Third-party risk management your examiners can follow
For banks and banking groups answering to the OCC, FDIC, Federal Reserve, OSFI, the ECB and national authorities, the PRA, RBI, MAS, APRA and Gulf regulators. One record per third party, depth scaled to critical activities, and evidence your board and examiners can trace.
The questions your program has to answer
Heads of third-party risk at banks tell us the hard part is not collecting questionnaires. It is proving to a board, an audit committee and an examiner that oversight is proportionate, current and complete.
Show me the evidence
Examiners test the file, not the policy. Every tiering decision, finding, exception and sign-off needs to be traceable to the document behind it.
Critical activities get more
Relationships that support critical activities, critical or important functions or material outsourcing need deeper diligence, tighter contracts and more frequent review.
Concentration you cannot see
Several of your critical vendors may depend on the same cloud region, core processor or card network. That risk sits in fourth parties, not in your contract list.
Exit plans that would work
Regulators increasingly expect documented, and for the most critical services tested, exit strategies. A paragraph in a policy is no longer enough.
The board owns the risk
Directors need to see where the bank is exposed, what changed and what decisions they are being asked to make, in a format they can read in ten minutes.
Many regulators, one program
Global groups answer to regimes with different vocabulary and registers. The program has to satisfy each without running five parallel processes.
The third-party lifecycle, as your regulators describe it
The 2023 interagency guidance, OSFI B-10, DORA and the EBA guidelines all describe the same arc. VendRisk360 structures each vendor record around it, so the program reads the way examiners expect.
- 1
Planning
Intake captures the business case, the service, the data types involved and whether the relationship supports a critical activity.
- 2
Due diligence
Criticality sets the scope under your policy: typically a full artifact-based assessment for Critical vendors, a focused one for Material and a streamlined review for Low risk.
- 3
Contracting
Contract evidence, SLAs and required provisions (audit rights, subcontracting, termination) are held on the vendor record.
- 4
Ongoing monitoring
Reassessment runs on the cadence your policy sets for each tier (for example, annually for Critical vendors), with continuous monitoring in between.
- 5
Termination and exit
Offboarding records data return or destruction, access removal and exit evidence, closing the loop for the examiner.
Artifact-based assessments, not self-attestation
For vendors that support critical activities, controls are assessed on evidence across 30+ control domains: a point-in-time, inside-out review your analysts perform, record and sign off on the platform, or that VendRisk360 assessors perform for you through Comprehensive Vendor Risk Assessment Services. Continuous monitoring adds the outside-in view between reviews.
- SOC 1 and SOC 2 review: exceptions, carve-outs, subservice organizations and CUECs, in-house or as an expert SOC Report Review
- Penetration tests, BCP and DR test results, financial condition and insurance
- Findings, remediation plans and risk acceptance with expiry dates
- Multi-stage sign-off with segregation of duties between analyst, reviewer and risk owner
Know which critical activities share a single point of failure
Nth-party intelligence maps the providers behind your providers: the clouds, processors, data centers and software your vendors rely on. It shows concentration across your critical activities and the blast radius when one of them fails.
- Fourth parties and subservice organizations drawn from SOC reports and vendor disclosures
- Concentration by provider, service and region, across Critical and Material vendors
- CUEC tracking: controls your vendors expect the bank to operate, mapped to your own
- Evidence for DORA concentration assessments, RBI concentration monitoring and board reporting
Board packs and examiner files from the same live data
Nine ready-made decks, including the Board report, Audit committee and examiner readiness, Concentration risk, Incident and breach briefing and the Regulator and examiner meeting deck. Each is generated from live vendor records and exports to PDF or editable PowerPoint.
- Examiner package export: inventory, tiering rationale, assessments, findings, sign-offs and monitoring history
- Executive dashboards: heat map, trends, program health and decisions needed
- Every figure traceable to the vendor record behind it
Exit strategies you can defend
DORA, the EBA guidelines, PRA SS2/21, OSFI B-10, RBI and APRA CPS 230 all expect you to plan for a critical provider failing or being replaced. VendRisk360 keeps that plan on the vendor record and keeps it current.
Stressed and orderly exit
Exit approach, alternative providers and transition timelines recorded for each critical arrangement.
Critical operations link
Which critical activity or operation depends on the vendor, recorded at intake and kept with the record.
Testing evidence
When the plan was last reviewed or tested, by whom, and what changed.
Offboarding evidence
Data return or destruction, access removal and final sign-off when a relationship ends.
Mapped to the regimes banks answer to
What each regime expects of a bank's third-party program, and how the platform supports it. Wording differs by jurisdiction; the underlying discipline is consistent.
| Regime | What it expects of your third-party program | How VendRisk360 supports it |
|---|---|---|
| United StatesInteragency Guidance on Third-Party Relationships (2023); OCC Bulletin 2023-17, FDIC FIL-29-2023, Federal Reserve SR 23-4 | ExpectsRisk-based oversight across the full lifecycle, with more comprehensive oversight for relationships that support critical activities, and board accountability for the program. | Platform supportLifecycle stages, criticality tiering, depth and cadence by tier, board reporting, and an audit trail of every decision. |
| United StatesFFIEC IT Examination Handbook | ExpectsOversight of technology service providers, including due diligence, contract provisions, business continuity and review of assurance reports. | Platform supportArtifact-based assessments across 30+ control domains, SOC report analysis and BCP and DR evidence review. |
| United StatesNYDFS 23 NYCRR 500.11 | ExpectsWritten third-party service provider security policies: identification, risk assessment, minimum cybersecurity practices, due diligence and periodic assessment. | Platform supportPolicy-driven intake and tiering, cybersecurity control domains, periodic reassessment and monitoring of vendor attack surface and breaches. |
| CanadaOSFI Guideline B-10, Third-Party Risk Management | ExpectsA third-party risk management framework, risk assessment before and during arrangements, subcontracting oversight, and plans for exit and disruption. | Platform supportRisk-scoped intake, nth-party mapping of subcontractors, continuous monitoring and exit evidence at offboarding. |
| European UnionDORA, Regulation (EU) 2022/2554; EBA Guidelines on outsourcing arrangements | ExpectsA register of information for ICT third-party arrangements, pre-contract assessment, contractual provisions, concentration risk assessment and exit strategies for critical or important functions. | Platform supportOne inventory of ICT third parties and functions, criticality tagging, concentration analysis, contract and exit evidence on each record. |
| United KingdomPRA SS2/21; FCA SYSC 8 | ExpectsMateriality assessment, proportionate due diligence, oversight of sub-outsourcing, business continuity and stressed exit plans for material outsourcing. | Platform supportMateriality captured at intake, tiered due diligence, fourth-party visibility and exit plans tracked against each material arrangement. |
| IndiaRBI Master Direction on Outsourcing of IT Services | ExpectsBoard-approved IT outsourcing policy, materiality assessment, due diligence, concentration risk monitoring, periodic review and exit strategy. | Platform supportMateriality tiering, evidence-based due diligence, concentration and nth-party analysis, board decks and offboarding evidence. |
| SingaporeMAS Guidelines on Outsourcing; MAS Technology Risk Management Guidelines | ExpectsAssessment of material outsourcing arrangements, service provider due diligence, ongoing monitoring, and business continuity and exit planning. | Platform supportTiered assessments, monitoring of adverse news, breaches and enforcement actions, and exit evidence per arrangement. |
| Saudi Arabia and UAESAMA Cyber Security Framework and outsourcing requirements; CBUAE Outsourcing Regulation and Standards | ExpectsThird-party cybersecurity requirements, outsourcing risk assessment, oversight of material outsourcing and regulator engagement. | Platform supportCybersecurity control domains, tiered due diligence and a documented approval trail for each arrangement. |
| PhilippinesBSP outsourcing and IT risk management regulations | ExpectsService provider due diligence, contract safeguards, ongoing oversight and continuity for BSP-supervised financial institutions. | Platform supportStructured due diligence, findings and remediation tracking, and monitoring between assessments. |
| AustraliaAPRA CPS 230 and CPS 234 | ExpectsIdentification of material service providers and critical operations, a service provider management policy, and assessment of third parties’ information security capability. | Platform supportMaterial service provider tagging, critical operation links, information security control domains and board-level reporting. |
VendRisk360 is aligned to and maps to the regulations and standards named on this page. It does not certify compliance, and it is not legal advice. Your organization remains responsible for its own regulatory obligations and for confirming how they apply to it.
The same discipline, in your regulator’s words
- Third-party risk management (TPRM)
- Critical activities
- ICT third-party risk
- Register of information
- Critical or important functions
- Material outsourcing
- Outsourcing register
- Material service providers
- Critical operations
- Subcontracting and sub-outsourcing
- Fourth and nth parties
- Concentration risk
- Exit strategy
- Operational resilience
Structure for the whole three lines of defense
Business owners request and own vendors, the third-party risk team runs due diligence, and risk, compliance and internal audit review and challenge. Roles and sign-off stages keep those responsibilities separate and visible.
- Custom roles for relationship owners, TPRM analysts, reviewers, second line and internal audit
- Segregation of duties enforced at each sign-off stage
- Vendor portal with one-time-code access, so vendors upload evidence without new accounts
- Confirmed-only monitoring alerts for attack surface, shadow infrastructure, indicators of compromise, breaches, adverse news, sanctions and enforcement actions
- SSO with SAML or OIDC, mandatory MFA and a full audit trail
Run it yourself, have us assess, or add a review
Run your program on the platform with your own analysts, or have VendRisk360 assess your vendors: you onboard the vendor and our certified assessors do the rest, while your bank keeps final approval of every risk decision. Add report-specific reviews for a single SOC, security or continuity report.
Run it on the platform
Your team manages its vendors, sends due diligence and evidence requests through the vendor portal, performs the review, records it and signs off. Every step is tracked with a full audit trail.
- Intake, tiering, assessments and sign-off under your own policy
- Monitoring signals and nth-party intelligence on the same record
- Board decks, dashboards and examiner package export
Have VendRisk360 assess your vendors
You onboard the vendor. Our certified assessors do the rest, and you see near real-time progress for every vendor on the platform and keep final approval.
- Evidence collection and vendor follow-up
- Assessment scaled to the vendor’s tier, with a second-expert quality review
- Findings and remediation follow-up, with Continuous Monitoring Services available between assessments
- Assessors holding CISSP, CISA, CISM, CRISC and ISO/IEC 27001 Lead Auditor and Lead Implementer, with PCI DSS implementation experience
Add report-specific reviews
Targeted expert reviews, each with a written review report for the vendor, available standalone or alongside the platform and services.
- SOC Report Review, with optional AI assistance
- Information Security Program Review
- Business Continuity Program Review
Frequently asked questions
How does VendRisk360 align to the 2023 Interagency Guidance and OCC Bulletin 2023-17?
The platform follows the lifecycle the guidance describes: planning, due diligence and third-party selection, contract negotiation, ongoing monitoring and termination. Each vendor is tiered by criticality, so relationships that support critical activities receive deeper due diligence, more frequent review and senior sign-off, and the decisions, evidence and approvals are recorded in one audit trail your examiners can follow.
Can we identify which vendors support critical activities or critical or important functions?
Yes. Intake captures the business case, the services provided and the data involved, and criticality tiering records whether the relationship supports a critical activity (US), a critical or important function (DORA, EBA), a material outsourcing (PRA, RBI, MAS) or a material service provider (APRA CPS 230). The same record then drives assessment depth and cadence.
Does it support the DORA register of information?
VendRisk360 holds the vendor inventory, the functions each ICT third party supports, criticality, contracts, subcontractors and fourth parties in one place, which is the information the register of information draws on. Your team remains responsible for the final register submission to your competent authority in the required format.
How are concentration risk and fourth parties handled?
Nth-party intelligence maps the providers your vendors rely on, including subservice organizations named in SOC reports, and shows where critical services concentrate on the same cloud, processor or software provider. Blast-radius analysis shows which of your vendors and critical activities are affected when one of those providers has an incident.
What do we give examiners?
The examiner package export assembles the inventory, tiering rationale, assessments, findings, remediation and risk acceptances, sign-offs and monitoring history. The Audit committee and examiner readiness deck and the Regulator and examiner meeting deck summarize the program for the meeting itself, in PDF or editable PowerPoint.
We are a global group. Can one program cover several regulators?
Yes. Tiering and control domains are consistent across the group, and the regulatory vocabulary of each regime (material outsourcing, critical or important functions, material service providers) is captured on the vendor record, so one assessment can support obligations in several jurisdictions. Each legal entity remains responsible for its own regulatory compliance.
See VendRisk360 on your bank's critical vendors
A tailored walkthrough with a third-party risk specialist, built around your program, your regulators and your vendors.