OCC Heightened Standards (12 CFR Part 30, Appendix D)
Third-Party Risk and Regulatory Integration

OCC Heightened Standards (12 CFR Part 30, Appendix D) OCCHS-8: Third-Party Risk Within Heightened Standards and Integration with Broader Regulation

Operate third-party risk within Heightened Standards + integrate with broader bank regulation. Third-party risk per Heightened Standards must (a) integrate with OCC Bulletin 2013-29 Third-Party Risk Management + Interagency Guidance on Third-Party Relationships Risk Management (June 2023) jointly issued by OCC + Federal Reserve + FDIC, (b) cover all third-party relationships including critical relationships + cloud service providers + fintech partnerships + outsourcing arrangements + with risk-based diligence + contractual requirements + ongoing monitoring + termination management, (c) align with Risk Governance Framework + Risk Appetite Statement + Risk Limits + Internal Audit coverage. Integration with broader regulation must address (a) Federal Reserve SR 12-17 Consolidated Supervision Framework for Large Financial Institutions + SR 16-11 Supervisory Guidance for Assessing Risk Management at Supervised Institutions with Total Consolidated Assets Less than USD 100 Billion, (b) FDIC Statement of Policy on Bank Merger Transactions + Risk Management Manual of Examination Policies, (c) State banking regulator coordination where applicable, (d) CFPB supervision and enforcement of consumer financial law, (e) FinCEN Bank Secrecy Act / Anti-Money Laundering compliance + OFAC sanctions compliance, (f) SEC and FINRA where applicable to broker-dealer subsidiaries, (g) HMDA + CRA + ECOA + FCRA + similar consumer protection law, (h) state attorneys general consumer financial regulation. Maintain regulatory inventory + change-monitoring + cross-regulator coordination via Chief Compliance Officer.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.