Due Diligence and Ongoing Monitoring

 View Only
  • 1.  Does your FI consider VISA and Mastercard to be Vendors?

    This message was posted by a user wishing to remain anonymous
    Posted 20 days ago
    This message was posted by a user wishing to remain anonymous

    Currently, we have VISA included on our vendor list, but I am having so much trouble getting anyone there to provide any sort of due diligence documentation including a SOC.  They make it seem like I am the only bank asking for their due diligence documentation. 

    • If you work with VISA (or Mastercard), do you consider them to be a vendor?  If not, why not?
    • If you do consider them to be a vendor, have you had any issues getting them to provide a SOC report and any additional forms of due diligence?

    Thanks in advance for any information you are willing to provided!



  • 2.  RE: Does your FI consider VISA and Mastercard to be Vendors?

    Posted 20 days ago

    We do consider VISA and Mastercard to be vendors. I just reviewed due diligence documentation from Mastercard. They didn't provide it all at first, but when we made a request, they sent a package of over 20 documents, including SOC reports



    ------------------------------
    Paul Kletchka | VP, Information Security Officer | Fahey Bank
    p: 1-740-751-6940 | w: faheybank.bank
    ------------------------------



  • 3.  RE: Does your FI consider VISA and Mastercard to be Vendors?

    Posted 13 days ago

    We absolutely consider VISA/Mastercard a high-risk vendor. They are a high risk vendor because they are providing services considered "mission critical" to the our credit union's daily operations; involved with the storage and/or transmission of personal, non-public information of our members; are subject to multiple consumer protection regulations; pose significant earning, capital, or reputation risks for us if the vendor is unable to perform as expected; and significant disruption in services could result from the vendor's failure to adequately provide services and manage risks.

    And yes, getting due diligence on our vendors each year can be a massive pain. It's a very heavy lift; a huge burden; complicated and challenging. So much so, that we have started requesting due diligence compliance language in our contracts. We ask for the below and are fairly successful in getting it. I will say we just switched to MC and they gave us everything for vetting. It will be interesting to see how the annual vendor review goes.....  VISA was historically a pain and gave very little, SOC reports were non-negotiable for us. 

    • Latest SOC reports (SOC 1 & SOC 2, if applicable) or equivalent third-party audit for applicable products
      • If you have a cloud service provider, 3rd party data center, or other 3rd party vendor that is critical to support the delivery of your services/products, please also include the SOC report for that vendor, and briefly describe the relationship between your company and the supporting critical vendor.
    • Gap/Bridge Letter(s) for the SOC reports
    • Information Security Policy, Privacy Policy, AI Policies and Model Cards, Standardized Information Gathering Questionnaire (SIG), and any other available Compliance Policies (AML, PCI, NACHA, BSA, etc.)
    • Cyber/Network Security Policies with Testing Requirements and Results (i.e. Vulnerability and/or Penetration Testing)
    • Incident Response Policies with client notification protocols
    • Disaster Recovery/Business Continuity/Pandemic Plans
    • Testing Results for your Disaster Recovery/Business Continuity Plan
    • Current Certificate of Insurance (e.g. Liability, E&O, Cyber/TEO/MPL, EPL/Fiduciary, Crime)
    • Latest Annual Financial Statement with period end date of 2025 or 2026 (audited financial statements, including two comparative years of results, with notes preferred)


    ------------------------------
    Katie Decker
    katie.decker@midflorida.com
    MIDFLORIDA Credit Union
    SVP Integrated Risk, Integrated Risk
    ------------------------------



  • 4.  RE: Does your FI consider VISA and Mastercard to be Vendors?

    This message was posted by a user wishing to remain anonymous
    Posted 13 days ago
    This message was posted by a user wishing to remain anonymous

    We also consider Visa and Mastercard to be vendors that must go through recertification annually. It's like pulling teeth to get the documents our SMEs need to do their risk assessments, but eventually, we do get what we need.




  • 5.  RE: Does your FI consider VISA and Mastercard to be Vendors?

    This message was posted by a user wishing to remain anonymous
    Posted 13 days ago
    This message was posted by a user wishing to remain anonymous

    Hi,

    We list MC as a vendor and because of the interchange income and how important card usage is to a financial institution, we have it listed as a Critical vendor. We get SOC 1 and SOC 2 reports from them every year.

    I hope this helps.

    Thanks!




  • 6.  RE: Does your FI consider VISA and Mastercard to be Vendors?

    This message was posted by a user wishing to remain anonymous
    Posted 13 days ago
    This message was posted by a user wishing to remain anonymous

    Visa has a trust portal within Visa Access where you can access their SOC reports, PCI, etc.  Work with your account rep at Visa to obtain access to the trust portal or you could try the enroll option on the log in screen. I've had access for several years now so I'm not exactly sure what the process is to get the access needed. It could possibly be an Admin at your organization that can get you the access needed. Yes, we consider Visa a vendor. I hope this information is helpful.




  • 7.  RE: Does your FI consider VISA and Mastercard to be Vendors?

    Posted 13 days ago

    We consider Visa a vendor.  We collect approx. 20 - 25 documents from them to include: SOCs, BCP, Recovery Exercise Report or latest Recovery Exercise Report ,  Most Recent Visa PCI Attestation of Compliance,  Latest Visa Global Key Controls Document,  AI Policies, AI Model Cards, AI Usage Policies, AI Governance Policies,  Current Certificate of Insurance (e.g. Liability, E&O, Cyber/TEO/MPL, EPL/Fiduciary, Crime), W-9



    ------------------------------
    Jenn Watts
    Vendor Management Specialist
    ------------------------------



  • 8.  RE: Does your FI consider VISA and Mastercard to be Vendors?

    This message was posted by a user wishing to remain anonymous
    Posted 13 days ago
    This message was posted by a user wishing to remain anonymous

    Yes, we consider Visa a vendor/third-party relationship.  We do have them classified as an exempt vendor, which is approved by Steering Committee annually.  Exempt vendors are typically critical/high rated vendors that we know we will not be able to obtain the usual due diligence required for that level.  We still attempt to gather what we can.  Visa does have SOC reports available through their visaonline.com site, if you have access.




  • 9.  RE: Does your FI consider VISA and Mastercard to be Vendors?

    Posted 4 days ago

    Yes, our organization has rated VISA and MasterCard as high-risk vendors as an outage would have a significant impact on our operations. We are able to retrieve due diligence annually through their Customer Trust Portals. Initially it was hard to get in contact with a representative to grant us access to the portal, but now that we received access it's a breeze to retrieve documentation. Good luck!