FFIEC Vendor Management Due Diligence Checklist for Banks

A vendor management due diligence checklist for banks under FFIEC and interagency expectations works through a defined sequence: classify the vendor by risk, gather documentation, evaluate financial condition and ownership, test information security, verify business continuity capacity, confirm legal and regulatory compliance, lock the right provisions into the contract, account for subcontractors, and set up ongoing monitoring and an exit path before the relationship starts. The 2023 Interagency Guidance on Third-Party Relationships, issued jointly by the OCC, Federal Reserve, and FDIC, is the framework examiners use to judge whether that process is adequate.1Federal Register. Interagency Guidance on Third-Party Relationships: Risk Management Federal banking agencies also hold statutory authority under 12 U.S.C. ยง 1867 to examine a third-party service provider as if the services were performed by the bank itself, so the checklist protects both the institution and its vendor from regulatory exposure.2Office of the Law Revision Counsel. 12 USC 1867 – Regulation and Examination of Bank Service Companies

Start by Tiering the Vendor

Not every vendor gets the same treatment. The interagency guidance says the depth of due diligence should be proportional to the risk and complexity of the relationship, with the most comprehensive review reserved for vendors supporting critical activities.1Federal Register. Interagency Guidance on Third-Party Relationships: Risk Management Critical activities are those where a vendor failure could cause significant risk to the institution, meaningfully harm customers, or materially affect financial condition or operations.3Office of the Comptroller of the Currency. Third-Party Risk Management: A Guide for Community Banks

Factors pushing a vendor into the critical tier include access to sensitive customer data, transaction processing responsibilities, and delivery of essential technology services. Assign every prospective vendor to a risk tier before detailed evaluation begins, because that classification decides how many of the items below you need to dig into and how deep to go on each.

Documents to Collect Before You Analyze Anything

Gathering the paperwork upfront avoids the back-and-forth that stretches vetting for weeks. For publicly traded vendors, SEC filings supply audited financials and material disclosures. For private companies, request the documents directly. A working intake list:

  • Audited financial statements, annual reports, and any SEC filings. The FFIEC IT Examination Handbook expects institutions to receive audited financials from critical vendors at least annually.4Federal Financial Institutions Examination Council. FFIEC Information Technology Examination Handbook – Management Booklet
  • SOC 1 Type II reports on controls over financial reporting, and SOC 2 Type II reports on security, availability, processing integrity, confidentiality, and privacy. These are industry-standard audit reports rather than a regulatory mandate, but examiners routinely expect them for critical vendors, and the interagency guidance identifies them as examples of audit reports institutions should obtain contractually.5Federal Reserve System. Interagency Guidance on Third-Party Relationships: Risk Management
  • Insurance certificates for professional liability and cyber liability, including whether coverage extends to incidents caused by the vendor’s own subcontractors.
  • Business continuity and disaster recovery plans, with documented recovery objectives and testing results.
  • Corporate organizational documents: articles of incorporation, ownership structure, and executive leadership.
  • Compliance documentation: licenses, regulatory examination results, and any history of enforcement actions or litigation.

Keep these in a centralized repository so each checklist item traces to a specific document. Examiners will evaluate whether you can produce evidence supporting your risk assessments, not just the assessments themselves.

Financial Condition and Governance

A vendor that can’t stay solvent can’t deliver services. The interagency guidance directs institutions to review available financial information to determine whether the third party has the financial capability and stability to perform the activity.1Federal Register. Interagency Guidance on Third-Party Relationships: Risk Management In practice, look at balance sheet metrics like current ratios and debt levels, track profitability trends over multiple years, and flag signs that the vendor is burning cash or carrying unsustainable obligations.

Governance evaluation is the other side of the same page. The guidance calls for evaluating the qualifications and experience of a third party’s principals and key personnel.1Federal Register. Interagency Guidance on Third-Party Relationships: Risk Management Document the ownership structure, identify beneficial owners, assess the depth of executive management, and look at whether independent board oversight or audit committees exist.

Beneficial Ownership

For private vendors that are legal entity customers of your institution, FinCEN’s Customer Due Diligence Rule requires collecting beneficial ownership information. Under 31 CFR 1010.230, identify any individual who directly or indirectly owns 25 percent or more of the entity’s equity interests, plus a single individual with significant management control.6FinCEN. CDD Rule FAQs For each beneficial owner, collect name, date of birth, address, and an identification number such as a Social Security number. Even where the CDD Rule doesn’t technically apply, the interagency guidance separately calls for evaluating the vendor’s ownership structure, including beneficial ownership and whether the entity has foreign or domestic ownership.1Federal Register. Interagency Guidance on Third-Party Relationships: Risk Management

Information Security and Technical Controls

This is where vendor due diligence failures cause the most damage. A vendor with access to customer data or a network connection can become the entry point for a breach that regulators and customers hold you responsible for.

Encryption first. The vendor should protect sensitive information both in transit and at rest, using current standards appropriate to the data and threat environment.7Federal Financial Institutions Examination Council. FFIEC Information Technology Examination Handbook – Information Security Ask specifically what algorithms and key lengths are in use, and whether encrypted data and encryption keys are stored separately.

Access controls next. The vendor should apply the principle of least privilege, meaning users get only the minimum level of access necessary for their job functions.7Federal Financial Institutions Examination Council. FFIEC Information Technology Examination Handbook – Information Security Ask for access control policies, evidence of periodic access reviews, and the process for revoking access when employees leave or change roles.

Beyond those fundamentals, verify that the vendor conducts regular independent penetration testing, review the results and remediation timelines, and document physical security at data centers.

Using the NIST Cybersecurity Framework as a Reference

Many institutions use the NIST Cybersecurity Framework 2.0 as a common vocabulary when evaluating vendor security posture. The framework provides tiers for cybersecurity risk governance and a structure for creating current and target organizational profiles, letting institutions compare where a vendor stands against where it needs to be.8National Institute of Standards and Technology. The NIST Cybersecurity Framework (CSF) 2.0 The CSF is sector-neutral and doesn’t prescribe specific outcomes, but asking vendors to self-assess against its categories produces more structured, comparable responses than open-ended questionnaires.

Business Continuity and Recovery Objectives

A vendor’s continuity plan should include two numbers that drive the whole conversation. The Recovery Time Objective defines the maximum time a system can remain unavailable before there is an unacceptable impact on operations. The Recovery Point Objective defines how far back in time data must be restored to resume normal business functions, expressed in minutes, hours, or days from the point of disruption.9Federal Financial Institutions Examination Council. FFIEC Information Technology Examination Handbook – Business Continuity Management

Capture both objectives, compare them against your institution’s own tolerance thresholds, and flag any gaps. A vendor with a 48-hour RTO partnered with a bank that needs core processing restored within four hours is a mismatch no amount of good intentions can fix. The FFIEC expects outsourcing contracts to clearly address both RTOs and RPOs.10Federal Financial Institutions Examination Council. Business Continuity Planning Booklet Appendix J – Strengthening the Resilience of Outsourced Technology Services Beyond the stated objectives, confirm the vendor actually tests its recovery plans, review the most recent results, and verify geographic redundancy for critical systems.

Legal and Regulatory Compliance

Compliance due diligence does two jobs: it confirms the vendor won’t drag your institution into regulatory trouble, and it verifies the vendor can help you meet your own obligations. The interagency guidance directs institutions to evaluate the vendor’s ownership structure for sanctions exposure, confirm that necessary licenses and legal authority exist, and determine whether the vendor has the processes and controls to keep the institution in compliance.1Federal Register. Interagency Guidance on Third-Party Relationships: Risk Management Your checklist should cover:

  • Litigation and enforcement history: pending lawsuits, regulatory actions, consent orders, or fines. An active federal enforcement action needs senior-management-level evaluation.
  • OFAC screening: verify that neither the vendor nor its owners appear on Office of Foreign Assets Control sanctions lists.
  • Data privacy under GLBA. The FTC’s Safeguards Rule requires contracts that spell out security expectations, build in ways to monitor the vendor’s work, and provide for periodic reassessments.11Federal Trade Commission. FTC Safeguards Rule: What Your Business Needs to Know
  • Consumer protection: if the vendor interacts with your customers or handles consumer-facing processes, evaluate whether it has identified and mitigated areas of potential consumer harm.
  • Breach notification: state notification deadlines range from roughly 10 to 30 days depending on jurisdiction. Verify the vendor can meet the fastest applicable deadline.

Contract Provisions Examiners Look For

The contract is itself a risk management tool, and examiners read it closely. The interagency guidance identifies provisions that well-managed institutions address in their vendor contracts.5Federal Reserve System. Interagency Guidance on Third-Party Relationships: Risk Management

  • Performance standards with measurable service-level agreements defining adequate performance and the consequences of falling short.
  • Right to audit for the institution and its regulators, access to relevant records, remediation of identified deficiencies, and a description of the types and frequency of audit reports the institution is entitled to receive, such as SOC reports or PCI compliance reports.5Federal Reserve System. Interagency Guidance on Third-Party Relationships: Risk Management
  • Data ownership: clear statements about who owns data generated during the relationship and the extent to which the vendor can use your institution’s information or intellectual property.
  • Subcontracting restrictions: notification before using subcontractors, ability to prohibit specific subcontractors, and no assignment or transfer of the vendor’s obligations without your consent.5Federal Reserve System. Interagency Guidance on Third-Party Relationships: Risk Management
  • Default and termination: define what constitutes a default, allow opportunities to cure, and establish termination conditions with notice periods that permit an orderly transition.
  • Dispute resolution: a process for resolving disagreements without interrupting services during the dispute.

Without predefined termination provisions, an institution needing to exit may face the choice of negotiating a costly early cancellation or continuing with a vendor that isn’t meeting expectations. Building the exit path into the contract at the start eliminates that leverage problem.

Subcontractor and Fourth-Party Exposure

Your vendor’s vendors are your problem, even though you have no direct contractual relationship with them. Regulators don’t expect you to independently manage every subcontractor in a vendor’s supply chain, but they do expect you to make sure your vendors are managing their own third-party risk. The interagency guidance includes a vendor’s reliance on, exposure to, and use of subcontractors as a factor institutions should monitor on an ongoing basis.1Federal Register. Interagency Guidance on Third-Party Relationships: Risk Management

Address this two ways. During initial due diligence, ask the vendor to identify any subcontractors involved in delivering the services, especially those with access to your data or your customers’ data. In the contract, require notification before outsourcing critical functions and before changing critical subcontractors. The practical question to hold in mind: what happens to your institution if this vendor loses a key subcontractor?

AI and Emerging Technology Vendors

Vendors providing AI-powered tools or automated decision-making systems introduce risks that traditional checklists weren’t built to catch. The FS-ISAC’s Generative AI Vendor Risk Assessment Guide, designed to supplement existing third-party risk management programs in alignment with the 2023 interagency guidance, identifies several categories unique to AI vendor evaluation.12FS-ISAC. Generative AI Vendor Risk Assessment Guide

For AI vendors, add questions about how models are trained, validated, and maintained over time. Ask about data privacy and retention, particularly whether customer data is used in model training. Evaluate integration with your existing technology stack and whether the vendor relies on its own subcontractors for AI infrastructure. Because AI solutions evolve rapidly, standardized questionnaires may not keep pace with the risks. The FS-ISAC framework recommends tiered assessment plans based on an initial risk analysis, with the depth of the questionnaire scaling to reflect the use case, the sensitivity of data, and the potential for customer-facing exposure.12FS-ISAC. Generative AI Vendor Risk Assessment Guide

Board and Senior Management Oversight

The board of directors carries ultimate responsibility for overseeing third-party risk management. The interagency guidance is direct: the board provides guidance on acceptable risk appetite, approves policies, and holds management accountable for execution.1Federal Register. Interagency Guidance on Third-Party Relationships: Risk Management Management directs due diligence, ensures contracts are properly reviewed and approved, escalates significant issues to the board, and terminates relationships no longer aligned with the institution’s strategy.

Your checklist should include a governance layer. After the financial, security, and legal assessments are complete, assign a final risk rating based on the institution’s internal risk appetite. For critical vendors, formal sign-off by senior management or the board should precede the start of the relationship. The board or a designated committee should periodically review whether existing vendor relationships still align with strategic goals and risk profile, and whether management has remediated any significant monitoring findings.1Federal Register. Interagency Guidance on Third-Party Relationships: Risk Management

Ongoing Monitoring After Onboarding

Due diligence is not a one-time event. The interagency guidance requires ongoing monitoring throughout the life of every relationship, with more frequent and comprehensive review for vendors supporting critical activities.1Federal Register. Interagency Guidance on Third-Party Relationships: Risk Management Typical activities include reviewing vendor performance reports and control effectiveness, holding periodic meetings with vendor representatives, and testing your own internal controls for managing the relationship.

Track changes in the vendor’s financial condition, lapses in insurance coverage, shifts in key personnel, new subcontractor arrangements, and the vendor’s response to emerging threats or security incidents.1Federal Register. Interagency Guidance on Third-Party Relationships: Risk Management Any of these can alter the risk profile enough to warrant a fresh round of enhanced due diligence rather than waiting for the next scheduled review. The FFIEC IT Examination Handbook also expects management to evaluate the quality of service, control environment, and financial condition of third parties providing critical IT services on an ongoing basis.4Federal Financial Institutions Examination Council. FFIEC Information Technology Examination Handbook – Management Booklet

Plan the Exit Before You Sign

Plan the exit before you sign the contract. An exit strategy addresses how the institution will transition away if the relationship deteriorates, the vendor’s financial condition weakens, regulatory problems emerge, or strategic priorities change. Building exit provisions into the contract from the outset, including data return and destruction procedures, transition support timelines, and system access termination, prevents the vendor from having leverage when you most need to leave.

Document whether backup providers or in-house alternatives exist for the services the vendor delivers. For critical vendors, identify the operational continuity risks of a sudden exit and estimate how long a transition would realistically take. If the answer to “how would we replace this vendor within 90 days?” is “we couldn’t,” that concentration risk belongs in the board’s periodic reporting.

Recordkeeping and Examination Readiness

Every element of the due diligence process should be documented and retained. The final due diligence report, including risk ratings, supporting analysis, approval records, and any conditions or exceptions, needs to be stored securely and made accessible for regulatory examinations. Examiners will evaluate whether you have a documented framework for identifying, measuring, and monitoring risks across all vendor relationships, and whether the board and senior management are providing effective oversight.4Federal Financial Institutions Examination Council. FFIEC Information Technology Examination Handbook – Management Booklet

Examiners also assess the adequacy of third-party audit reports in terms of scope, independence, expertise, frequency, and whether corrective actions were taken on identified issues.4Federal Financial Institutions Examination Council. FFIEC Information Technology Examination Handbook – Management Booklet A clean audit trail from initial risk classification through ongoing monitoring makes the difference between an examination that confirms sound practices and one that generates matters requiring attention.