Policy, Program and Procedures

 View Only
  • 1.  Criticality criteria for third party vendors

    This message was posted by a user wishing to remain anonymous
    Posted 7 hours ago
    This message was posted by a user wishing to remain anonymous

    For financial institutions greater than 5 billion in assets, what is your criteria for determining whether a third party vendor is critical (e.g., operational importance, data sensitivity, compliance impact, etc.)?  Do you use some sort of matrix or questionnaire?  



    -------------------------------------------


  • 2.  RE: Criticality criteria for third party vendors

    Posted 5 hours ago

    Good morning! We use both a matrix and a questionnaire. The risk impact matrix we have created derives from our risk appetite which informs our questionnaire. Within our system, the questionnaire will deliver us a result based on the answers to questions regarding cost, financial impact, data shared, operational impact, transaction reliance, and third-party reliance. The weighting is based on our risk appetite. Whatever the vendor calculates out to, we will discuss with our vendor owners what that means for oversight, and if the vendor should be upgraded, downgraded, or accepted at their calculated classification level. 

    -------------------------------------------



  • 3.  RE: Criticality criteria for third party vendors

    Posted 5 hours ago

    We use first a materiality assessment of 7 questions that include- Will this vendor access borrower or employee confidential data?  Will this vendor have major impact on our ability to operate our business? Are there significant internal resources needed to manage and monitor this vendor? Will this vendor process financial transactions?  Will this borrower have direct or indirect communication with our clients, customers or board?   Does this vendor market products or services for  us? 

    If the answer to any of these are yes, the vendor is considered material and then goes through a risk assessment. We have a series of weighted responses that will calculate based on the overall weight a risk tier of the vendor. The tiers range from Enterprise Critical Tier 0 (very high risk tier) Critical  Tier 1 (high risk) Medium Risk Tier 2, Low Risk Tier 3.   The vendors who are not material are assigned a Tier 4 rating.    Think of the risk assessment questions in terms of what risks your organization could face through the engagement- Will this vendor access restricted borrower data- High weight assigned. If no, then no weight is assigned.   What are our Recovery times for this vendor should they become inoperable? Immediate- Highest weight assigned,  24-72 Hours- High weight, >72- 1 week medium, indefinitely, low or no weight.  These are just quick examples- we have around 25 questions in ours that will aggregate and assign a tier. If TPRM has a vendor that tiers lower than we think appropriate or we think the vendor use could be expanded in a way that might impact the risk tier in the future (think pilot vs. permanent relationship) TPRM can elevate the tier accordingly.   I hope that helps!  We built our own but there are lots of places that offer examples that you can research.