Due Diligence and Ongoing Monitoring

 View Only
  • 1.  Critical Vendor

    This message was posted by a user wishing to remain anonymous
    Posted 07-17-2023 02:26 PM
    This message was posted by a user wishing to remain anonymous

    Good Morning all,

    I need the community's opinion on a vendor criticality.

    We are a financial institution and one of our vendors <w:sdt docpart="38B7A95281C74D5FA3162531986B50EA" text="t" id="-356811658">provides Foreign Remittance and Exchange Service for Wire Transfer. Previously we didn't consider the wire transfer as critical.</w:sdt>

    I am trying to figure out if we should consider them a Critical vendor. We use a very similar definition as Venminder. Which is:

    • Suppose there was a significant third-party vendor failure. Would the sudden loss of this third party cause significant disruption to your business?
    • Would the sudden loss impact your organization's customers?
    • If the vendor service is disrupted, would there be a negative impact on your operations if the time to restore service took more than 24 hours?

    I want to know how other FI classify wire transfers, and why.

    Thanks



  • 2.  RE: Critical Vendor

    This message was posted by a user wishing to remain anonymous
    Posted 07-17-2023 04:03 PM
    This message was posted by a user wishing to remain anonymous

    Good afternoon,

    Are those the only questions you're asking to determine the criticality of a vendor? If so, it may help to add if that vendor will have access to non-public information and/or if that vendor will have access to your customer/member data; Determine what level of your customer/member will this vendor have access to and what the cost of breach will be. Your organization will have to determine those metrics. Another question you may want to incorporate is the annual cost with the vendor. 

    It was medium criticality for us initially, but after further discussion with our stakeholders and based on additional factors, we overrode the criticality to a high rating. This will also allow our organization to initiate ongoing VDD on an annual basis. 




  • 3.  RE: Critical Vendor

    This message was posted by a user wishing to remain anonymous
    Posted 07-18-2023 02:29 PM
    This message was posted by a user wishing to remain anonymous

    We use the same "impact focused" questions to determine criticality.  

    We do not rate wire transfers as critical.  ACH would be an alternative for domestic transfers and our volume in international wire transfers is low - there wouldn't be a significant impact. 




  • 4.  RE: Critical Vendor

    This message was posted by a user wishing to remain anonymous
    Posted 07-24-2023 08:46 AM
    This message was posted by a user wishing to remain anonymous

    Thank you for all the responses.