A mid-sized credit union can easily depend on a core banking processor, a cloud host, a digital-banking vendor, a card network, a collections agency, and several hundred smaller suppliers. Each one performs work the institution is still accountable for.

Third party vendor management is the operating discipline that turns your list of suppliers into a set of relationships you can see, rank, and control. However, outsourcing the work never outsources the responsibility.

The sections that follow work through the vendor lifecycle stage by stage. It follows the third-party relationship life cycle the federal banking agencies use, so the vendor risk management program you build lines up with what your examiners expect.

This article stays on the vendors themselves and how you run them across their lifecycle. See our companion piece on building a third-party risk management program for a different approach.

Organizations are building up third party vendor management.

The Vendor Management Lifecycle Under the 2023 Interagency Guidance

The anchor document for US banks is the Interagency Guidance on Third-Party Relationships: Risk Management, issued by the Federal Reserve, FDIC, and OCC. It organised risk management around five lifecycle stages:

  1. Planning
  2. Due diligence and third-party selection
  3. Contract negotiation
  4. Ongoing monitoring
  5. Termination

These are the same stages that structure any TPRM program, applied here to the vendor population specifically. Two principles from the guidance shape the whole lifecycle:

  • Risk-based proportionality
  • Coverage across every stage

The table below maps each vendor lifecycle stage to its objective, the main activities, the function that usually owns it, and a typical review cadence.

Lifecycle StageObjectiveKey ActivitiesReview Cadence
PlanningDecide whether and how to engageAssess the activity, confirm strategic fit, identify exit optionsPer engagement
Due diligence & selectionConfirm the vendor can perform safelyFinancial, security, compliance, and resilience review scoped by tierBefore contracting
Contract negotiationLock obligations into enforceable termsPerformance measures, audit rights, breach notice, termination provisionsAt signing and renewal
Ongoing monitoringDetect deterioration before it disrupts serviceKRI and SLA tracking, reassessment, issue managementQuarterly to annual by tier
TerminationExit without disruption or data lossTransition planning, data return and destruction, access revocationPer exit

The community-bank companion resource the agencies released in May 2024 adds a governance chapter to those five stages, acknowledging that smaller institutions need proportionate paths to the same outcomes.

Planning and Vendor Risk Tiering

The programme starts with a complete vendor inventory. That means every supplier, including the ones a business line signed up without telling procurement.

With the inventory in hand, assess each vendor and assign it a tier. Tiering rests on inherent risk, the risk a relationship carries before any controls are applied. Ask what data the vendor touches, whether it faces customers, and whether its failure would interrupt a critical operation. Residual risk then guides ongoing decisions.

Most vendor risk management programs settle on three or four tiers, reserving the top tier for critical vendors whose failure could cause major customer impact or safety-and-soundness concerns.

Due Diligence and Contracting

For a critical vendor, the guidance points to a broad review covering financial condition, information-security practices, business continuity and resilience, compliance management, reliance on subcontractors, and operational capacity.

SOC 2 reports, audited financials, penetration-test summaries, business-continuity test results, and complaint histories belong in the vendor file. When a vendor cannot or will not provide something, record the gap, weigh it, and decide.The 2023 guidance lists provisions to address:

  • Performance measures
  • Audit and information-access rights
  • Data security and breach notification
  • Business-continuity obligations
  • Limits on subcontracting
  • Termination rights

If a critical vendor depends on its own critical subcontractors, those fourth parties belong in your risk picture too.

Ongoing Monitoring and Vendor Performance

The static annual questionnaire is giving way to a continuous view that tracks financial health, security ratings, adverse news, regulatory actions, and performance against service-level agreements on a cadence matched to the tier. Critical vendors warrant quarterly or continuous review.

Vendor management differs from pure risk monitoring in that it also watches performance. Many institutions consolidate this work in a vendor risk management platform so assessments, documents, and performance data live in one system.

Tie monitoring outputs to an issue-management process with severity ratings, named owners, deadlines, and escalation, and report aging issues on critical vendors to the board risk committee.

Termination and Offboarding

Whether a contract ends by plan, by default, or because a vendor's risk profile deteriorated, the exit needs to protect the institution and its customers. Plan the transition before you need it, especially for critical vendors.Offboarding has a short, non-negotiable checklist:

  • Return or destroy institution and customer data,
  • Revoke system and facility access
  • Confirm any subcontractors do the same
  • Settle final obligations

Be sure to map concentration as it deserves attention. If several critical activities run through a single provider, or through several providers sitting on the same underlying infrastructure, the institution's exit options narrow.

Governance and Building the VRM Programme

A vendor risk management program earns credibility through governance and measurement. The common structure follows three lines:

  • Relationship owners in the business who run the vendors day to day
  • A vendor-risk function that sets standards and challenges the assessments
  • Internal audit testing whether the programme works as written

Board reporting should cover the critical-vendor population, concentration, material issues, and a few program-health metrics.

Keep the metrics small and pointed to include the share of vendors tiered, due-diligence currency for critical vendors, monitoring tasks completed on time, open issues by severity and age, and time to offboard.

Compliance evidence runs through all of it, and the sibling guide to third-party vendor compliance covers how to document that evidence for examiners.

Platforms such as Predict360 provide a centralized third-party data repository, configurable onboarding and due-diligence checklists, vendor risk categorization, and reporting embedded in the same system.

Frequently Asked Questions

What is the difference between vendor management and third-party risk management?

Vendor management covers contracted suppliers and service providers. Third-party risk management includes vendors plus fintech partnerships, referral arrangements, joint ventures, and other business relationships that may not involve a purchase contract.

Which regulation governs third-party vendor management for banks?

For US banks, the primary reference is the Interagency Guidance on Third-Party Relationships: Risk Management, issued by the Federal Reserve, FDIC, and OCC. It applies a risk-based, lifecycle approach to all banking organizations and replaced the agencies' earlier separate guidance. A May 2024 companion guide gives community banks proportionate implementation direction. The FFIEC IT Examination Handbook also informs vendor oversight expectations.

What belongs in a vendor management program policy?

A vendor management program policy should define what counts as a vendor, the tiering methodology, due-diligence requirements by tier, contract standards, monitoring cadence, escalation paths, and roles across the three lines. Keep the policy short enough that business lines follow it, and push procedural detail into standards documents beneath it.

Read your current vendor inventory against the five stages and mark where the programme goes quiet. From there, extending the work into enterprise governance and the right supporting tooling is what moves a vendor list toward a working programme.

Streamline Risk Management

The Predict360 Enterprise Risk Management Software ensures managers have complete visibility of enterprise risk on a single dashboard.

Request Demo
  • Cloud-Based
  • Risk Repository
  • Assess Risks
  • Real-time Monitoring