FaSQUAL: The BSIA-led Vetting Passport for the UK Security Industry Powered by Neotas Read More →
Generate AI-Powered Audit-Ready Due Diligence Reports instantly. Learn More →
Third-party vendor risk management for financial institutions

Third-party vendor risk management for financial institutions

Examiners changed the question. Until 2023 they asked whether a bank had a vendor management policy. Now they ask how the institution verified a partner’s ownership, financial condition and regulatory history, and the enforcement record shows what happens when the answer is a questionnaire.

This guide covers third party vendor risk management for financial institutions end to end: every US, UK and EU obligation in force in 2026, the five-stage lifecycle examiners test against, how deep due diligence has to go at each risk tier, and how to choose vendor management software for financial institutions that produces evidence, not paperwork.

Quick answer

Third-party risk management in financial services is the process banks, credit unions and fintechs use to identify, assess and monitor the risks their vendors, partners and service providers create.

In the US it is governed by the Interagency Guidance on Third-Party Relationships (OCC, Federal Reserve, FDIC, June 2023) and NYDFS Part 500. In the EU and UK, DORA and PRA SS2/21 apply.

Key takeaways

  • Third-party involvement in data breaches doubled from 15% to 30% between the 2024 and 2025 Verizon Data Breach Investigations Reports. [1]
  • The Interagency Guidance on Third-Party Relationships (June 6, 2023) sets one lifecycle standard for all US banking organisations: planning, due diligence, contracting, ongoing monitoring and termination. [5]
  • The Federal Reserve’s June 2024 cease and desist order against Evolve Bancorp shows regulators now treat weak fintech partner oversight as unsafe and unsound banking practice. [9]
  • On 18 November 2025 the European Supervisory Authorities designated the first 19 critical ICT third-party providers under DORA, placing cloud giants under direct EU oversight. [4]
  • UK regulators began direct oversight of HM Treasury-designated Critical Third Parties on 13 July 2026, adding a second supervisory layer above firms’ own outsourcing controls. [12]
  • Questionnaires and database checks miss undisclosed ownership links, non-English adverse media and post-onboarding deterioration; OSINT-led due diligence closes those gaps.

Who this guide serves

Three roles carry the weight of third-party risk management in financial institutions. If one of these is your desk, this page was built for the decision in front of you.

Heads of third-party and vendor risk

Running hundreds of vendors with a small team, accountable for zero exam findings. The tiering model and depth scorecard set defensible priorities.

CCOs and BSA officers at sponsor banks

Answering for fintech partner oversight after the 2024-2026 consent orders. The partnership due diligence section maps evidence to supervisory expectations.

UK and EU resilience and outsourcing leads

Holding DORA registers and SS2/21 obligations while designated critical providers move under direct regulator oversight. The comparison table shows where regimes diverge.

What is third-party risk management in financial services?

Third-party risk management (TPRM) in financial services is the discipline of identifying, assessing, monitoring and controlling the risks that vendors, fintech partners, outsourcers and other service providers introduce to a bank, credit union, insurer or investment firm. It covers operational, cyber, compliance, financial, reputational and concentration risk across the full relationship, from selection to exit.

The same program goes by several names. Third party vendor risk management for financial institutions is the phrase US regulators and buyers use most; bank vendor management and vendor risk management in financial services describe the same obligations. Whatever the label, the requirements below are identical.

The regulatory baseline differs by market but the expectation is the same: the institution owns the risk even when a third party performs the activity. US agencies restated this in the Interagency Guidance on Third-Party Relationships in June 2023, and the Financial Stability Board built the same principle into its 2023 global toolkit for financial institutions and authorities. [15] For the discipline in general, outside the financial-services context, start with the Neotas guide to third-party risk management.

How is TPRM different from vendor risk management in banking?

Vendor risk management covers suppliers under contract. TPRM in banking is wider: the Interagency Guidance applies to any business arrangement, including fintech partnerships, referral arrangements, appointed agents and services where no formal vendor contract exists. [5] A bank sponsoring a Banking-as-a-Service program carries third-party obligations for that fintech even though the fintech is a revenue partner, not a supplier.

Related: TPRM lifecycle explained | Vendor due diligence services | Third-party risk management framework

Why third-party risk is now a board issue for financial institutions

Third-party risk moved from a procurement checklist to a board agenda item because vendor failures now stop banking operations and freeze customer money. According to the Verizon 2025 Data Breach Investigations Report, the share of breaches involving a third party doubled from 15% to 30% in one year. [1] SecurityScorecard’s 2025 Global Third-Party Breach Report puts third-party involvement at 35.5% of all 2024 breaches. [2]

Four incidents between 2023 and 2024 changed how examiners, boards and courts view third-party risk management in banking. Each one traces a different failure mode.

Incident What happened Failure mode TPRM lesson
ION Cleared Derivatives, Jan 2023 Ransomware at one market-infrastructure vendor forced dozens of banks and brokers onto manual derivatives processing. Concentration in a single niche vendor Map which vendors sit under critical business services and test manual fallbacks.
MOVEit exploitation, mid 2023 One vulnerability in a widely used file-transfer tool exposed data at hundreds of organisations, including financial institutions, through vendors and vendors’ vendors. Fourth-party software dependency An annual questionnaire cannot catch a zero-day. Monitoring must run between assessments.
Synapse bankruptcy, Apr 2024 A Banking-as-a-Service middleware provider collapsed, freezing end-customer funds held through partner banks while ledgers were reconciled. Financial and operational failure of a partner, not a cyber event Due diligence must test partner financial condition, recordkeeping and governance, not only security controls.
CrowdStrike outage, Jul 2024 A defective content update disabled an estimated 8.5 million Windows devices, disrupting banking, payments and trading operations worldwide. [14] A trusted security vendor as the single point of failure Even top-tier vendors fail. Exit plans and impact tolerances apply to the vendors you trust most.

Fourth-party and concentration risk

Fourth-party risk is the exposure created by your vendors’ own subcontractors and suppliers. MOVEit reached most victims this way: through a tool their vendors used, not one they bought. Concentration risk compounds the problem when many institutions depend on the same provider, which is the exact scenario the EU’s critical-provider regime and the UK Critical Third Parties regime were built for. Neotas covers the wider discipline in its guide to supply chain risk management and the companion supply chain risk assessment guide.

US regulatory requirements for third-party risk management

US third-party risk management requirements for financial institutions come from four main sources: the Interagency Guidance on Third-Party Relationships, NYDFS Part 500, the GLBA Safeguards Rule and SEC disclosure rules. The Interagency Guidance, finalised on June 6, 2023 by the OCC, Federal Reserve and FDIC, replaced OCC Bulletin 2013-29 and the agencies’ earlier separate guidance with one lifecycle standard. [5] [6]

The guidance is principles-based and risk-based. It names the due diligence factors examiners expect institutions to evaluate: strategy and goals, legal and regulatory compliance, financial condition, business experience, qualifications of key personnel, risk management, information security, reliance on subcontractors, insurance and, for relevant relationships, AML/CFT exposure. The Federal Reserve’s May 2024 publication and the OCC’s community bank guide translate those factors into worked examples for smaller institutions. [8] [7]

Requirement Who it applies to Core third-party obligation Status
Interagency Guidance (OCC 2023-17, SR 23-4, FIL-29-2023) All OCC, Fed and FDIC supervised banking organisations Full lifecycle risk management proportionate to the relationship’s risk and criticality In force since June 6, 2023 [5]
NYDFS 23 NYCRR Part 500 Banks, insurers and financial firms licensed in New York Third-party service provider security policies, periodic provider assessment, MFA for remote access, 72-hour incident reporting Second Amendment fully phased in as of November 1, 2025 [10]
GLBA Safeguards Rule Financial institutions under FTC jurisdiction, with parallel banking-agency standards Select capable service providers, bind safeguards by contract, periodically reassess In force
SEC cybersecurity disclosure and Regulation S-P Public companies; broker-dealers, investment companies and advisers Disclose material cyber incidents including those at service providers; oversee providers handling customer information Disclosure rule effective December 2023; S-P amendments adopted 2024
Bank-fintech joint statement and RFI, July 2024 Banks in deposit, payment and lending arrangements with fintechs Supervisory focus on partner due diligence, recordkeeping and account reconciliation Active exam and enforcement priority

The enforcement signal: Evolve Bancorp, June 14, 2024

The Federal Reserve found Evolve “engaged in unsafe and unsound banking practices by failing to have in place an effective risk management framework” for its fintech partnerships, alongside AML and consumer compliance deficiencies. [9] Similar orders reached other sponsor banks through 2024 and beyond. Weak partner due diligence is now an enforcement matter, not a maturity gap.

Two practical implications follow. First, examiners test evidence, not policy documents: they ask how the institution verified a partner’s financial condition, ownership and regulatory history, which is where enhanced due diligence earns its keep. Second, the AML/CFT due diligence factor pulls TPRM into financial crime compliance territory: sanctions exposure, beneficial ownership and adverse media on the third party itself, not just its controls. A documented third-party risk management policy ties both threads to board accountability.

Neotas — Rated Chartis FCC50

Test your vendor tiering against the Interagency Guidance before your next exam does

A Neotas specialist walks your current third-party inventory against the guidance’s due diligence factors and shows where questionnaire evidence will not satisfy an examiner. 45 minutes, your data, no slideware.

Book a due diligence gap review

UK and EU requirements: DORA, SS2/21 and the Critical Third Parties regime

The EU’s Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) has applied to financial entities since 17 January 2025 and is the strictest third-party regime in force. [11] It requires an ICT third-party risk strategy, a register of information covering every ICT contract, mandatory contractual terms, incident reporting and tested exit plans. On 18 November 2025 the European Supervisory Authorities designated the first 19 critical ICT third-party providers, including the major cloud platforms, for direct EU-level oversight, with the list refreshed annually. [4]

The UK runs a parallel track. PRA Supervisory Statement SS2/21 sets outsourcing and third-party expectations for banks and insurers, including materiality assessment, due diligence, sub-outsourcing controls and exit planning. [13] On top of firm-level rules, the Bank of England, PRA and FCA began direct oversight of HM Treasury-designated Critical Third Parties on 13 July 2026. [12] Designation does not reduce a firm’s own obligations; it adds supervisory reach over the providers everyone depends on. For a requirement-by-requirement breakdown, see the Neotas guides to DORA compliance requirements and DORA compliance for third-party risk management.

Obligation US (Interagency Guidance) EU (DORA) UK (SS2/21 + CTP regime)
Scope All third-party business arrangements, risk-based ICT services to financial entities Outsourcing and material third parties; designated CTPs
Inventory requirement Expected in practice; no prescribed register format Mandatory register of information, regulator-collected Outsourcing register per SS2/21
Due diligence Named factors incl. financial condition, legal standing, subcontractors, AML/CFT Pre-contract assessment incl. concentration and exit feasibility Proportionate due diligence before and during the arrangement
Oversight of the provider itself Bank Service Company Act examination authority Direct ESA oversight of 19 designated CTPPs since Nov 2025 Direct regulator oversight of designated CTPs since 13 Jul 2026
Exit planning Termination stage of the lifecycle Documented and tested exit strategies for critical functions Stressed exit plans for material outsourcing

US institutions are not exempt from DORA

DORA applies to EU financial entities, so a US bank’s EU subsidiary is in scope, and US vendors serving EU financial entities inherit DORA contract terms. If your institution operates in both markets, one due diligence standard built to the stricter regime is cheaper than two.

The third-party risk management lifecycle for financial institutions

The Interagency Guidance structures third-party risk management as five stages: planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination. [5] Governance, documentation and independent review run through all five. The Neotas TPRM lifecycle guide and TPRM methodology cover each stage in depth; here is the financial-services version.

1

Planning

Define what the relationship does for the institution, which critical operations it touches, and the inherent risk before anyone signs. This is where the risk tier is set and where a risk management framework earns board sign-off.

2

Due diligence and third-party selection

Evaluate the guidance’s named factors at a depth matching the tier: financial condition, ownership, legal and regulatory history, subcontractor reliance, information security and AML/CFT exposure. Work from a structured vendor due diligence checklist and questionnaire, then verify independently.

3

Contract negotiation

Bind the risk decisions into terms: performance measures, audit and information rights, subcontracting limits, incident notification windows, data handling, insurance and termination triggers. DORA-scope contracts carry the mandatory Article 30 provisions on top.

4

Ongoing monitoring

Track performance, control health and external risk signals for the life of the relationship. The failure cases above all broke between annual reviews, which is why ongoing monitoring is the stage examiners probe hardest.

5

Termination

Plan the exit at onboarding: data return and destruction, service transition, and the fallback if the vendor fails suddenly rather than contractually. Synapse proved that an untested exit plan is a customer-harm event waiting for a trigger.

Risk tiering and vendor due diligence depth

Risk tiering assigns each third party a level, usually critical, high, medium or low, based on data sensitivity, operational criticality, customer impact and substitutability, and then sets the due diligence depth and monitoring cadence for that level. A bank overseeing 300 vendors cannot investigate all of them equally, and the guidance does not ask it to; it asks for depth proportionate to risk. A third-party risk assessment sets the tier; a vendor risk assessment template keeps the scoring consistent.

The practical question is what “depth” means at each tier. The Neotas Vendor Due Diligence Depth Scorecard maps five evidence levels to the guidance’s due diligence factors. The level, not the questionnaire score, is what an examiner can audit.

Depth level Evidence type What it proves Appropriate tier
L1: Self-attested Questionnaire answers from the vendor What the vendor says about itself Low
L2: Document-verified SOC 2, ISO 27001 certificates, financial statements, insurance A third party audited specific controls at a point in time Medium
L3: Database-screened Sanctions, watchlist and registry checks on the entity and directors No exact-name match on structured lists Medium to high
L4: OSINT-led EDD Open-source investigation: adverse media in any language, beneficial ownership tracing, litigation, regulatory history, analyst review What the vendor did not disclose and databases did not index High and critical; all fintech partners
L5: Continuously monitored L4 plus alerting on new adverse media, ownership changes and risk events across monitored sources The relationship is still safe today, not at last review Critical and concentration-risk vendors

Due diligence for bank-fintech partnerships

Fintech partners warrant L4 depth at minimum. The July 2024 joint statement and the Evolve order both centre on the same gaps: partner financial condition, recordkeeping, ownership and compliance capability. [9] Verifying an ultimate beneficial owner matters because a sanctioned or previously banned individual behind a partner never shows up in a SIG questionnaire, and rarely in a name-only database screen against the corporate entity.

Where questionnaires and database checks fall short

A questionnaire records what a vendor chooses to say about itself on one day. A database screen finds exact-name matches on structured lists. Both are necessary, and both share five blind spots that matter most in financial services, where the due diligence factors include reputation, ownership and AML/CFT exposure. A standard TPRM questionnaire covers controls; it does not investigate the counterparty.

Unstructured risk

Litigation records, regulatory actions and news reporting live in unstructured sources no list-based screen indexes fully.

Non-English risk

A vendor’s fraud coverage in its home-market press never reaches an English-only screen. Neotas analysts search across 200+ languages.

Ownership risk

Holding structures, aliases and nominee directors hide the people behind a vendor from entity-name screening.

Vendor-filtered risk

Questionnaires are answered by the party with the strongest incentive to present well. Self-attestation is not verification.

Post-onboarding risk

Ownership changes, financial distress and new enforcement actions arrive between annual reviews, exactly when nobody is looking.

Open-source intelligence (OSINT) closes these gaps by investigating what exists about the vendor in the public domain rather than what the vendor submits. In Neotas engagements, analyst-reviewed OSINT background checks and adverse media screening have surfaced undisclosed ownership links, director litigation histories and foreign-language press coverage that questionnaire-and-database processes had already passed. Our case studies document the pattern across financial-services engagements.

Capability Questionnaire Security ratings tool OSINT-led EDD
Security control coverage Self-reported Externally observed, cyber only Contextual, via disclosures and incident history
Financial condition and viability Self-reported Not covered Investigated from filings, records and press
Beneficial ownership and hidden links Disclosed only Not covered Traced through registries and open sources
Adverse media, any language Not covered Not covered Core capability, analyst reviewed
Change detection after onboarding Annual at best Continuous, cyber posture only Continuous across integrated sources, alert driven
Maps to Interagency Guidance factors Partially Information security factor only Financial, legal, reputational, ownership and AML/CFT factors

Neotas — Rated Chartis FCC50

See what OSINT finds on your highest-risk vendors that questionnaires missed

Pick one critical vendor or fintech partner. Neotas runs OSINT-led enhanced due diligence across adverse media, ownership and regulatory history in 200+ languages, with analyst review and a full audit trail, and shows you the delta against your current file.

Request a due diligence demo

Continuous monitoring: what regulators expect between assessments

Regulators expect institutions to detect material change in a third party when it happens, not at the next annual review. The Interagency Guidance describes ongoing monitoring as commensurate with risk and continuing for the duration of the relationship. [5] NYDFS requires periodic reassessment of third-party providers, and DORA requires financial entities to monitor ICT third-party risk throughout the arrangement. [10] [11]

Signals worth monitoring

New adverse media, enforcement actions, ownership or leadership changes, financial distress markers, litigation, sanctions developments and negative sentiment around the vendor.

Cadence by tier

Critical vendors: continuous alerting plus annual deep review. High: continuous alerting plus review every 12 to 18 months. Medium: annual screen refresh. Low: event-driven only.

Evidence for examiners

Keep the alert, the analyst decision and the action taken in one audit trail. A monitoring program that cannot show its record does not exist at exam time.

Neotas runs this as continuous monitoring across its integrated sources, with configurable alerting, dashboards and a full audit trail, alongside online reputation monitoring for reputationally sensitive relationships. The general principles are covered in the Neotas guide to risk intelligence.

Vendor management software for financial institutions: how to choose

Vendor management software for financial institutions falls into three categories: GRC platforms that run questionnaires and workflow at scale, security ratings tools that observe cyber posture continuously, and intelligence-led platforms that investigate the counterparty itself. Most FI programs need workflow plus depth; the common buying mistake is paying for workflow and assuming depth comes with it. The Neotas TPRM software page covers the platform side; screening software and the OSINT investigation platform cover the investigation side.

What bank vendor management software must include

Bank vendor management software must produce evidence an examiner can audit against the Interagency Guidance: a complete vendor inventory with risk tiers, due diligence records against the named factors, contract obligations tracked to expiry, monitoring alerts with analyst decisions, and exit plans on file. [5] Credit unions weigh the same criteria at smaller vendor counts, with NCUA examination in place of OCC review.

Price the software on cost per assessed vendor at your required depth level, not per seat. A platform that manages 300 questionnaires cheaply but leaves fintech partners at L1 evidence costs more at exam time than it saves at renewal.

Selection criterion What to test Neotas capability
Due diligence depth Can it evidence the Interagency Guidance factors beyond self-attestation? OSINT and social media intelligence with EDD built into every tier, plus premium data-source access
Language coverage Does screening reach the vendor’s home-market press and records? Search coverage across 200+ languages with a multilingual portal
Monitoring Are changes detected between reviews, with alerts a human can act on? Continuous monitoring across integrated sources, dashboards and custom alerting
Auditability Can every finding and decision be shown to an examiner? Full audit trail on every search, finding and analyst decision
Human review Who separates a true adverse-media hit from a false positive? Expert analyst team across managed and self-serve delivery models

Common third-party risk management mistakes in financial services

These five failures recur across the programs Neotas reviews and across the public enforcement record. Each one is cheap to fix before an exam and expensive after.

1. Screening the entity but not the people behind it

A clean company name means little if a director or beneficial owner carries sanctions exposure, fraud history or a prior regulatory ban. Screen owners and key personnel, not just the legal entity.

2. Treating the SOC 2 report as due diligence

A SOC 2 covers security controls at a point in time. It says nothing about financial condition, ownership, litigation or AML/CFT exposure, which are named due diligence factors in the Interagency Guidance.

3. Tiering by spend instead of risk

A $30,000 middleware provider can freeze customer funds; a $3M facilities contract cannot. Tier by data access, customer impact and substitutability, not invoice size.

4. Letting monitoring stop at cyber posture

Synapse was not a cyber event. Financial deterioration, ownership changes and governance failures need monitoring too, and none of them appear on a security rating.

5. Writing exit plans nobody has tested

An exit plan that has never been walked through fails on the day it is needed. Test the critical-vendor exits annually, including the sudden-failure scenario, not just the orderly one.

Neotas — Rated Chartis FCC50

Build a third-party risk program that stands up to examiners, in the US, UK and EU

Neotas combines OSINT-led enhanced due diligence, adverse media and beneficial ownership investigation with continuous monitoring, delivered with analyst review, a full audit trail and coverage across 200+ languages.

Schedule a platform demo

Third-Party Risk Management (TPRM): The Complete Guide

The Neotas TPRM hub covers what third-party risk management is, the risk categories it addresses and how organisations across sectors structure a program, beyond the financial-services focus of this page.

The TPRM Lifecycle: Stages, Process and Assessment

A stage-by-stage walkthrough of the third-party risk management lifecycle, from planning and due diligence through ongoing monitoring and termination, with assessment methods for each stage.

Third-Party Risk Management Framework

How to build a third-party risk management framework: governance structure, risk tiering methodology, due diligence depth by tier and the documentation that holds it together.

Enhanced Due Diligence (EDD) Services

What enhanced due diligence involves, when a third party or partner warrants it, and how OSINT-led EDD investigates ownership, litigation, regulatory history and adverse media beyond database screening.

Adverse Media Screening

How adverse media screening works, why negative news is a leading indicator of vendor and partner risk, and how analyst-reviewed screening separates true risk signals from false positives.

DORA Compliance for Third-Party Risk Management

DORA’s ICT third-party risk requirements in detail: the register of information, mandatory contract terms, exit strategies and what the critical ICT third-party provider regime means for financial entities.

Vendor Due Diligence Checklist and Questionnaire

A working vendor due diligence checklist and questionnaire structure: the questions to ask, the documents to collect and the independent verification that turns answers into evidence.

Healthcare Third-Party Risk Management

The healthcare counterpart to this guide: HIPAA business associate obligations, vendor risk in clinical and payer settings, and how due diligence depth applies to healthcare third parties.

Third-party risk management in financial services: FAQs

What is third-party risk management in the banking sector?
Third-party risk management in the banking sector is the process of identifying, assessing and monitoring the risks that vendors, fintech partners and service providers create for a bank. US banking regulators set the standard in the Interagency Guidance on Third-Party Relationships (June 2023), which expects risk management across planning, due diligence, contracting, ongoing monitoring and termination. The bank remains accountable for the activity even when a third party performs it. The full discipline is covered in the Neotas guide to third-party risk management.
What are the 5 phases of third-party risk management?
The 5 phases of third-party risk management, as set out in the Interagency Guidance, are: planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination. Governance, documentation and independent review apply across all five phases. Each phase scales with the risk tier of the relationship, so a critical vendor gets deeper due diligence and tighter monitoring than a low-risk supplier. The Neotas TPRM lifecycle guide walks through each phase with assessment methods.
What are the best vendor risk management platforms for financial institutions?
The best vendor management software for financial institutions depends on the dominant gap: GRC platforms handle questionnaire workflow, security ratings tools observe cyber posture, and intelligence-led providers such as Neotas investigate the counterparty through OSINT, adverse media and beneficial ownership research. Evaluate depth of due diligence evidence, language coverage, monitoring between reviews, auditability and analyst review. The Neotas TPRM software page covers selection criteria in detail.
What should bank vendor management software include?
Bank vendor management software should include a tiered vendor inventory, due diligence records mapped to the Interagency Guidance factors, contract and obligation tracking, monitoring alerts with a documented analyst decision on each, and exit plans for critical vendors, all held in an audit trail an examiner can walk through. Screening depth matters as much as workflow: software that stops at questionnaires leaves financial condition, ownership and adverse media unverified. Selection criteria are compared in the Neotas guide to TPRM software.
What does the Interagency Guidance on Third-Party Relationships require?
The Interagency Guidance requires banking organisations to manage third-party relationships through a full lifecycle proportionate to risk and criticality. Due diligence must evaluate named factors including financial condition, legal and regulatory compliance, ownership, subcontractor reliance, information security and AML/CFT exposure. It applies to all business arrangements, not only contracted vendors, which pulls fintech partnerships into scope. It replaced OCC Bulletin 2013-29 and prior agency guidance on June 6, 2023. A documented third-party risk management policy is how institutions evidence it.
Does DORA apply to US financial institutions?
DORA applies to EU financial entities, so a US institution is in scope through its EU subsidiaries and branches, and US vendors serving EU financial entities inherit DORA’s contractual requirements. A US bank with EU operations needs the register of information, mandatory contract terms and tested exit strategies for those entities. Many multi-market institutions run one third-party risk management standard built to DORA because it is stricter than the US baseline. See the Neotas guide to DORA compliance requirements.
How often should banks and credit unions reassess third-party vendors?
Banks and credit unions should reassess third-party vendors on a risk-based cadence: continuous monitoring plus annual deep review for critical vendors, reviews every 12 to 18 months for high-risk vendors, annual screening refresh for medium risk, and event-driven review for low risk. No US regulation fixes a single frequency; the Interagency Guidance expects monitoring commensurate with risk, and NYDFS Part 500 requires periodic third-party provider assessment. The important shift is from calendar-driven reviews to change detection through ongoing monitoring.
What is the difference between third-party risk management and vendor risk management in financial services?
In financial services, vendor risk management covers suppliers under contract; third-party risk management covers every external business arrangement, including fintech partners, agents, referral relationships and service providers with no vendor contract. In financial services the distinction matters because the Interagency Guidance uses the wider definition, so a Banking-as-a-Service partner is a third party even though it is a revenue relationship. A third-party risk assessment applies the same rigour to both.
What is fourth-party risk in financial services?
Fourth-party risk is the exposure created by your third parties’ own subcontractors, software and suppliers. The MOVEit exploitation reached most financial institutions this way, through a file-transfer tool their vendors used rather than one they bought. The Interagency Guidance names reliance on subcontractors as a due diligence factor, and DORA requires visibility into ICT subcontracting chains. Managing it starts with mapping which vendors support critical operations, covered in the Neotas guide to supply chain risk management.
What is a critical third party under the UK CTP regime?
A critical third party (CTP) is a service provider designated by HM Treasury because its failure could threaten UK financial stability, typically a major cloud or technology provider serving many firms at once. The Bank of England, PRA and FCA began direct oversight of the first designated CTPs on 13 July 2026. Designation adds regulator oversight of the provider; it does not reduce a firm’s own outsourcing and third-party risk management obligations under PRA SS2/21, which still require due diligence, monitoring and exit plans.
How does NYDFS Part 500 affect third-party risk management?
NYDFS Part 500 requires covered New York financial institutions to maintain third-party service provider security policies, assess providers periodically, apply multi-factor authentication to remote access including third-party applications, and report cybersecurity incidents within 72 hours. The Second Amendment’s requirements phased in fully by November 1, 2025. NYDFS holds the covered entity accountable for vendor cyber risk; compliance cannot be delegated to the provider. Provider assessment is where a vendor risk assessment template keeps evidence consistent.
What should due diligence on a bank-fintech partnership include?
Due diligence on a bank-fintech partnership should cover the partner’s financial condition and funding runway, beneficial ownership, leadership backgrounds, regulatory and litigation history, compliance capability, recordkeeping and reconciliation practices, and adverse media in every relevant language. The 2024-2026 enforcement record, starting with the Federal Reserve’s Evolve order, shows regulators test exactly these points. Questionnaires alone cannot verify them, which is why sponsor banks pair them with OSINT-led enhanced due diligence.
What is OSINT-enhanced vendor due diligence for financial institutions?
OSINT-enhanced vendor due diligence for financial institutions uses open-source intelligence to investigate a vendor independently of what the vendor discloses: adverse media in any language, beneficial ownership tracing through registries, litigation and regulatory history, and risk signals across public and premium sources, reviewed by analysts. It closes the gaps that questionnaires and exact-name database screens leave open, particularly hidden ownership and non-English coverage. Neotas explains the method in its guides to OSINT background checks and open source intelligence.
How do financial institutions manage concentration risk from cloud providers?
Financial institutions manage cloud concentration risk by mapping which critical business services depend on which provider, setting impact tolerances for disruption, negotiating exit and portability terms, and testing failover and exit plans. Regulators now share the burden: the ESAs directly oversee 19 designated critical ICT providers under DORA, and UK regulators oversee designated Critical Third Parties. Neither regime removes the institution’s duty to plan for provider failure; CrowdStrike showed that even trusted providers can take down operations in hours.
What triggers enhanced due diligence on a third party?
Enhanced due diligence on a third party is triggered by a critical or high risk tier, access to customer data or funds, a fintech partnership, foreign ownership or operations, adverse media hits, complex ownership structures, or any finding a standard screen cannot resolve. It is also the right response to red flags mid-relationship, such as leadership churn or new enforcement activity. The Neotas enhanced due diligence checklist lists the triggers and the evidence each one calls for.
Which frameworks support third-party risk management in financial services?
The frameworks most used for third-party risk management in financial services are NIST CSF 2.0 and NIST SP 800-161 for supply chain security, ISO/IEC 27001 and 27036 for information security in supplier relationships, the Shared Assessments SIG questionnaire for standardised information gathering, and the FFIEC IT Examination Handbook for US bank examinations. Frameworks structure the questions; regulation defines the obligation. Building them into one operating model is covered in the Neotas third-party risk management framework guide.
What is the $3000 rule in banking?
The $3,000 rule is a Bank Secrecy Act recordkeeping requirement: financial institutions must record and retain identifying information for purchases of monetary instruments, and for funds transfers, of $3,000 or more. It is a customer-side AML control rather than a third-party risk rule, but it illustrates the recordkeeping standard regulators expect banks to hold their fintech partners to as well, a point made sharply by the Synapse ledger failures. Related AML obligations are covered in the Neotas guide to anti-money laundering regulations.

Third-party vendor risk management for financial institutions: the bottom line

Third-party vendor risk management for financial institutions is now judged on evidence alongside the policy documents. The Interagency Guidance names the due diligence factors, DORA and the UK CTP regime add register and oversight obligations, and the 2024-2026 enforcement record shows the cost of relying on what vendors say about themselves.

The institutions that pass exams cleanly run the same play: tier every relationship, match due diligence depth to the tier, verify ownership and adverse media independently through enhanced due diligence, and monitor for change between reviews.

If your current vendor files stop at questionnaires and certificates, request a Neotas demo and see the delta on one of your own critical vendors.

Share:

Picture of Neotas Enhanced Due Diligence

Neotas Enhanced Due Diligence

Neotas Enhanced Due Diligence covers 600Bn+ Archived web pages, 1.8Bn+ court records, 198M+ Corporate records, Global Social Media platforms, and more than 40,000 Media sources from over 100 countries to help you screen & manage risks.

A detailed guide to TPRM and a downloadable checklist to implement the TPRM Framework in 2026

Book a Demo

Explore Neotas Enhanced Due Diligence