Skip to content
RiskTemplates · The Daily Brief Sunday, July 26, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Third-Party Risk

OCC 2023-17 Vendor Contract Provisions: What Goes in Every Critical Vendor Agreement — and What Examiners Flag First

OCC Bulletin 2023-17 specifies exactly what should be in every critical vendor contract — from right-to-audit to subcontracting controls to exit planning. Here's the complete list, where most agreements fall short, and what to do when a large vendor won't accept the terms the guidance requires.

By Rebecca Leung · June 15, 2026 ·
Table of Contents

TL;DR:

  • OCC Bulletin 2023-17 (joint interagency guidance from the OCC, Federal Reserve, and FDIC) specifies over a dozen contract provisions that banking organizations should include in agreements with critical vendors — covering audit rights, subcontracting, data handling, BCP/DR, and exit planning.
  • The contract negotiation stage is phase three of the five-stage TPRM lifecycle. Provisions locked in here determine what leverage you actually have during ongoing monitoring and at termination.
  • Vendor oversight deficiencies appear in over 40% of community bank examinations; missing or inadequate contract provisions are among the most commonly cited specific gaps.
  • When you can’t negotiate a provision with a large vendor, the guidance provides a documented compensating-control path — but only if you write it down at the time of contracting.

An examiner sits down with your TPRM program documentation. She doesn’t start with your vendor list or your due diligence checklist. She pulls three critical vendor contracts at random.

She’s not checking whether you negotiated a competitive price. She’s checking whether you can audit the vendor without the vendor’s prior consent, whether your data handling clause covers what the vendor actually does with customer NPI, and whether you have explicit termination rights if the vendor is acquired or if a regulator directs you to exit the relationship.

Those provisions should be in every critical vendor contract under OCC Bulletin 2023-17 — the joint interagency guidance issued by the OCC, Federal Reserve, and FDIC on June 6, 2023. Most practitioners know the guidance exists. Fewer know exactly which contract terms it specifies, and fewer still have a systematic process to verify that existing contracts include them.

This post covers what the guidance actually says about contracts, where most agreements fall short, and what to do when a vendor won’t accept the provisions the guidance requires.

Where Contracts Fit in the TPRM Lifecycle

The 2023 interagency guidance structures third-party risk management as a five-stage lifecycle:

  1. Planning — define the business need; conduct a risk assessment before selecting any vendor
  2. Due Diligence and Third-Party Selection — evaluate vendor capabilities, financial condition, and compliance posture
  3. Contract Negotiation — establish the formal terms of the relationship
  4. Ongoing Monitoring — continuous oversight proportional to risk
  5. Termination — managed exit or wind-down

The contract negotiation stage is where risk assessment and due diligence findings get codified into enforceable obligations. If due diligence reveals that a vendor handles sensitive customer data, the contract must require protection of it. If due diligence reveals a single point of failure in a critical service, the contract must establish BCP and DR requirements.

That’s why examiners pull contracts. A rigorous risk assessment paired with a weak contract signals the bank assessed the risk but didn’t actually manage it.

What the Guidance Says Should Be in Every Critical Vendor Contract

The interagency guidance addresses contract negotiation content in detail across several categories. For critical third-party relationships, examiners expect all of the following.

Nature and Scope of the Arrangement

The contract should clearly define what the vendor is — and is not — authorized to do. This includes the specific services covered, the geographic scope of those services, which personnel or systems are authorized to access the bank’s data or infrastructure, and any explicit restrictions on how the vendor may use bank data for its own purposes.

A scope clause that allows the vendor to “use data to improve services” without defining what that means creates compliance risk under GLBA and gives examiners reason to question whether customer data controls extend to the vendor.

Performance Standards and Service Level Agreements

The guidance expects measurable performance benchmarks — uptime, processing speed, error rates, response times — with explicit remediation rights when a vendor misses them. A well-drafted SLA specifies:

  • The measurement period and methodology
  • Notification timelines when performance degrades
  • Cure periods before the bank may exercise remediation rights
  • Available remedies: fee credits, required remediation plans, enhanced reporting, or exit triggers

SLAs that specify performance metrics without any consequence for missing them are common in community bank contracts and a reliable exam finding.

Security and Confidentiality

This is often the most negotiated section. The guidance expects provisions addressing:

  • Data encryption requirements at rest and in transit
  • Access control standards and authentication requirements for vendor personnel accessing bank systems or data
  • Incident notification — how quickly the vendor must notify the bank of a security event affecting bank data or systems
  • Restrictions on vendor use of bank data for any purpose beyond the contracted service
  • Obligations to return or destroy bank data at contract termination

The incident notification timeline in the vendor contract should align with the bank’s own regulatory notification obligations. If the bank has a 36-hour notification obligation to its primary federal regulator under the Computer-Security Incident Notification rule (12 CFR Part 53), the vendor contract should require vendor notification to the bank with sufficient lead time to permit the bank to make its own notification.

Audit and Report Requirements

The right to audit is one of the provisions that most frequently falls short in practice — particularly in contracts with cloud providers, core banking platforms, and large SaaS vendors.

The guidance expects banks to have the right to examine vendor books and records relevant to the contracted services, including the ability to conduct or commission independent assessments. When banks cannot negotiate direct audit rights — most commonly with hyperscalers and dominant platform vendors — the guidance’s risk-based framework accepts compensating controls:

Compensating ControlWhat to Require
SOC 2 Type II reportsAnnual report provided on request; scope covers the specific services used
ISO 27001 certificationCurrent certificate and most recent surveillance audit report
Penetration testing resultsThird-party test of the environment hosting bank data, annually
Regulatory exam resultsFor vendors that are themselves regulated entities

If you’re relying on compensating controls rather than direct audit rights, document in writing at the time of contracting: (1) why direct rights weren’t obtained, (2) what compensating controls you’re accepting, and (3) who approved the exception. Examiners will ask, and the documentation should be in the contract file, not reconstructed after the fact.

Regulatory Compliance

The vendor must agree to comply with all laws and regulations applicable to the services it provides. For bank-critical vendors, this typically encompasses BSA/AML obligations where applicable, consumer protection requirements where the vendor’s activities touch bank customers, and privacy and data protection requirements under GLBA and applicable state laws.

This clause should also specify which party bears responsibility for monitoring regulatory changes — and what process applies when a regulatory change requires modifications to the service or to the contract itself.

Dispute Resolution

A defined escalation and dispute resolution process, including the governing law and jurisdiction for contract disputes. This provision matters more than it seems: disputes over data ownership, indemnification scope, or liability for regulatory penalties can take years to resolve without a clear contractual framework establishing who decides and under what law.

Liability and Indemnification

The guidance expects provisions that address each party’s liability for their own acts and omissions, indemnification for third-party claims arising from vendor failure, insurance requirements (cyber liability, errors and omissions), and caps on liability.

Liability caps that apply without exception to data breach scenarios are a specific area of examiner attention. A $50,000 liability cap in a contract with a vendor processing millions of customer records creates a risk management gap the bank should have identified in due diligence and addressed in contracting.

Subcontracting

This is where fourth-party risk becomes a contract requirement rather than just a policy consideration. OCC 2023-17 expects the primary vendor contract to address subcontracting explicitly:

ProvisionWhat It Requires
Prior bank consentBank must approve before vendor subcontracts critical services
Flow-down obligationsSubcontractors must be held to equivalent security, privacy, and performance standards
Primary vendor liabilityPrimary vendor remains fully responsible for subcontractor performance
Bank oversight rightsBank retains audit rights over subcontractors or right to require evidence of subcontractor oversight
Change notificationVendor must notify bank before changing subcontractors for critical services

The interagency guidance’s treatment of subcontracting directly connects to fourth-party and nth-party risk — see our guide to nth-party risk under OCC 2023-17 for how to map and manage the full subcontracting chain.

Business Continuity and Disaster Recovery

The guidance expects vendor BCP/DR obligations to be spelled out contractually: recovery time and recovery point objectives for services the bank depends on, the vendor’s obligation to test its plans, and an obligation to provide testing results on request. The vendor should also be required to notify the bank of disruptions that affect service delivery within defined timeframes.

Community banks whose vendors provide core banking services are particularly exposed here. A vendor BCP failure can quickly become a bank operational risk event — and without contractual BCP requirements and testing evidence, the bank has no visibility into whether the vendor can recover within the bank’s own RTO expectations.

Termination Rights

Termination provisions define what the bank can actually do when things go wrong. The guidance expects:

  • For-cause termination: specific triggering events — material breach, vendor insolvency, regulatory action against the vendor, a security incident exceeding a defined threshold
  • Termination for convenience: the bank’s right to exit for business reasons, with reasonable notice
  • Regulatory direction: the right to terminate if a regulator specifically directs the bank to exit the relationship
  • Change of control: the right to exit or renegotiate if the vendor is acquired by another entity, particularly a competitor
  • Cure periods: defined timeframes for the vendor to remedy a breach before termination becomes effective

Vendor contracts that include for-cause termination but exclude termination-for-convenience and regulatory-direction rights are a recurring exam finding. The absence of a regulatory-direction exit right creates a particular problem in BaaS environments, where consent orders against sponsor banks have sometimes required rapid exits from fintech partnerships.

Exit Planning

Contract-level exit planning provisions address what happens when the relationship ends — whether at natural term, by early termination, or through a vendor insolvency scenario.

The guidance expects:

  • The vendor’s obligation to maintain bank data in a portable, usable format throughout the term
  • Transition assistance requirements — how long the vendor will support a migration, what tasks are included
  • Data return or destruction timelines and certifications
  • Restrictions on vendor use of bank data post-termination

Exit planning provisions have received heightened examiner attention following the 2024 Synapse bankruptcy, which demonstrated what happens when a middleware vendor’s collapse occurs without adequate data portability and transition provisions — approximately $160 million in customer deposits were frozen as trustees tried to reconcile ledgers with no clear process for returning customer funds. See also our critical vendor exit planning guide for the full wind-down process.

When the Vendor Won’t Accept the Provisions

The Federal Register notice accompanying OCC 2023-17 acknowledged directly what every TPRM practitioner knows: banking organizations “may lack sufficient leverage in negotiations with larger third parties and may struggle to get certain ‘typical’ provisions into contracts.”

The guidance’s response is risk-based, not prescriptive. For provisions you can’t negotiate:

  1. Document the attempt — record in the contract file that you sought the provision and the vendor declined
  2. Document the compensating control — specify what alternative evidence or protection you’re accepting in lieu of the provision
  3. Document the approval — confirm who reviewed and approved the exception, at what level of authority
  4. Build it into ongoing monitoring — if you’re relying on SOC reports in lieu of audit rights, build an annual review of those reports into your monitoring calendar

What examiners don’t accept is a missing provision with no documented rationale. An undocumented gap looks like something you missed. A documented gap with a compensating control looks like something you managed.

A Contract Review Calendar

The guidance doesn’t prescribe a fixed review interval, but exam expectations favor:

EventRequired Action
New vendor contractFull provision review before execution
Contract renewal (≥3 years)Treat as new — full provision review
Significant scope changeTriggered review of affected provisions
Material vendor incidentTriggered review of security and termination provisions
Vendor change of controlTriggered review of all provisions
Annual cycle (critical vendors)Verify key provisions remain adequate; update exception log

So What?

The contract is not a formality at the end of due diligence. It is the mechanism through which risk assessment findings become enforceable obligations — and the document an examiner uses to verify that your TPRM program functions in practice, not just on paper.

If your vendor list is well-organized and your due diligence process is solid but your contracts predate OCC 2023-17 and were negotiated without attention to its provisions, you have a program gap. The path forward: targeted provision review at each renewal, documented exceptions with compensating controls for provisions you can’t negotiate, and a file structure that makes the review visible and auditable.

The BaaS Consent Order Playbook illustrates what contract gaps look like at scale — the 2022-2025 enforcement wave against BaaS banks surfaced TPRM deficiencies across BSA/AML coverage, ongoing monitoring, and contractual documentation that were consistent enough across agencies and institutions to define a minimum standard. Contract provisions were a recurring gap in virtually every order.

The Third-Party Risk Management (TPRM) Kit includes a vendor contract review checklist mapped to OCC 2023-17’s contract negotiation requirements, a provision exception log template, and a critical vendor tiering methodology you can apply to your existing vendor inventory starting this week.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Does OCC 2023-17 apply to fintechs directly?
Not directly — OCC 2023-17 is interagency guidance directed at banking organizations supervised by the OCC, Federal Reserve, and FDIC. But fintechs in bank partnerships feel its effects indirectly: their bank partners must satisfy the guidance when managing the fintech as a third party. That means banks require fintechs to accept contract terms reflecting OCC 2023-17's standards. Fintechs that understand what the guidance requires are better positioned to negotiate efficiently and avoid friction in bank partnership due diligence.
What makes a vendor 'critical' under OCC 2023-17?
The guidance doesn't use a single bright-line definition, but it defines criticality through risk characteristics: involvement in core banking operations, significant customer data processing, difficulty of substitution, and services subject to specific regulatory requirements. Examiners expect a formal criticality tiering methodology — and more rigorous contract requirements applied to vendors in the highest tier.
What if a large cloud vendor won't accept our right-to-audit clause?
The interagency guidance directly acknowledges this problem. The Federal Register notice accompanying OCC 2023-17 noted that banks 'may lack sufficient leverage in negotiations with larger third parties.' The guidance's risk-based approach allows compensating controls: if you can't get direct audit rights, you can compensate with SOC 2 Type II reports, ISO 27001 certifications, penetration testing summaries, and regulatory exam results. The key is documenting in writing why direct audit rights weren't obtained and what alternative evidence you're accepting.
How often do examiners actually pull vendor contracts?
Regularly. Vendor oversight deficiencies appear in over 40% of community bank examinations, and examiners reviewing TPRM programs routinely request a sample of critical vendor contracts to verify required provisions are present. They focus particularly on BCP/DR requirements, data handling and security provisions, and termination rights — areas where community banks have historically had the weakest contractual protection.
What provisions do I need if my vendor subcontracts part of the service?
OCC 2023-17 requires the primary vendor contract to address subcontracting explicitly. At minimum: the bank must consent before the vendor subcontracts critical services, the subcontractor must be held to equivalent standards, the primary vendor remains fully liable for subcontractor performance, and the bank retains audit rights over subcontractors or the right to require evidence of subcontractor oversight.
When should I review existing vendor contracts against OCC 2023-17?
New contracts: full review before execution. Renewals: treat as new if the term is three years or more, or if scope changed significantly. Triggered reviews: after a material vendor incident, significant ownership change, or when ongoing monitoring flags a concern. For critical vendors, an annual review cadence is appropriate even absent a trigger.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Third-Party Risk Management (TPRM) Kit

Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.