Good morning! We use both a matrix and a questionnaire. The risk impact matrix we have created derives from our risk appetite which informs our questionnaire. Within our system, the questionnaire will deliver us a result based on the answers to questions regarding cost, financial impact, data shared, operational impact, transaction reliance, and third-party reliance. The weighting is based on our risk appetite. Whatever the vendor calculates out to, we will discuss with our vendor owners what that means for oversight, and if the vendor should be upgraded, downgraded, or accepted at their calculated classification level.
-------------------------------------------
Original Message:
Sent: 02-19-2026 10:10 AM
From: Anonymous Member
Subject: Criticality criteria for third party vendors
This message was posted by a user wishing to remain anonymous
For financial institutions greater than 5 billion in assets, what is your criteria for determining whether a third party vendor is critical (e.g., operational importance, data sensitivity, compliance impact, etc.)? Do you use some sort of matrix or questionnaire?
-------------------------------------------