Skip to content
Industries / Banks

Third-party risk management your examiners can follow

For banks and banking groups answering to the OCC, FDIC, Federal Reserve, OSFI, the ECB and national authorities, the PRA, RBI, MAS, APRA and Gulf regulators. One record per third party, depth scaled to critical activities, and evidence your board and examiners can trace.

Seen through your eyes

The questions your program has to answer

Heads of third-party risk at banks tell us the hard part is not collecting questionnaires. It is proving to a board, an audit committee and an examiner that oversight is proportionate, current and complete.

Show me the evidence

Examiners test the file, not the policy. Every tiering decision, finding, exception and sign-off needs to be traceable to the document behind it.

Critical activities get more

Relationships that support critical activities, critical or important functions or material outsourcing need deeper diligence, tighter contracts and more frequent review.

Concentration you cannot see

Several of your critical vendors may depend on the same cloud region, core processor or card network. That risk sits in fourth parties, not in your contract list.

Exit plans that would work

Regulators increasingly expect documented, and for the most critical services tested, exit strategies. A paragraph in a policy is no longer enough.

The board owns the risk

Directors need to see where the bank is exposed, what changed and what decisions they are being asked to make, in a format they can read in ten minutes.

Many regulators, one program

Global groups answer to regimes with different vocabulary and registers. The program has to satisfy each without running five parallel processes.

Lifecycle

The third-party lifecycle, as your regulators describe it

The 2023 interagency guidance, OSFI B-10, DORA and the EBA guidelines all describe the same arc. VendRisk360 structures each vendor record around it, so the program reads the way examiners expect.

  1. 1

    Planning

    Intake captures the business case, the service, the data types involved and whether the relationship supports a critical activity.

  2. 2

    Due diligence

    Criticality sets the scope under your policy: typically a full artifact-based assessment for Critical vendors, a focused one for Material and a streamlined review for Low risk.

  3. 3

    Contracting

    Contract evidence, SLAs and required provisions (audit rights, subcontracting, termination) are held on the vendor record.

  4. 4

    Ongoing monitoring

    Reassessment runs on the cadence your policy sets for each tier (for example, annually for Critical vendors), with continuous monitoring in between.

  5. 5

    Termination and exit

    Offboarding records data return or destruction, access removal and exit evidence, closing the loop for the examiner.

Due diligence

Artifact-based assessments, not self-attestation

For vendors that support critical activities, controls are assessed on evidence across 30+ control domains: a point-in-time, inside-out review your analysts perform, record and sign off on the platform, or that VendRisk360 assessors perform for you through Comprehensive Vendor Risk Assessment Services. Continuous monitoring adds the outside-in view between reviews.

  • SOC 1 and SOC 2 review: exceptions, carve-outs, subservice organizations and CUECs, in-house or as an expert SOC Report Review
  • Penetration tests, BCP and DR test results, financial condition and insurance
  • Findings, remediation plans and risk acceptance with expiry dates
  • Multi-stage sign-off with segregation of duties between analyst, reviewer and risk owner
See vendor risk assessment services
Concentration and systemic risk

Know which critical activities share a single point of failure

Nth-party intelligence maps the providers behind your providers: the clouds, processors, data centers and software your vendors rely on. It shows concentration across your critical activities and the blast radius when one of them fails.

  • Fourth parties and subservice organizations drawn from SOC reports and vendor disclosures
  • Concentration by provider, service and region, across Critical and Material vendors
  • CUEC tracking: controls your vendors expect the bank to operate, mapped to your own
  • Evidence for DORA concentration assessments, RBI concentration monitoring and board reporting
Explore nth-party intelligence
Board and examiner reporting

Board packs and examiner files from the same live data

Nine ready-made decks, including the Board report, Audit committee and examiner readiness, Concentration risk, Incident and breach briefing and the Regulator and examiner meeting deck. Each is generated from live vendor records and exports to PDF or editable PowerPoint.

  • Examiner package export: inventory, tiering rationale, assessments, findings, sign-offs and monitoring history
  • Executive dashboards: heat map, trends, program health and decisions needed
  • Every figure traceable to the vendor record behind it
See board and executive reporting
Operational resilience

Exit strategies you can defend

DORA, the EBA guidelines, PRA SS2/21, OSFI B-10, RBI and APRA CPS 230 all expect you to plan for a critical provider failing or being replaced. VendRisk360 keeps that plan on the vendor record and keeps it current.

Stressed and orderly exit

Exit approach, alternative providers and transition timelines recorded for each critical arrangement.

Critical operations link

Which critical activity or operation depends on the vendor, recorded at intake and kept with the record.

Testing evidence

When the plan was last reviewed or tested, by whom, and what changed.

Offboarding evidence

Data return or destruction, access removal and final sign-off when a relationship ends.

Global regulatory alignment

Mapped to the regimes banks answer to

What each regime expects of a bank's third-party program, and how the platform supports it. Wording differs by jurisdiction; the underlying discipline is consistent.

Bank third-party risk regulations by jurisdiction and platform support
United StatesInteragency Guidance on Third-Party Relationships (2023); OCC Bulletin 2023-17, FDIC FIL-29-2023, Federal Reserve SR 23-4ExpectsRisk-based oversight across the full lifecycle, with more comprehensive oversight for relationships that support critical activities, and board accountability for the program.Platform supportLifecycle stages, criticality tiering, depth and cadence by tier, board reporting, and an audit trail of every decision.
United StatesFFIEC IT Examination HandbookExpectsOversight of technology service providers, including due diligence, contract provisions, business continuity and review of assurance reports.Platform supportArtifact-based assessments across 30+ control domains, SOC report analysis and BCP and DR evidence review.
United StatesNYDFS 23 NYCRR 500.11ExpectsWritten third-party service provider security policies: identification, risk assessment, minimum cybersecurity practices, due diligence and periodic assessment.Platform supportPolicy-driven intake and tiering, cybersecurity control domains, periodic reassessment and monitoring of vendor attack surface and breaches.
CanadaOSFI Guideline B-10, Third-Party Risk ManagementExpectsA third-party risk management framework, risk assessment before and during arrangements, subcontracting oversight, and plans for exit and disruption.Platform supportRisk-scoped intake, nth-party mapping of subcontractors, continuous monitoring and exit evidence at offboarding.
European UnionDORA, Regulation (EU) 2022/2554; EBA Guidelines on outsourcing arrangementsExpectsA register of information for ICT third-party arrangements, pre-contract assessment, contractual provisions, concentration risk assessment and exit strategies for critical or important functions.Platform supportOne inventory of ICT third parties and functions, criticality tagging, concentration analysis, contract and exit evidence on each record.
United KingdomPRA SS2/21; FCA SYSC 8ExpectsMateriality assessment, proportionate due diligence, oversight of sub-outsourcing, business continuity and stressed exit plans for material outsourcing.Platform supportMateriality captured at intake, tiered due diligence, fourth-party visibility and exit plans tracked against each material arrangement.
IndiaRBI Master Direction on Outsourcing of IT ServicesExpectsBoard-approved IT outsourcing policy, materiality assessment, due diligence, concentration risk monitoring, periodic review and exit strategy.Platform supportMateriality tiering, evidence-based due diligence, concentration and nth-party analysis, board decks and offboarding evidence.
SingaporeMAS Guidelines on Outsourcing; MAS Technology Risk Management GuidelinesExpectsAssessment of material outsourcing arrangements, service provider due diligence, ongoing monitoring, and business continuity and exit planning.Platform supportTiered assessments, monitoring of adverse news, breaches and enforcement actions, and exit evidence per arrangement.
Saudi Arabia and UAESAMA Cyber Security Framework and outsourcing requirements; CBUAE Outsourcing Regulation and StandardsExpectsThird-party cybersecurity requirements, outsourcing risk assessment, oversight of material outsourcing and regulator engagement.Platform supportCybersecurity control domains, tiered due diligence and a documented approval trail for each arrangement.
PhilippinesBSP outsourcing and IT risk management regulationsExpectsService provider due diligence, contract safeguards, ongoing oversight and continuity for BSP-supervised financial institutions.Platform supportStructured due diligence, findings and remediation tracking, and monitoring between assessments.
AustraliaAPRA CPS 230 and CPS 234ExpectsIdentification of material service providers and critical operations, a service provider management policy, and assessment of third parties’ information security capability.Platform supportMaterial service provider tagging, critical operation links, information security control domains and board-level reporting.

VendRisk360 is aligned to and maps to the regulations and standards named on this page. It does not certify compliance, and it is not legal advice. Your organization remains responsible for its own regulatory obligations and for confirming how they apply to it.

The same discipline, in your regulator’s words

  • Third-party risk management (TPRM)
  • Critical activities
  • ICT third-party risk
  • Register of information
  • Critical or important functions
  • Material outsourcing
  • Outsourcing register
  • Material service providers
  • Critical operations
  • Subcontracting and sub-outsourcing
  • Fourth and nth parties
  • Concentration risk
  • Exit strategy
  • Operational resilience
Built for bank teams

Structure for the whole three lines of defense

Business owners request and own vendors, the third-party risk team runs due diligence, and risk, compliance and internal audit review and challenge. Roles and sign-off stages keep those responsibilities separate and visible.

  • Custom roles for relationship owners, TPRM analysts, reviewers, second line and internal audit
  • Segregation of duties enforced at each sign-off stage
  • Vendor portal with one-time-code access, so vendors upload evidence without new accounts
  • Confirmed-only monitoring alerts for attack surface, shadow infrastructure, indicators of compromise, breaches, adverse news, sanctions and enforcement actions
  • SSO with SAML or OIDC, mandatory MFA and a full audit trail
Ways to work with us

Run it yourself, have us assess, or add a review

Run your program on the platform with your own analysts, or have VendRisk360 assess your vendors: you onboard the vendor and our certified assessors do the rest, while your bank keeps final approval of every risk decision. Add report-specific reviews for a single SOC, security or continuity report.

Vendor Lifecycle Management Platform

Run it on the platform

Your team manages its vendors, sends due diligence and evidence requests through the vendor portal, performs the review, records it and signs off. Every step is tracked with a full audit trail.

  • Intake, tiering, assessments and sign-off under your own policy
  • Monitoring signals and nth-party intelligence on the same record
  • Board decks, dashboards and examiner package export
Explore the platform
Comprehensive Vendor Risk Assessment Services

Have VendRisk360 assess your vendors

You onboard the vendor. Our certified assessors do the rest, and you see near real-time progress for every vendor on the platform and keep final approval.

  • Evidence collection and vendor follow-up
  • Assessment scaled to the vendor’s tier, with a second-expert quality review
  • Findings and remediation follow-up, with Continuous Monitoring Services available between assessments
  • Assessors holding CISSP, CISA, CISM, CRISC and ISO/IEC 27001 Lead Auditor and Lead Implementer, with PCI DSS implementation experience
Explore the assessment services
Report-Specific Reviews

Add report-specific reviews

Targeted expert reviews, each with a written review report for the vendor, available standalone or alongside the platform and services.

  • SOC Report Review, with optional AI assistance
  • Information Security Program Review
  • Business Continuity Program Review
Explore report-specific reviews
FAQ

Frequently asked questions

How does VendRisk360 align to the 2023 Interagency Guidance and OCC Bulletin 2023-17?

The platform follows the lifecycle the guidance describes: planning, due diligence and third-party selection, contract negotiation, ongoing monitoring and termination. Each vendor is tiered by criticality, so relationships that support critical activities receive deeper due diligence, more frequent review and senior sign-off, and the decisions, evidence and approvals are recorded in one audit trail your examiners can follow.

Can we identify which vendors support critical activities or critical or important functions?

Yes. Intake captures the business case, the services provided and the data involved, and criticality tiering records whether the relationship supports a critical activity (US), a critical or important function (DORA, EBA), a material outsourcing (PRA, RBI, MAS) or a material service provider (APRA CPS 230). The same record then drives assessment depth and cadence.

Does it support the DORA register of information?

VendRisk360 holds the vendor inventory, the functions each ICT third party supports, criticality, contracts, subcontractors and fourth parties in one place, which is the information the register of information draws on. Your team remains responsible for the final register submission to your competent authority in the required format.

How are concentration risk and fourth parties handled?

Nth-party intelligence maps the providers your vendors rely on, including subservice organizations named in SOC reports, and shows where critical services concentrate on the same cloud, processor or software provider. Blast-radius analysis shows which of your vendors and critical activities are affected when one of those providers has an incident.

What do we give examiners?

The examiner package export assembles the inventory, tiering rationale, assessments, findings, remediation and risk acceptances, sign-offs and monitoring history. The Audit committee and examiner readiness deck and the Regulator and examiner meeting deck summarize the program for the meeting itself, in PDF or editable PowerPoint.

We are a global group. Can one program cover several regulators?

Yes. Tiering and control domains are consistent across the group, and the regulatory vocabulary of each regime (material outsourcing, critical or important functions, material service providers) is captured on the vendor record, so one assessment can support obligations in several jurisdictions. Each legal entity remains responsible for its own regulatory compliance.

Get started

See VendRisk360 on your bank's critical vendors

A tailored walkthrough with a third-party risk specialist, built around your program, your regulators and your vendors.