responses
  • For each ongoing monitoring cycle: Dated activity notes, flagged exceptions, and evidence of follow-up on any issues identified
  • For each trigger event: A documented decision about whether the event warranted an out-of-cycle review and, if not, why not
  • For the tiering decision itself: Written documentation of the criteria used to classify each vendor as critical, significant, or routine

A TPRM program that exists on paper is a policy document. A TPRM program that examiners can verify is a vendor file.


The Third-Party Risk Management (TPRM) Kit includes a structured vendor due diligence questionnaire mapped to OCC 2023-17’s eight due diligence elements, a critical activity tiering matrix, an ongoing monitoring tracker with trigger-event protocols, and a contract provisions checklist — designed to produce the documentation file this post describes.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What does OCC Bulletin 2023-17 require for vendor due diligence?
OCC Bulletin 2023-17 — the interagency third-party risk management guidance issued June 6, 2023 by the OCC, Federal Reserve, and FDIC — requires banking organizations to conduct due diligence proportionate to the risk and criticality of the third-party relationship. For critical activities, due diligence should cover the vendor's financial condition, business experience and qualifications, key personnel, risk management practices, information security controls, operational resilience capabilities, subcontractor reliance, insurance coverage, and existing contractual arrangements with other parties.
How does OCC 2023-17 define a 'critical activity'?
OCC Bulletin 2023-17 does not provide a single bright-line definition, but treats an activity as 'critical' when the failure or disruption of the third party could cause significant risk to the banking organization, its customers, or the broader financial system. In practice, examiners look for evidence that you've assessed which vendors support activities where substitution would be difficult, where the volume or scale is material, where regulatory obligations flow through the vendor, and where sensitive customer data is involved.
What was the FDIC's finding rate for TPRM deficiencies in 2024?
According to FDIC's 2024 Risk Review, 35% of FDIC-supervised institutions had at least one third-party risk management finding during their examination. The two most common deficiency categories were incomplete due diligence and inadequate ongoing monitoring — the same two areas that appear in most BaaS-related consent orders from 2022 through 2025.
What specific items do examiners expect to find in a vendor due diligence file?
For a critical vendor, a complete due diligence file typically contains: the vendor's most recent audited financial statements, SOC 2 Type II report (or equivalent third-party assessment), a completed vendor questionnaire covering information security and operational resilience, reference checks or qualifications review for key personnel, subcontractor mapping, evidence of insurance coverage review, and confirmation that no material contractual arrangements with other parties create conflicts or concentration risk. For Tier 2 vendors, some of these elements may be scaled down, but the file should document that scaling decision.
How often does ongoing monitoring documentation need to be updated for critical vendors?
OCC 2023-17 describes ongoing monitoring as a continuous process, not an annual event. For critical vendors, most well-run programs use quarterly reviews of financial health and incident activity, with annual comprehensive reassessments. Examiners look for evidence of monitoring triggers — events that should prompt an out-of-cycle review (vendor acquisition, data breach, regulatory action, key personnel departure, significant service degradation) — and documentation that those triggers were actually acted on.
What triggered the FDIC consent orders against Piermont Bank, Sutton Bank, and Thread Bank?
All three were issued in 2024 in connection with BaaS programs. Piermont Bank's February 2024 consent order cited unsafe and unsound banking practices and failure to maintain internal controls and information systems adequate for the bank's size and the scope of its third-party relationships. Sutton Bank's February 2024 order required revised AML/CFT policies and documented oversight of third-party relationships. Thread Bank's May 2024 order specifically required the bank to implement a documented risk assessment of each fintech partner — a baseline TPRM requirement that was missing.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Third-Party Risk Management (TPRM) Kit

Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.