Skip to content
Industries / Credit unions

Vendor and CUSO oversight at credit-union scale

Your core processor, digital-banking platform, card processor and CUSOs carry most of your operational risk. VendRisk360 gives a lean team a program NCUA examiners, your board and your supervisory committee can follow, without a department to run it.

Seen through your eyes

What vendor oversight looks like at a credit union

Credit unions depend on a small number of providers for almost everything members touch, and usually oversee them with one or two people alongside other duties.

Core and digital-banking dependence

A single core processor and a handful of digital-banking, card and payments providers run your member experience. Their SOC 1 reports and CUECs matter more than any questionnaire.

CUSOs are different

A CUSO may be a service provider you also invest in or lend to, shared with other credit unions. Oversight has to cover the service and the relationship.

Lean teams

Vendor management often sits with a compliance officer, the CISO or the CFO. The program has to be proportionate and efficient, not a second job.

Examiners look to your oversight

NCUA examiners assess vendor risk through the credit union’s own program, so your file has to show the risk assessment, the diligence and the monitoring.

Board and supervisory committee

Directors approve the program and the supervisory committee oversees audit. Both need a clear, current view of vendor risk and open issues.

Incidents at your providers

A breach or outage at a shared provider can reach many credit unions at once, and NCUA’s cyber incident notification rule includes incidents at third parties.

Core, digital banking and card processing

Read the SOC 1 once. Track the CUECs all year.

Your most critical providers deliver assurance through SOC reports. VendRisk360 analyzes each one for exceptions, carve-outs and subservice organizations, and lists the complementary user entity controls the report expects your credit union to operate.

  • Expert SOC Report Review available: report type and period, opinion, exceptions, carve-outs and bridge letters
  • CUECs mapped to your own controls, with gaps assigned an owner
  • Subservice organizations (data centers, clouds, print and mail) added to your fourth-party map
  • Audit period verified, so gaps in report coverage are visible
Proportionate by design

A program one or two people can run

Criticality tiering puts your time where the risk is and gives you a documented reason for everything else.

  1. 1

    One inventory

    Every vendor and CUSO in one directory, with the business owner, services, member data involved and contract dates.

  2. 2

    Tier by criticality

    Your policy sets the evidence, cadence and sign-off for each tier (for example, annual review for Critical vendors), and the platform enforces it, with the rationale recorded.

  3. 3

    Collect evidence easily

    Requests go out through the vendor portal, and vendors upload documents against each one with one-time-code access. Dates and expiry are tracked.

  4. 4

    Monitor in between

    Outside-in, confirmed-only alerts on breaches and incidents, attack surface, shadow infrastructure, adverse news, sanctions and enforcement actions, routed to the vendor owner.

Continuous monitoring

Know first when a shared provider has a problem

Signals are confirmed before they alert, so a small team is not buried in noise. When a provider used by many credit unions has an incident, you see which of your services depend on it.

Data breaches

Disclosed incidents and credential exposure linked to your vendors.

Attack surface

Exposed services and configuration posture on vendor domains.

Adverse news

Litigation, financial distress and leadership change.

Sanctions and enforcement

Regulatory actions, consent orders and sanctions listings.

Board and supervisory committee

Reporting your board will actually read

Generate the Board deck, Annual program review and Audit committee and examiner readiness deck from live data. Directors see exposure, trends and decisions needed. The supervisory committee sees the evidence behind every figure.

  • PDF and editable PowerPoint, ready for the board packet
  • Examiner package export for the NCUA examination
  • Custom read-only roles for supervisory committee members and internal auditors
  • Every sign-off, risk acceptance and change in one audit trail
See board and executive reporting
Regulatory alignment

Mapped to NCUA expectations

What NCUA and the standards credit unions benchmark against expect of your vendor program, and how the platform supports each. State-chartered credit unions should also consider their state regulator’s requirements.

Credit union vendor oversight requirements and platform support
NCUA12 CFR Part 748 and Appendix A (member information security)ExpectsDue diligence in selecting service providers, contracts requiring appropriate safeguards for member information, and monitoring of service providers.Platform supportData-type scoping at intake, security control domains in assessments, contract evidence on the record and continuous monitoring.
NCUALetter to Credit Unions 07-CU-13, Evaluating Third Party RelationshipsExpectsRisk assessment, due diligence, risk measurement, monitoring and control of third-party relationships, scaled to their complexity and risk.Platform supportCriticality tiering (Critical, Material, Low risk) driving assessment depth and cadence, with findings and remediation tracked to closure.
NCUA12 CFR Part 712, Credit Union Service OrganizationsExpectsCUSOs must meet reporting requirements, and credit unions that invest in or lend to CUSOs remain accountable for the risk.Platform supportOne record per CUSO with services, ownership context, financial evidence and assessment history.
NCUACyber incident notification (12 CFR 748.1(c))ExpectsNotify NCUA of reportable cyber incidents, including incidents at third parties that affect the credit union.Platform supportConfirmed-only breach and incident signals linked to your vendors, with blast radius across your services.
BenchmarkInteragency Guidance on Third-Party Relationships (2023); FFIEC IT Examination HandbookExpectsThe federal banking agencies’ lifecycle model and technology service provider oversight, widely used by credit unions as a benchmark.Platform supportLifecycle stages from intake to offboarding, SOC report analysis and BCP and DR evidence review.
AssuranceSOC 1 and SOC 2 reportsExpectsReview of your core and digital-banking providers’ reports, including exceptions, subservice organizations and the complementary user entity controls you must operate.Platform supportSOC report review on the platform or as an expert SOC Report Review, and CUEC tracking mapped to your own controls.

VendRisk360 is aligned to and maps to the regulations and standards named on this page. It does not certify compliance, and it is not legal advice. Your organization remains responsible for its own regulatory obligations and for confirming how they apply to it.

  • Vendor management
  • Third-party relationships
  • CUSOs
  • Core processor
  • Digital banking provider
  • Card processor
  • Member information
  • Complementary user entity controls (CUECs)
  • Subservice organizations
  • Supervisory committee
  • Examiner readiness
Security

Built for member data

Your vendor files contain your providers’ security details and your own control gaps. VendRisk360 protects them accordingly.

  • SSO with SAML or OIDC and mandatory MFA
  • Tenant isolation enforced by database row-level security
  • Encryption in transit and at rest, enterprise cloud hosting
  • Custom roles and a full audit trail of every action
Ways to work with us

No vendor management team? We can run it with you.

Many credit unions oversee dozens of vendors with one person. Run the program yourself on the platform, or have VendRisk360 assess your vendors: you onboard the vendor, and our certified assessors collect evidence, follow up with vendors, run the assessments and track remediation, while your credit union keeps final approval. Add report-specific reviews whenever you need an expert opinion on one report.

Vendor Lifecycle Management Platform

Run it on the platform

Your team manages its vendors, sends due diligence and evidence requests through the vendor portal, performs the review, records it and signs off. Every step is tracked with a full audit trail.

  • Intake, tiering, assessments and sign-off under your own policy
  • Monitoring signals and nth-party intelligence on the same record
  • Board decks, dashboards and examiner package export
Explore the platform
Comprehensive Vendor Risk Assessment Services

Have VendRisk360 assess your vendors

You onboard the vendor. Our certified assessors do the rest, and you see near real-time progress for every vendor on the platform and keep final approval.

  • Evidence collection and vendor follow-up
  • Assessment scaled to the vendor’s tier, with a second-expert quality review
  • Findings and remediation follow-up, with Continuous Monitoring Services available between assessments
  • Assessors holding CISSP, CISA, CISM, CRISC and ISO/IEC 27001 Lead Auditor and Lead Implementer, with PCI DSS implementation experience
Explore the assessment services
Report-Specific Reviews

Add report-specific reviews

Targeted expert reviews, each with a written review report for the vendor, available standalone or alongside the platform and services.

  • SOC Report Review, with optional AI assistance
  • Information Security Program Review
  • Business Continuity Program Review
Explore report-specific reviews
FAQ

Frequently asked questions

Is VendRisk360 sized for a credit union with a small risk team?

Yes. Criticality tiering keeps full assessments for the handful of vendors that matter most (typically the core processor, digital banking, card processing and key CUSOs), while Low-risk vendors get a streamlined review, on the cadence your own policy sets. The platform tracks every request, review and sign-off, and a VendRisk360 SOC Report Review can take the heaviest reports off your desk, so one or two people can run a defensible program. A named reviewer approves every conclusion.

Can VendRisk360 run our vendor management program for us?

Yes. With Comprehensive Vendor Risk Assessment Services, your credit union onboards its vendors and VendRisk360’s certified assessors do the rest: evidence collection and vendor follow-up, completeness and validity checks, the risk assessments with a second-expert quality review, findings and remediation follow-up and reassessments on your cadence. Continuous Monitoring Services can be added between assessments. Progress for every vendor is visible in near real time on the platform, ready for your board and examiners. Final approval and risk acceptance stay with your credit union.

How does it help with CUSOs?

A CUSO is both a service provider and, often, an entity the credit union invests in or lends to. VendRisk360 records the relationship on one vendor record with the services provided, the member data involved and the financial and operational evidence you collect, and tiers it like any other third party so oversight matches the risk.

What do NCUA examiners typically want to see?

Examiners look for a risk assessment of each relationship, due diligence proportionate to that risk, contract safeguards, ongoing monitoring and reporting to the board. VendRisk360 keeps all of that on the vendor record with an audit trail, and the examiner package export assembles it into one file.

Does it help with the NCUA cyber incident notification rule?

The rule requires a federally insured credit union to notify NCUA of a reportable cyber incident, including one at a third party that affects it. Continuous monitoring surfaces confirmed breach and incident signals linked to your vendors, and blast-radius analysis shows which services are affected, so your team can make the notification decision quickly. The decision and the notification remain yours.

Can we report to the board and the supervisory committee from the platform?

Yes. The Board deck, the Annual program review deck and the Audit committee and examiner readiness deck are generated from live data and export to PDF or editable PowerPoint. Supervisory committees can review the same evidence, sign-offs and findings through a read-only role.

Get started

See VendRisk360 on your credit union’s vendors

A tailored walkthrough with a third-party risk specialist, built around your program, your regulators and your vendors.