Third-Party Vendor Risk Management Checklist

This comprehensive third-party vendor risk management checklist ensures regulatory compliance with OCC, FDIC, CFPB, Federal Reserve, OCC Bulletin 2013-29. Annual third-party risk management review for financial institutions covering vendor due diligence, contract requirements, ongoing monitoring, and concentration risk per OCC Bulletin 2013-29, FDIC FIL-44-2008, and CFPB Supervisory Highlights on vendor management. Third-party failures increasingly drive bank examination findings and enforcement

  • Industry: Financial Services
  • Frequency: Monthly / Quarterly
  • Estimated Time: 45 minutes
  • Role: Compliance Officer / Branch Manager
  • Total Items: 18
  • Compliance: OCC, FDIC, CFPB, Federal Reserve, OCC Bulletin 2013-29

Vendor Inventory and Tiering

Maintain vendor inventory per OCC guidance.

  • Is comprehensive vendor inventory maintained listing all third-party relationships with services provided?
  • Has each vendor been assigned a risk tier (critical, high, moderate, low) based on business impact and data access?
  • Are critical activities (core banking, payment processing, IT infrastructure) clearly identified with concentration risk noted?
  • Are material fourth-party subcontractors of critical vendors identified and risk assessed?

Pre-Engagement Due Diligence

Verify due diligence per OCC 2013-29.

  • Has vendor financial stability been assessed including financial statements and credit review for critical vendors?
  • Has SOC 1 or SOC 2 Type II report been obtained and reviewed for critical technology vendors?
  • Has vendor cybersecurity posture been assessed including penetration testing and vulnerability management?
  • Has vendor's Business Continuity Plan been reviewed confirming recovery capability for critical services?
  • Have vendor references been checked including peer financial institution users?

Contract Requirements

Verify contract protections per OCC guidance.

  • Do vendor contracts include data security requirements, breach notification (typically 24-72 hours), and data disposal?
  • Does contract provide bank right-to-audit or right-to-receive audit reports?
  • Does contract require vendor to notify bank before engaging material subcontractors?
  • Does contract define RTO/RPO requirements and vendor obligations for business continuity?
  • Does contract include termination for cause and data return/destruction requirements?

Ongoing Monitoring and Performance

Verify ongoing monitoring per OCC lifecycle guidance.

  • Are critical vendor relationships reviewed at least annually with refreshed due diligence?
  • Are SLA performance metrics tracked and vendor failures escalated and documented?
  • Are vendor incidents and disruptions logged and analyzed for trend patterns?
  • Is aggregate third-party risk exposure reported to board or risk committee annually?

Related Financial Services Banking Checklists

Why Use This Third-Party Vendor Risk Management Checklist?

This third-party vendor risk management checklist helps financial services teams maintain compliance and operational excellence. Designed for compliance officer / branch manager professionals, this checklist covers 18 critical inspection points across 4 sections. Recommended frequency: monthly / quarterly.

Ensures compliance with OCC, FDIC, CFPB, Federal Reserve, OCC Bulletin 2013-29. Regulatory-aligned for audit readiness and inspection documentation.

Frequently Asked Questions

What is a Third-Party Vendor Risk Management Checklist?

A Third-Party Vendor Risk Management Checklist is a standardized inspection form used by compliance officer / branch manager to ensure consistent financial services operations. It contains 27 inspection points organized into 4 sections. FREE third-party vendor risk management checklist PDF. Annual third-party risk management review for financial institutions covering vendor due diligence, contract requirements, ongoing monitoring, and concentration risk per OCC Bulletin 2013-29, FDIC FIL-44-2008, and CFPB Supervisory Highlights on vendor management. Compliant with OCC, FDIC, CFPB, Federal Reserve. Download FREE digital template for financial services & banking operations compliance now.

How often should I use this financial services checklist?

This checklist is designed to be completed monthly / quarterly. Regular use ensures compliance with OCC and FDIC and helps identify issues before they become problems.

Can I download this Third-Party Vendor Risk Management Checklist as a PDF?

Yes, you can download this checklist as a FREE PDF for printing or offline use. The checklist includes 27 fields across 4 sections and typically takes 45 minutes to complete.

What compliance standards does this checklist cover?

This checklist helps ensure compliance with OCC, FDIC, CFPB, Federal Reserve, OCC Bulletin 2013-29. Following these standards protects your organization and ensures best practices.

How do I complete this financial services inspection checklist?

Begin by completing the header fields for Institution/Branch Name, Review Date, Reviewer/Compliance Officer, Review Period, and Charter/Registration Number. Work through each of the 4 sections, marking items Yes or No as applicable. Finally, complete the footer fields and add your signature. The entire process takes approximately 45 minutes.

What are the key sections in this financial services checklist?

This financial services checklist is organized into 4 key sections: Vendor Inventory and Tiering, Pre-Engagement Due Diligence, Contract Requirements, Ongoing Monitoring and Performance. Each section contains specific inspection points that compliance officer / branch manager must verify. The structured layout ensures nothing is missed during financial services inspections and makes the process efficient, typically taking 45 minutes to complete.

Who should use this Third-Party Vendor Risk Management Checklist?

This checklist is primarily designed for compliance officer / branch manager working in financial services operations. However, it is also valuable for quality assurance teams, safety officers, compliance managers, and supervisors who need to verify that financial services standards are being met. Organizations of all sizes can benefit from using this Third-Party Vendor Risk Management Checklist to maintain consistency and accountability.

Browse More Checklists

POPProbe