My financial institution is considering entering into a relationship where we would refer our customers to a student loan organization website (linked from our corporate website) and the customer would enter their own confidential information into that 3rd party site and engage in a lending relationship with the student loan organization. Our financial institution would not be sharing any information directly.
For third parties where we share a customer's confidential information, we typically look at assessing the vendor's information security (SOC audit, policies, questionnaire), their financial condition as well as their compliance to things such as UDAAP and ID Theft red flags. However, in this case, we are referring the customer to an outside organization where they (the customer) enters into an agreement with that organization. My question is what type of due diligence should we require from the student loan organization in this type of relationship?