FAQs About Bank Vendor Management
Bank Vendor Management FAQs
What is vendor management?
Vendor management is the process a bank uses to identify, assess, select, monitor, and manage third-party service providers throughout the vendor relationship.
Why is vendor management important for banks?
Banks rely on third parties for many critical services, including technology, payments, cloud services, core processing, cybersecurity, and operational support. Effective vendor management helps the bank identify and manage risks associated with those relationships.
What is third-party risk management (TPRM)?
TPRM is the broader framework for identifying, assessing, monitoring, and controlling risks arising from third parties. Vendor management is an important component of a bank's overall third-party risk-management program.
Who is responsible for vendor management?
Vendor management is a shared responsibility. Business owners, procurement, information security, compliance, legal, risk management, and senior management may all have responsibilities depending on the nature and risk of the relationship. The board and senior management provide appropriate oversight.
What types of vendors require additional oversight?
Higher-risk vendors may include those that:
- Provide critical or essential services
- Have access to sensitive customer or bank information
- Connect directly to bank systems or networks
- Support payment processing
- Provide cloud or technology services
- Perform regulated or compliance-related functions
- Could materially affect the bank's operations or reputation if they fail
What is vendor risk assessment?
A vendor risk assessment evaluates the risks associated with engaging a particular third party. Factors may include the services provided, data accessed, system connectivity, financial condition, regulatory considerations, cybersecurity, business continuity, and concentration risk.
What is due diligence?
Vendor due diligence is the process of evaluating a third party before entering into a relationship. Depending on the risk, due diligence may include reviewing financial information, ownership, reputation, information-security controls, compliance programs, business continuity capabilities, insurance, references, and relevant certifications or reports.
How often should vendors be reviewed?
The frequency of vendor reviews should be based on the risk and criticality of the relationship. Higher-risk and critical vendors generally require more frequent monitoring and reassessment than lower-risk vendors.
What is a critical vendor?
A critical vendor is generally a third party whose failure or disruption could materially affect the bank's operations, customers, compliance obligations, financial condition, or reputation. The bank should establish criteria for determining which relationships are critical.
What should a vendor contract include?
Depending on the relationship and risk, contracts may address:
- Scope of services
- Performance standards and service levels
- Data protection and confidentiality
- Information-security requirements
- Regulatory compliance
- Audit and examination rights
- Incident and breach notification
- Business continuity and disaster recovery
- Insurance requirements
- Subcontractor management
- Data ownership and return
- Termination rights
- Record retention
- Appropriate indemnification and liability provisions
What are service-level agreements (SLAs)?
SLAs establish measurable performance expectations for a vendor. They may address availability, response times, processing requirements, support, incident resolution, and other service standards.
What is vendor cybersecurity due diligence?
Vendor cybersecurity due diligence evaluates whether a third party has appropriate controls to protect bank and customer information and systems. Depending on risk, the review may consider security policies, access controls, encryption, vulnerability management, incident response, penetration testing, independent assessments, and relevant certifications or reports.
What is a SOC report?
A SOC report is an independent examination report concerning controls at a service organization. Depending on the report type, it can provide information about controls relevant to security, availability, confidentiality, processing integrity, or privacy.
What is business continuity and disaster recovery (BC/DR)?
Business continuity and disaster recovery capabilities help a vendor maintain or restore critical services following disruptions such as cyber incidents, system failures, natural disasters, or other significant events.
Why should a bank review a vendor's financial condition?
A vendor's financial condition can affect its ability to continue providing services. Financial deterioration may increase the risk of service disruption, bankruptcy, reduced support, or other operational problems.
What is concentration risk?
Concentration risk occurs when a bank becomes excessively dependent on a particular vendor, service provider, technology platform, geographic location, or other third-party dependency. A significant disruption affecting that dependency could have a disproportionate impact on the bank.
What are fourth parties or subcontractors?
Fourth parties are organizations used by a bank's vendor to provide services to the bank. Banks should understand and manage relevant subcontractor risks, particularly when subcontractors have access to bank information, systems, or critical services.
Should vendors have access to customer information?
Vendor access should be limited to what is necessary to perform authorized services and should be subject to appropriate contractual, security, privacy, and access controls.
What should the bank do if a vendor experiences a security incident?
The bank should follow its incident-response and vendor-management procedures, assess the potential impact, coordinate with the vendor and appropriate internal teams, determine whether notification or regulatory obligations apply, and take appropriate corrective action.
What happens if a vendor does not meet its contractual requirements?
The bank should evaluate the issue, document the deficiency, and take corrective action consistent with the contract and vendor-management program. Actions may include remediation plans, increased monitoring, escalation, financial remedies, or termination when appropriate.
Can a bank outsource a regulated activity and transfer its responsibility to the vendor?
Outsourcing an activity does not eliminate the bank's responsibility to manage the associated risks and comply with applicable laws and regulatory requirements. The bank should maintain appropriate oversight of outsourced activities.
Why is ongoing vendor monitoring important?
A vendor's risk profile can change after onboarding. Ongoing monitoring helps the bank identify changes in financial condition, cybersecurity, ownership, services, regulatory compliance, performance, subcontractors, or other factors that could affect the relationship.
What should happen when a vendor relationship ends?
The bank should follow an established termination process that addresses access removal, return or destruction of data, recovery of bank property, outstanding obligations, record retention, transition of services, and other contractual or risk-management requirements.
What documentation should a bank maintain for vendors?
Documentation should be sufficient to demonstrate appropriate due diligence, risk assessment, approval, contracting, monitoring, issue management, and termination. Records should be maintained in accordance with the bank's policies and applicable requirements.
What should employees do if they want to engage a new vendor?
Employees should follow the bank's vendor-onboarding and procurement process before committing to a third party or sharing bank or customer information. The appropriate risk, compliance, security, legal, and business reviews should be completed based on the vendor's risk profile.
Most-Used Training Courses:
Recommended Online Training Courses