Latest Discussions

  • This message was posted by a user wishing to remain anonymous Our third-party risk assessments incorporate data 'type' when assessing the overall risks. Taking into account the industry I work in, data groups were developed, e.g. Group 1 (Low): name, ...

  • This message was posted by a user wishing to remain anonymous I have recently been asked to vet out a Mortgage broker for the secondary market. When I asked for their due diligence documents, they replied with a certification document and financials. ...

  • Yes, our organization has rated VISA and MasterCard as high-risk vendors as an outage would have a significant impact on our operations. We are able to retrieve due diligence annually through their Customer Trust Portals. Initially it was hard to get ...

  • Profile Picture

    TPRM Staffing Structure

    This message was posted by a user wishing to remain anonymous I'm researching how credit unions structure leadership over Vendor Management and Third-Party Risk Management programs. For those willing to share: What is your credit union's asset ...

    1 person likes this.
  • I'm looking for perspectives from others in the third-party risk management space regarding a potential enhancement to our Engagement Risk Assessment (ERA). Today, our assessment considers factors such as the sensitivity and type of data involved in ...

  • We absolutely consider VISA/Mastercard a high-risk vendor. They are a high risk vendor because they are providing services considered "mission critical" to the our credit union's daily operations; involved with the storage and/or transmission of personal, ...

  • This message was posted by a user wishing to remain anonymous Yes, we consider Visa a vendor/third-party relationship. We do have them classified as an exempt vendor, which is approved by Steering Committee annually. Exempt vendors are typically critical/high ...

  • This message was posted by a user wishing to remain anonymous We also consider Visa and Mastercard to be vendors that must go through recertification annually. It's like pulling teeth to get the documents our SMEs need to do their risk assessments, ...

  • We consider Visa a vendor. We collect approx. 20 - 25 documents from them to include: SOCs, BCP, Recovery Exercise Report or latest Recovery Exercise Report , Most Recent Visa PCI Attestation of Compliance, Latest Visa Global Key Controls Document, ...

  • We do consider VISA and Mastercard to be vendors. I just reviewed due diligence documentation from Mastercard. They didn't provide it all at first, but when we made a request, they sent a package of over 20 documents, including SOC reports ------------------------------ ...

  • This message was posted by a user wishing to remain anonymous Visa has a trust portal within Visa Access where you can access their SOC reports, PCI, etc. Work with your account rep at Visa to obtain access to the trust portal or you could try the ...

  • This message was posted by a user wishing to remain anonymous Hi, We list MC as a vendor and because of the interchange income and how important card usage is to a financial institution, we have it listed as a Critical vendor. We get SOC 1 and SOC ...

  • This message was posted by a user wishing to remain anonymous Currently, we have VISA included on our vendor list, but I am having so much trouble getting anyone there to provide any sort of due diligence documentation including a SOC. They make it ...

  • Just my own opinion, we do not need to assess credit bureaus, but we should assess audit and consulting firms based on the risk for the services they provide to the bank.

  • Profile Picture

    Credit Bureaus and Audit Companies

    This message was posted by a user wishing to remain anonymous Hi everyone-I'm curious whether your teams assess credit bureaus and auditing firms as part of your process. Thanks.

    1 person likes this.
  • Are any credit unions currently using push notifications for marketing purposes within their mobile apps? If so, could you share how you distinguish between marketing and transactional/service-related messages, including how consent is obtained and managed ...

  • Good afternoon, There are several factors to consider in this instance. While the specific requirements may vary depending on your risk methodology, based on the description provided-and assuming the service provider will have access to Non-Public Information ...

  • We are onboarding our first Brokered Deposits vendor since before the 2024 SVB, et al collapse. What due diligence do you gather from these types of vendors? Our last onboarding was very long time ago and the previous vendor program manager treated them ...

  • Since the ridiculous expansion in the 2023 guidance ("any business arrangement", which places Subway in scope for bringing lunch to a meeting), we (FDIC examined) have an ever-growing section in the TPRM policy & Standard governance documentation that ...

  • Profile Picture

    RE: Escrow and Title companies Due Diligence

    This message was posted by a user wishing to remain anonymous We include Escrow and Title Companies in our "in scope vendors". For ongoing due diligence we typically collect insurance only.