Leela

Vendor Management Policy

Third-party risk management governance, the vendor lifecycle, due diligence and contract standards, and sponsor bank coordination.

FieldValue
DocumentVendor Management Policy
Version1.0
OwnerCompliance Officer
ReviewAnnual, or on material program change

Authorities

This policy implements, within the sponsor bank's program:

  • Interagency Guidance on Third-Party Relationships: Risk Management (June 2023), issued by the OCC, Federal Reserve, and FDIC, which replaced OCC Bulletin 2013-29 and sets the life-cycle expectations for planning, due diligence, contracting, monitoring, and termination.
  • FFIEC IT Examination Handbook, Outsourcing Technology Services, for technology and data providers.
  • Gramm-Leach-Bliley Act and its safeguards rules, where a provider handles customer information.
  • The sponsor bank's program agreement, under which the bank approves critical service providers and expects notice when they change.

1. Purpose and Scope

This policy establishes the Company's third-party risk management program, which identifies, assesses, manages, and monitors the risks that service providers introduce to the Company and to the sponsor bank program. Effective vendor management is expected under the banking regulators' third-party relationship guidance and required by the program agreement with the sponsor bank, and it is a core component of the compliance management system. The policy applies to every third-party relationship, including software, cloud and infrastructure, payment and data processors, identity verification platforms, analytics providers, professional services, and any subcontractor they use for program work.

2. Definitions

TermDefinition
Service providerAny external party that performs services on behalf of the Company in connection with the program, regardless of contract type
Critical service providerA provider that accesses, stores, transmits, or processes unencrypted customer data; performs functions whose failure could expose the sponsor bank to significant risk; or could materially affect the sponsor bank's reputation. The sponsor bank has approval and direct examination rights over critical service providers
Material vendorA provider that does not meet the critical definition but performs functions important to the program
Standard vendorA low-risk provider with no customer data access and no regulated or program-critical function
Subcontractor or fourth partyAn entity a provider engages to perform some or all of its services to the Company

3. Roles and Responsibilities

The Compliance Officer owns the program, approves critical service provider engagements, coordinates sponsor bank approvals and notifications, reviews diligence findings, owns monitoring outputs and remediation, and reports to the CEO and the sponsor bank. Engineering and operations identify the need, take part in diligence on fit, integrate the vendor, and surface performance and security concerns. Finance reviews financial soundness and tracks spend and renewals. Outside counsel reviews and negotiates critical and material contracts. Each vendor has a designated owner responsible for day-to-day management, performance review, and escalation. The CEO approves critical engagements above a defined threshold and any engagement with material business or compliance implications.

4. Vendor Risk Classification

Each provider is placed in one of three tiers at the start of the engagement and re-evaluated at each annual review or on a material change.

TierDefinition
Tier 1, Critical service providerAccesses unencrypted customer data, performs core program functions, or could materially affect the sponsor bank's reputation. Subject to sponsor bank approval, full diligence, ongoing monitoring, and direct sponsor bank examination rights
Tier 2, Material vendorPerforms functions important to operations without meeting the critical definition; may have limited access to confidential information but not unencrypted customer data
Tier 3, Standard vendorLow risk; no customer data access; failure does not materially affect the program

The tier drives the depth of diligence, the contract requirements, and the monitoring cadence. The Compliance Officer assigns the tier and documents the rationale; the sponsor bank may ask for a tier to be adjusted.

5. Vendor Lifecycle

5.1 Planning and Identification

The team initiating an engagement documents the business need, the functions the vendor will perform, the data it will access, and the proposed integration. Before outreach, the Compliance Officer determines the likely tier and any sponsor bank notification or approval that applies.

5.2 Due Diligence and Selection

Diligence follows Section 13 and covers financial soundness, operational capability, compliance and regulatory standing, information security and data protection, business continuity, subcontractors, insurance, and references, scaled to the tier.

5.3 Contract Negotiation

Every contract includes the standard provisions in Section 14. Critical service provider contracts add sponsor bank step-in rights, direct reporting to the bank, bank audit and examination rights, and bank approval of material changes. Outside counsel reviews Tier 1 and significant Tier 2 contracts before execution.

5.4 Onboarding and Activation

After execution the vendor is entered in the inventory with its owner, tier, monitoring cadence, and renewal date; integrations get access controls, logging, and security testing; and the Compliance Officer confirms readiness before production activity.

5.5 Ongoing Monitoring

Each vendor is monitored to its tier: performance and service-level review, financial review, security and compliance attestations such as SOC 2 reports for vendors handling customer or confidential data, incident review, and review of proposed material changes. Tier 1 vendors are reviewed at least annually with an on-site or video walkthrough where practicable; Tier 2 annually; Tier 3 at the Compliance Officer's discretion or at renewal.

5.6 Issue Management and Remediation

Vendor performance issues, security incidents, regulatory matters, and other concerns enter the Issues Management process. The vendor owner and the Compliance Officer set severity and the response: corrective action plan, contractual escalation, suspension, or termination. Material issues affecting critical service providers are reported to the sponsor bank as the program agreement requires.

5.7 Termination and Offboarding

When a relationship ends, the Company revokes the vendor's access to systems and data, retrieves or confirms destruction of confidential information, settles obligations, and records the termination in the inventory. Critical service provider terminations require 60 days' advance notice to the sponsor bank.

6. Sponsor Bank Approval and Notification

EventSponsor bank treatment
New critical service providerPrior written approval, with 30 days' notice before contract execution
Termination of a critical service provider60 days' advance notice
Material change in scope of a critical relationshipPrior written approval
Material adverse change in a critical provider's creditworthiness, capability, or regulatory statusPrompt notice
New material vendorNotice under the operating procedures
Vendor incident affecting the programTreated as a program incident; notice per the incident response timeframes

7. Critical Service Provider Requirements

Critical service provider contracts include step-in rights allowing the sponsor bank to take the Company's place with the vendor to maintain continuity if the Company cannot perform or becomes insolvent or subject to regulatory action; direct reporting rights so the vendor reports to the bank on request; direct audit, communication, and examination rights for the bank, including site visits; and cooperation with modifications the bank requests to reflect changes in law or regulatory criticism. The Company facilitates the bank's access to these vendors on reasonable notice.

8. Subcontractor and Fourth-Party Management

Critical service providers disclose the subcontractors they use for program work at diligence, give notice of material subcontractor changes, and flow compliance, security, audit, and reporting obligations down to them. The Company may require additional diligence on a fourth party where the function or data exposure is material.

9. Vendor Inventory

A central inventory records, for each provider: legal name and contacts; function and program role; tier and rationale; owner; contract effective and renewal dates; key provisions; material subcontractors; most recent diligence date and findings; most recent monitoring review and outcome; open issues; status; and sponsor bank notification or approval records. The Compliance Officer maintains it with input from vendor owners.

10. Reporting and Governance

The Compliance Officer reports vendor activity to the CEO at least quarterly, covering new engagements, incidents, material monitoring findings, renewals, and open sponsor bank items. The sponsor bank receives the notices in Section 6, vendor matters in the quarterly compliance report, and a summary of the annual program review.

11. Annual Program Review

The Compliance Officer reviews the program annually: inventory completeness and accuracy, tier appropriateness, diligence and monitoring completion, open issues, vendor performance against expectations, concentration risk, and updates required to this policy. The sponsor bank receives a summary.

12. Recordkeeping

Vendor records, including diligence files, contracts, monitoring reviews, and issue records, are retained for seven years from the end of the relationship under the Recordkeeping Policy.

13. Due Diligence Standards by Tier

Tier 1 diligence covers legal and corporate standing with sanctions screening of the vendor and its principals; two years of financial statements; operational capability with references and a demonstration; compliance and regulatory standing; information security through a current SOC 2 Type II or comparable attestation; data protection and privacy practices; business continuity and disaster recovery with recovery objectives and test results; subcontractors; insurance; and references and adverse media. It is written up in a diligence memo that records findings, gaps, mitigations, and the engagement decision, signed by the Compliance Officer, with a summary provided to the sponsor bank.

Tier 2 diligence is proportionate: entity verification and sanctions screening, a financial reference, compliance standing, a SOC 2 report or security questionnaire, data protection confirmation, insurance where warranted, and references, captured in a summary approved by the vendor owner and the Compliance Officer.

Tier 3 diligence confirms the legal entity and the absence of sanctions or obvious negative indicators, with a capability and pricing review, documented in a brief approval memo or retained correspondence.

The decision framework: proceed on clean diligence; proceed with documented mitigations where risks are mitigable; and remediate, select an alternative, or document the rationale and escalate to the CEO and, for Tier 1, the sponsor bank where material gaps remain.

14. Contract Provisions

Every contract includes a service description and deliverables; term and renewal; pricing; confidentiality for at least five years after termination; compliance with applicable law; data protection with breach notification and return or destruction of data; insurance; mutual indemnification; a reasonable limitation of liability with carve-outs; termination for cause and convenience; records and audit access; subcontracting restrictions; survival; and governing law.

Critical service provider contracts add sponsor bank step-in rights, direct reporting to the bank, bank audit and examination rights, notice of material change, subcontractor flow-down, bank-requested modifications, seven-year records retention, transition assistance, and, where feasible, the bank as an additional insured.

Any contract with access to customer data, regardless of tier, adds data ownership by the sponsor bank, permitted use limited to the services, safeguards consistent with the interagency guidelines, sub-processor disclosure and consent, immediate breach notification, return or destruction with certification, seven-year retention, and no cross-border transfer without approval.