Vendor Management Policy
Third-party risk management governance, the vendor lifecycle, due diligence and contract standards, and sponsor bank coordination.
| Field | Value |
|---|---|
| Document | Vendor Management Policy |
| Version | 1.0 |
| Owner | Compliance Officer |
| Review | Annual, or on material program change |
Authorities
This policy implements, within the sponsor bank's program:
- Interagency Guidance on Third-Party Relationships: Risk Management (June 2023), issued by the OCC, Federal Reserve, and FDIC, which replaced OCC Bulletin 2013-29 and sets the life-cycle expectations for planning, due diligence, contracting, monitoring, and termination.
- FFIEC IT Examination Handbook, Outsourcing Technology Services, for technology and data providers.
- Gramm-Leach-Bliley Act and its safeguards rules, where a provider handles customer information.
- The sponsor bank's program agreement, under which the bank approves critical service providers and expects notice when they change.
1. Purpose and Scope
This policy establishes the Company's third-party risk management program, which identifies, assesses, manages, and monitors the risks that service providers introduce to the Company and to the sponsor bank program. Effective vendor management is expected under the banking regulators' third-party relationship guidance and required by the program agreement with the sponsor bank, and it is a core component of the compliance management system. The policy applies to every third-party relationship, including software, cloud and infrastructure, payment and data processors, identity verification platforms, analytics providers, professional services, and any subcontractor they use for program work.
2. Definitions
| Term | Definition |
|---|---|
| Service provider | Any external party that performs services on behalf of the Company in connection with the program, regardless of contract type |
| Critical service provider | A provider that accesses, stores, transmits, or processes unencrypted customer data; performs functions whose failure could expose the sponsor bank to significant risk; or could materially affect the sponsor bank's reputation. The sponsor bank has approval and direct examination rights over critical service providers |
| Material vendor | A provider that does not meet the critical definition but performs functions important to the program |
| Standard vendor | A low-risk provider with no customer data access and no regulated or program-critical function |
| Subcontractor or fourth party | An entity a provider engages to perform some or all of its services to the Company |
3. Roles and Responsibilities
The Compliance Officer owns the program, approves critical service provider engagements, coordinates sponsor bank approvals and notifications, reviews diligence findings, owns monitoring outputs and remediation, and reports to the CEO and the sponsor bank. Engineering and operations identify the need, take part in diligence on fit, integrate the vendor, and surface performance and security concerns. Finance reviews financial soundness and tracks spend and renewals. Outside counsel reviews and negotiates critical and material contracts. Each vendor has a designated owner responsible for day-to-day management, performance review, and escalation. The CEO approves critical engagements above a defined threshold and any engagement with material business or compliance implications.
4. Vendor Risk Classification
Each provider is placed in one of three tiers at the start of the engagement and re-evaluated at each annual review or on a material change.
| Tier | Definition |
|---|---|
| Tier 1, Critical service provider | Accesses unencrypted customer data, performs core program functions, or could materially affect the sponsor bank's reputation. Subject to sponsor bank approval, full diligence, ongoing monitoring, and direct sponsor bank examination rights |
| Tier 2, Material vendor | Performs functions important to operations without meeting the critical definition; may have limited access to confidential information but not unencrypted customer data |
| Tier 3, Standard vendor | Low risk; no customer data access; failure does not materially affect the program |
The tier drives the depth of diligence, the contract requirements, and the monitoring cadence. The Compliance Officer assigns the tier and documents the rationale; the sponsor bank may ask for a tier to be adjusted.
5. Vendor Lifecycle
5.1 Planning and Identification
The team initiating an engagement documents the business need, the functions the vendor will perform, the data it will access, and the proposed integration. Before outreach, the Compliance Officer determines the likely tier and any sponsor bank notification or approval that applies.
5.2 Due Diligence and Selection
Diligence follows Section 13 and covers financial soundness, operational capability, compliance and regulatory standing, information security and data protection, business continuity, subcontractors, insurance, and references, scaled to the tier.
5.3 Contract Negotiation
Every contract includes the standard provisions in Section 14. Critical service provider contracts add sponsor bank step-in rights, direct reporting to the bank, bank audit and examination rights, and bank approval of material changes. Outside counsel reviews Tier 1 and significant Tier 2 contracts before execution.
5.4 Onboarding and Activation
After execution the vendor is entered in the inventory with its owner, tier, monitoring cadence, and renewal date; integrations get access controls, logging, and security testing; and the Compliance Officer confirms readiness before production activity.
5.5 Ongoing Monitoring
Each vendor is monitored to its tier: performance and service-level review, financial review, security and compliance attestations such as SOC 2 reports for vendors handling customer or confidential data, incident review, and review of proposed material changes. Tier 1 vendors are reviewed at least annually with an on-site or video walkthrough where practicable; Tier 2 annually; Tier 3 at the Compliance Officer's discretion or at renewal.
5.6 Issue Management and Remediation
Vendor performance issues, security incidents, regulatory matters, and other concerns enter the Issues Management process. The vendor owner and the Compliance Officer set severity and the response: corrective action plan, contractual escalation, suspension, or termination. Material issues affecting critical service providers are reported to the sponsor bank as the program agreement requires.
5.7 Termination and Offboarding
When a relationship ends, the Company revokes the vendor's access to systems and data, retrieves or confirms destruction of confidential information, settles obligations, and records the termination in the inventory. Critical service provider terminations require 60 days' advance notice to the sponsor bank.
6. Sponsor Bank Approval and Notification
| Event | Sponsor bank treatment |
|---|---|
| New critical service provider | Prior written approval, with 30 days' notice before contract execution |
| Termination of a critical service provider | 60 days' advance notice |
| Material change in scope of a critical relationship | Prior written approval |
| Material adverse change in a critical provider's creditworthiness, capability, or regulatory status | Prompt notice |
| New material vendor | Notice under the operating procedures |
| Vendor incident affecting the program | Treated as a program incident; notice per the incident response timeframes |
7. Critical Service Provider Requirements
Critical service provider contracts include step-in rights allowing the sponsor bank to take the Company's place with the vendor to maintain continuity if the Company cannot perform or becomes insolvent or subject to regulatory action; direct reporting rights so the vendor reports to the bank on request; direct audit, communication, and examination rights for the bank, including site visits; and cooperation with modifications the bank requests to reflect changes in law or regulatory criticism. The Company facilitates the bank's access to these vendors on reasonable notice.
8. Subcontractor and Fourth-Party Management
Critical service providers disclose the subcontractors they use for program work at diligence, give notice of material subcontractor changes, and flow compliance, security, audit, and reporting obligations down to them. The Company may require additional diligence on a fourth party where the function or data exposure is material.
9. Vendor Inventory
A central inventory records, for each provider: legal name and contacts; function and program role; tier and rationale; owner; contract effective and renewal dates; key provisions; material subcontractors; most recent diligence date and findings; most recent monitoring review and outcome; open issues; status; and sponsor bank notification or approval records. The Compliance Officer maintains it with input from vendor owners.
10. Reporting and Governance
The Compliance Officer reports vendor activity to the CEO at least quarterly, covering new engagements, incidents, material monitoring findings, renewals, and open sponsor bank items. The sponsor bank receives the notices in Section 6, vendor matters in the quarterly compliance report, and a summary of the annual program review.
11. Annual Program Review
The Compliance Officer reviews the program annually: inventory completeness and accuracy, tier appropriateness, diligence and monitoring completion, open issues, vendor performance against expectations, concentration risk, and updates required to this policy. The sponsor bank receives a summary.
12. Recordkeeping
Vendor records, including diligence files, contracts, monitoring reviews, and issue records, are retained for seven years from the end of the relationship under the Recordkeeping Policy.
13. Due Diligence Standards by Tier
Tier 1 diligence covers legal and corporate standing with sanctions screening of the vendor and its principals; two years of financial statements; operational capability with references and a demonstration; compliance and regulatory standing; information security through a current SOC 2 Type II or comparable attestation; data protection and privacy practices; business continuity and disaster recovery with recovery objectives and test results; subcontractors; insurance; and references and adverse media. It is written up in a diligence memo that records findings, gaps, mitigations, and the engagement decision, signed by the Compliance Officer, with a summary provided to the sponsor bank.
Tier 2 diligence is proportionate: entity verification and sanctions screening, a financial reference, compliance standing, a SOC 2 report or security questionnaire, data protection confirmation, insurance where warranted, and references, captured in a summary approved by the vendor owner and the Compliance Officer.
Tier 3 diligence confirms the legal entity and the absence of sanctions or obvious negative indicators, with a capability and pricing review, documented in a brief approval memo or retained correspondence.
The decision framework: proceed on clean diligence; proceed with documented mitigations where risks are mitigable; and remediate, select an alternative, or document the rationale and escalate to the CEO and, for Tier 1, the sponsor bank where material gaps remain.
14. Contract Provisions
Every contract includes a service description and deliverables; term and renewal; pricing; confidentiality for at least five years after termination; compliance with applicable law; data protection with breach notification and return or destruction of data; insurance; mutual indemnification; a reasonable limitation of liability with carve-outs; termination for cause and convenience; records and audit access; subcontracting restrictions; survival; and governing law.
Critical service provider contracts add sponsor bank step-in rights, direct reporting to the bank, bank audit and examination rights, notice of material change, subcontractor flow-down, bank-requested modifications, seven-year records retention, transition assistance, and, where feasible, the bank as an additional insured.
Any contract with access to customer data, regardless of tier, adds data ownership by the sponsor bank, permitted use limited to the services, safeguards consistent with the interagency guidelines, sub-processor disclosure and consent, immediate breach notification, return or destruction with certification, seven-year retention, and no cross-border transfer without approval.