Third-party vendor risk management for financial institutions
Examiners changed the question. Until 2023 they asked whether a bank had a vendor management policy. Now they ask how the institution verified a partner’s ownership, financial condition and regulatory history, and the enforcement record shows what happens when the answer is a questionnaire.
This guide covers third party vendor risk management for financial institutions end to end: every US, UK and EU obligation in force in 2026, the five-stage lifecycle examiners test against, how deep due diligence has to go at each risk tier, and how to choose vendor management software for financial institutions that produces evidence, not paperwork.
Quick answer
Third-party risk management in financial services is the process banks, credit unions and fintechs use to identify, assess and monitor the risks their vendors, partners and service providers create.
In the US it is governed by the Interagency Guidance on Third-Party Relationships (OCC, Federal Reserve, FDIC, June 2023) and NYDFS Part 500. In the EU and UK, DORA and PRA SS2/21 apply.
Key takeaways
- Third-party involvement in data breaches doubled from 15% to 30% between the 2024 and 2025 Verizon Data Breach Investigations Reports. [1]
- The Interagency Guidance on Third-Party Relationships (June 6, 2023) sets one lifecycle standard for all US banking organisations: planning, due diligence, contracting, ongoing monitoring and termination. [5]
- The Federal Reserve’s June 2024 cease and desist order against Evolve Bancorp shows regulators now treat weak fintech partner oversight as unsafe and unsound banking practice. [9]
- On 18 November 2025 the European Supervisory Authorities designated the first 19 critical ICT third-party providers under DORA, placing cloud giants under direct EU oversight. [4]
- UK regulators began direct oversight of HM Treasury-designated Critical Third Parties on 13 July 2026, adding a second supervisory layer above firms’ own outsourcing controls. [12]
- Questionnaires and database checks miss undisclosed ownership links, non-English adverse media and post-onboarding deterioration; OSINT-led due diligence closes those gaps.
Contents
What is TPRM in financial services
Why it is now a board issue
US regulatory requirements ⚠
UK and EU: DORA, SS2/21, CTP
The TPRM lifecycle ★
Risk tiering and due diligence depth
Where questionnaires fall short ★
Continuous monitoring
Vendor management software ★
Common mistakes ⚠
FAQs
Who this guide serves
Three roles carry the weight of third-party risk management in financial institutions. If one of these is your desk, this page was built for the decision in front of you.
Heads of third-party and vendor risk
Running hundreds of vendors with a small team, accountable for zero exam findings. The tiering model and depth scorecard set defensible priorities.
CCOs and BSA officers at sponsor banks
Answering for fintech partner oversight after the 2024-2026 consent orders. The partnership due diligence section maps evidence to supervisory expectations.
UK and EU resilience and outsourcing leads
Holding DORA registers and SS2/21 obligations while designated critical providers move under direct regulator oversight. The comparison table shows where regimes diverge.
What is third-party risk management in financial services?
Third-party risk management (TPRM) in financial services is the discipline of identifying, assessing, monitoring and controlling the risks that vendors, fintech partners, outsourcers and other service providers introduce to a bank, credit union, insurer or investment firm. It covers operational, cyber, compliance, financial, reputational and concentration risk across the full relationship, from selection to exit.
The same program goes by several names. Third party vendor risk management for financial institutions is the phrase US regulators and buyers use most; bank vendor management and vendor risk management in financial services describe the same obligations. Whatever the label, the requirements below are identical.
The regulatory baseline differs by market but the expectation is the same: the institution owns the risk even when a third party performs the activity. US agencies restated this in the Interagency Guidance on Third-Party Relationships in June 2023, and the Financial Stability Board built the same principle into its 2023 global toolkit for financial institutions and authorities. [15] For the discipline in general, outside the financial-services context, start with the Neotas guide to third-party risk management.
How is TPRM different from vendor risk management in banking?
Vendor risk management covers suppliers under contract. TPRM in banking is wider: the Interagency Guidance applies to any business arrangement, including fintech partnerships, referral arrangements, appointed agents and services where no formal vendor contract exists. [5] A bank sponsoring a Banking-as-a-Service program carries third-party obligations for that fintech even though the fintech is a revenue partner, not a supplier.
Related: TPRM lifecycle explained | Vendor due diligence services | Third-party risk management framework
Why third-party risk is now a board issue for financial institutions
Third-party risk moved from a procurement checklist to a board agenda item because vendor failures now stop banking operations and freeze customer money. According to the Verizon 2025 Data Breach Investigations Report, the share of breaches involving a third party doubled from 15% to 30% in one year. [1] SecurityScorecard’s 2025 Global Third-Party Breach Report puts third-party involvement at 35.5% of all 2024 breaches. [2]
Four incidents between 2023 and 2024 changed how examiners, boards and courts view third-party risk management in banking. Each one traces a different failure mode.
| Incident | What happened | Failure mode | TPRM lesson |
|---|---|---|---|
| ION Cleared Derivatives, Jan 2023 | Ransomware at one market-infrastructure vendor forced dozens of banks and brokers onto manual derivatives processing. | Concentration in a single niche vendor | Map which vendors sit under critical business services and test manual fallbacks. |
| MOVEit exploitation, mid 2023 | One vulnerability in a widely used file-transfer tool exposed data at hundreds of organisations, including financial institutions, through vendors and vendors’ vendors. | Fourth-party software dependency | An annual questionnaire cannot catch a zero-day. Monitoring must run between assessments. |
| Synapse bankruptcy, Apr 2024 | A Banking-as-a-Service middleware provider collapsed, freezing end-customer funds held through partner banks while ledgers were reconciled. | Financial and operational failure of a partner, not a cyber event | Due diligence must test partner financial condition, recordkeeping and governance, not only security controls. |
| CrowdStrike outage, Jul 2024 | A defective content update disabled an estimated 8.5 million Windows devices, disrupting banking, payments and trading operations worldwide. [14] | A trusted security vendor as the single point of failure | Even top-tier vendors fail. Exit plans and impact tolerances apply to the vendors you trust most. |
Fourth-party and concentration risk
Fourth-party risk is the exposure created by your vendors’ own subcontractors and suppliers. MOVEit reached most victims this way: through a tool their vendors used, not one they bought. Concentration risk compounds the problem when many institutions depend on the same provider, which is the exact scenario the EU’s critical-provider regime and the UK Critical Third Parties regime were built for. Neotas covers the wider discipline in its guide to supply chain risk management and the companion supply chain risk assessment guide.
US regulatory requirements for third-party risk management
US third-party risk management requirements for financial institutions come from four main sources: the Interagency Guidance on Third-Party Relationships, NYDFS Part 500, the GLBA Safeguards Rule and SEC disclosure rules. The Interagency Guidance, finalised on June 6, 2023 by the OCC, Federal Reserve and FDIC, replaced OCC Bulletin 2013-29 and the agencies’ earlier separate guidance with one lifecycle standard. [5] [6]
The guidance is principles-based and risk-based. It names the due diligence factors examiners expect institutions to evaluate: strategy and goals, legal and regulatory compliance, financial condition, business experience, qualifications of key personnel, risk management, information security, reliance on subcontractors, insurance and, for relevant relationships, AML/CFT exposure. The Federal Reserve’s May 2024 publication and the OCC’s community bank guide translate those factors into worked examples for smaller institutions. [8] [7]
| Requirement | Who it applies to | Core third-party obligation | Status |
|---|---|---|---|
| Interagency Guidance (OCC 2023-17, SR 23-4, FIL-29-2023) | All OCC, Fed and FDIC supervised banking organisations | Full lifecycle risk management proportionate to the relationship’s risk and criticality | In force since June 6, 2023 [5] |
| NYDFS 23 NYCRR Part 500 | Banks, insurers and financial firms licensed in New York | Third-party service provider security policies, periodic provider assessment, MFA for remote access, 72-hour incident reporting | Second Amendment fully phased in as of November 1, 2025 [10] |
| GLBA Safeguards Rule | Financial institutions under FTC jurisdiction, with parallel banking-agency standards | Select capable service providers, bind safeguards by contract, periodically reassess | In force |
| SEC cybersecurity disclosure and Regulation S-P | Public companies; broker-dealers, investment companies and advisers | Disclose material cyber incidents including those at service providers; oversee providers handling customer information | Disclosure rule effective December 2023; S-P amendments adopted 2024 |
| Bank-fintech joint statement and RFI, July 2024 | Banks in deposit, payment and lending arrangements with fintechs | Supervisory focus on partner due diligence, recordkeeping and account reconciliation | Active exam and enforcement priority |
The enforcement signal: Evolve Bancorp, June 14, 2024
The Federal Reserve found Evolve “engaged in unsafe and unsound banking practices by failing to have in place an effective risk management framework” for its fintech partnerships, alongside AML and consumer compliance deficiencies. [9] Similar orders reached other sponsor banks through 2024 and beyond. Weak partner due diligence is now an enforcement matter, not a maturity gap.
Two practical implications follow. First, examiners test evidence, not policy documents: they ask how the institution verified a partner’s financial condition, ownership and regulatory history, which is where enhanced due diligence earns its keep. Second, the AML/CFT due diligence factor pulls TPRM into financial crime compliance territory: sanctions exposure, beneficial ownership and adverse media on the third party itself, not just its controls. A documented third-party risk management policy ties both threads to board accountability.
Neotas — Rated Chartis FCC50
Test your vendor tiering against the Interagency Guidance before your next exam does
A Neotas specialist walks your current third-party inventory against the guidance’s due diligence factors and shows where questionnaire evidence will not satisfy an examiner. 45 minutes, your data, no slideware.
Book a due diligence gap review
UK and EU requirements: DORA, SS2/21 and the Critical Third Parties regime
The EU’s Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) has applied to financial entities since 17 January 2025 and is the strictest third-party regime in force. [11] It requires an ICT third-party risk strategy, a register of information covering every ICT contract, mandatory contractual terms, incident reporting and tested exit plans. On 18 November 2025 the European Supervisory Authorities designated the first 19 critical ICT third-party providers, including the major cloud platforms, for direct EU-level oversight, with the list refreshed annually. [4]
The UK runs a parallel track. PRA Supervisory Statement SS2/21 sets outsourcing and third-party expectations for banks and insurers, including materiality assessment, due diligence, sub-outsourcing controls and exit planning. [13] On top of firm-level rules, the Bank of England, PRA and FCA began direct oversight of HM Treasury-designated Critical Third Parties on 13 July 2026. [12] Designation does not reduce a firm’s own obligations; it adds supervisory reach over the providers everyone depends on. For a requirement-by-requirement breakdown, see the Neotas guides to DORA compliance requirements and DORA compliance for third-party risk management.
| Obligation | US (Interagency Guidance) | EU (DORA) | UK (SS2/21 + CTP regime) |
|---|---|---|---|
| Scope | All third-party business arrangements, risk-based | ICT services to financial entities | Outsourcing and material third parties; designated CTPs |
| Inventory requirement | Expected in practice; no prescribed register format | Mandatory register of information, regulator-collected | Outsourcing register per SS2/21 |
| Due diligence | Named factors incl. financial condition, legal standing, subcontractors, AML/CFT | Pre-contract assessment incl. concentration and exit feasibility | Proportionate due diligence before and during the arrangement |
| Oversight of the provider itself | Bank Service Company Act examination authority | Direct ESA oversight of 19 designated CTPPs since Nov 2025 | Direct regulator oversight of designated CTPs since 13 Jul 2026 |
| Exit planning | Termination stage of the lifecycle | Documented and tested exit strategies for critical functions | Stressed exit plans for material outsourcing |
US institutions are not exempt from DORA
DORA applies to EU financial entities, so a US bank’s EU subsidiary is in scope, and US vendors serving EU financial entities inherit DORA contract terms. If your institution operates in both markets, one due diligence standard built to the stricter regime is cheaper than two.
The third-party risk management lifecycle for financial institutions
The Interagency Guidance structures third-party risk management as five stages: planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination. [5] Governance, documentation and independent review run through all five. The Neotas TPRM lifecycle guide and TPRM methodology cover each stage in depth; here is the financial-services version.
Planning
Define what the relationship does for the institution, which critical operations it touches, and the inherent risk before anyone signs. This is where the risk tier is set and where a risk management framework earns board sign-off.
Due diligence and third-party selection
Evaluate the guidance’s named factors at a depth matching the tier: financial condition, ownership, legal and regulatory history, subcontractor reliance, information security and AML/CFT exposure. Work from a structured vendor due diligence checklist and questionnaire, then verify independently.
Contract negotiation
Bind the risk decisions into terms: performance measures, audit and information rights, subcontracting limits, incident notification windows, data handling, insurance and termination triggers. DORA-scope contracts carry the mandatory Article 30 provisions on top.
Ongoing monitoring
Track performance, control health and external risk signals for the life of the relationship. The failure cases above all broke between annual reviews, which is why ongoing monitoring is the stage examiners probe hardest.
Termination
Plan the exit at onboarding: data return and destruction, service transition, and the fallback if the vendor fails suddenly rather than contractually. Synapse proved that an untested exit plan is a customer-harm event waiting for a trigger.
Risk tiering and vendor due diligence depth
Risk tiering assigns each third party a level, usually critical, high, medium or low, based on data sensitivity, operational criticality, customer impact and substitutability, and then sets the due diligence depth and monitoring cadence for that level. A bank overseeing 300 vendors cannot investigate all of them equally, and the guidance does not ask it to; it asks for depth proportionate to risk. A third-party risk assessment sets the tier; a vendor risk assessment template keeps the scoring consistent.
The practical question is what “depth” means at each tier. The Neotas Vendor Due Diligence Depth Scorecard maps five evidence levels to the guidance’s due diligence factors. The level, not the questionnaire score, is what an examiner can audit.
| Depth level | Evidence type | What it proves | Appropriate tier |
|---|---|---|---|
| L1: Self-attested | Questionnaire answers from the vendor | What the vendor says about itself | Low |
| L2: Document-verified | SOC 2, ISO 27001 certificates, financial statements, insurance | A third party audited specific controls at a point in time | Medium |
| L3: Database-screened | Sanctions, watchlist and registry checks on the entity and directors | No exact-name match on structured lists | Medium to high |
| L4: OSINT-led EDD | Open-source investigation: adverse media in any language, beneficial ownership tracing, litigation, regulatory history, analyst review | What the vendor did not disclose and databases did not index | High and critical; all fintech partners |
| L5: Continuously monitored | L4 plus alerting on new adverse media, ownership changes and risk events across monitored sources | The relationship is still safe today, not at last review | Critical and concentration-risk vendors |
Due diligence for bank-fintech partnerships
Fintech partners warrant L4 depth at minimum. The July 2024 joint statement and the Evolve order both centre on the same gaps: partner financial condition, recordkeeping, ownership and compliance capability. [9] Verifying an ultimate beneficial owner matters because a sanctioned or previously banned individual behind a partner never shows up in a SIG questionnaire, and rarely in a name-only database screen against the corporate entity.
Where questionnaires and database checks fall short
A questionnaire records what a vendor chooses to say about itself on one day. A database screen finds exact-name matches on structured lists. Both are necessary, and both share five blind spots that matter most in financial services, where the due diligence factors include reputation, ownership and AML/CFT exposure. A standard TPRM questionnaire covers controls; it does not investigate the counterparty.
Unstructured risk
Litigation records, regulatory actions and news reporting live in unstructured sources no list-based screen indexes fully.
Non-English risk
A vendor’s fraud coverage in its home-market press never reaches an English-only screen. Neotas analysts search across 200+ languages.
Ownership risk
Holding structures, aliases and nominee directors hide the people behind a vendor from entity-name screening.
Vendor-filtered risk
Questionnaires are answered by the party with the strongest incentive to present well. Self-attestation is not verification.
Post-onboarding risk
Ownership changes, financial distress and new enforcement actions arrive between annual reviews, exactly when nobody is looking.
Open-source intelligence (OSINT) closes these gaps by investigating what exists about the vendor in the public domain rather than what the vendor submits. In Neotas engagements, analyst-reviewed OSINT background checks and adverse media screening have surfaced undisclosed ownership links, director litigation histories and foreign-language press coverage that questionnaire-and-database processes had already passed. Our case studies document the pattern across financial-services engagements.
| Capability | Questionnaire | Security ratings tool | OSINT-led EDD |
|---|---|---|---|
| Security control coverage | Self-reported | Externally observed, cyber only | Contextual, via disclosures and incident history |
| Financial condition and viability | Self-reported | Not covered | Investigated from filings, records and press |
| Beneficial ownership and hidden links | Disclosed only | Not covered | Traced through registries and open sources |
| Adverse media, any language | Not covered | Not covered | Core capability, analyst reviewed |
| Change detection after onboarding | Annual at best | Continuous, cyber posture only | Continuous across integrated sources, alert driven |
| Maps to Interagency Guidance factors | Partially | Information security factor only | Financial, legal, reputational, ownership and AML/CFT factors |
Neotas — Rated Chartis FCC50
See what OSINT finds on your highest-risk vendors that questionnaires missed
Pick one critical vendor or fintech partner. Neotas runs OSINT-led enhanced due diligence across adverse media, ownership and regulatory history in 200+ languages, with analyst review and a full audit trail, and shows you the delta against your current file.
Request a due diligence demo
Continuous monitoring: what regulators expect between assessments
Regulators expect institutions to detect material change in a third party when it happens, not at the next annual review. The Interagency Guidance describes ongoing monitoring as commensurate with risk and continuing for the duration of the relationship. [5] NYDFS requires periodic reassessment of third-party providers, and DORA requires financial entities to monitor ICT third-party risk throughout the arrangement. [10] [11]
Signals worth monitoring
New adverse media, enforcement actions, ownership or leadership changes, financial distress markers, litigation, sanctions developments and negative sentiment around the vendor.
Cadence by tier
Critical vendors: continuous alerting plus annual deep review. High: continuous alerting plus review every 12 to 18 months. Medium: annual screen refresh. Low: event-driven only.
Evidence for examiners
Keep the alert, the analyst decision and the action taken in one audit trail. A monitoring program that cannot show its record does not exist at exam time.
Neotas runs this as continuous monitoring across its integrated sources, with configurable alerting, dashboards and a full audit trail, alongside online reputation monitoring for reputationally sensitive relationships. The general principles are covered in the Neotas guide to risk intelligence.
Vendor management software for financial institutions: how to choose
Vendor management software for financial institutions falls into three categories: GRC platforms that run questionnaires and workflow at scale, security ratings tools that observe cyber posture continuously, and intelligence-led platforms that investigate the counterparty itself. Most FI programs need workflow plus depth; the common buying mistake is paying for workflow and assuming depth comes with it. The Neotas TPRM software page covers the platform side; screening software and the OSINT investigation platform cover the investigation side.
What bank vendor management software must include
Bank vendor management software must produce evidence an examiner can audit against the Interagency Guidance: a complete vendor inventory with risk tiers, due diligence records against the named factors, contract obligations tracked to expiry, monitoring alerts with analyst decisions, and exit plans on file. [5] Credit unions weigh the same criteria at smaller vendor counts, with NCUA examination in place of OCC review.
Price the software on cost per assessed vendor at your required depth level, not per seat. A platform that manages 300 questionnaires cheaply but leaves fintech partners at L1 evidence costs more at exam time than it saves at renewal.
| Selection criterion | What to test | Neotas capability |
|---|---|---|
| Due diligence depth | Can it evidence the Interagency Guidance factors beyond self-attestation? | OSINT and social media intelligence with EDD built into every tier, plus premium data-source access |
| Language coverage | Does screening reach the vendor’s home-market press and records? | Search coverage across 200+ languages with a multilingual portal |
| Monitoring | Are changes detected between reviews, with alerts a human can act on? | Continuous monitoring across integrated sources, dashboards and custom alerting |
| Auditability | Can every finding and decision be shown to an examiner? | Full audit trail on every search, finding and analyst decision |
| Human review | Who separates a true adverse-media hit from a false positive? | Expert analyst team across managed and self-serve delivery models |
Common third-party risk management mistakes in financial services
These five failures recur across the programs Neotas reviews and across the public enforcement record. Each one is cheap to fix before an exam and expensive after.
1. Screening the entity but not the people behind it
A clean company name means little if a director or beneficial owner carries sanctions exposure, fraud history or a prior regulatory ban. Screen owners and key personnel, not just the legal entity.
2. Treating the SOC 2 report as due diligence
A SOC 2 covers security controls at a point in time. It says nothing about financial condition, ownership, litigation or AML/CFT exposure, which are named due diligence factors in the Interagency Guidance.
3. Tiering by spend instead of risk
A $30,000 middleware provider can freeze customer funds; a $3M facilities contract cannot. Tier by data access, customer impact and substitutability, not invoice size.
4. Letting monitoring stop at cyber posture
Synapse was not a cyber event. Financial deterioration, ownership changes and governance failures need monitoring too, and none of them appear on a security rating.
5. Writing exit plans nobody has tested
An exit plan that has never been walked through fails on the day it is needed. Test the critical-vendor exits annually, including the sudden-failure scenario, not just the orderly one.
Neotas — Rated Chartis FCC50
Build a third-party risk program that stands up to examiners, in the US, UK and EU
Neotas combines OSINT-led enhanced due diligence, adverse media and beneficial ownership investigation with continuous monitoring, delivered with analyst review, a full audit trail and coverage across 200+ languages.
Schedule a platform demo
Related reading
Third-Party Risk Management (TPRM): The Complete Guide
The Neotas TPRM hub covers what third-party risk management is, the risk categories it addresses and how organisations across sectors structure a program, beyond the financial-services focus of this page.
The TPRM Lifecycle: Stages, Process and Assessment
A stage-by-stage walkthrough of the third-party risk management lifecycle, from planning and due diligence through ongoing monitoring and termination, with assessment methods for each stage.
Third-Party Risk Management Framework
How to build a third-party risk management framework: governance structure, risk tiering methodology, due diligence depth by tier and the documentation that holds it together.
Enhanced Due Diligence (EDD) Services
What enhanced due diligence involves, when a third party or partner warrants it, and how OSINT-led EDD investigates ownership, litigation, regulatory history and adverse media beyond database screening.
Adverse Media Screening
How adverse media screening works, why negative news is a leading indicator of vendor and partner risk, and how analyst-reviewed screening separates true risk signals from false positives.
DORA Compliance for Third-Party Risk Management
DORA’s ICT third-party risk requirements in detail: the register of information, mandatory contract terms, exit strategies and what the critical ICT third-party provider regime means for financial entities.
Vendor Due Diligence Checklist and Questionnaire
A working vendor due diligence checklist and questionnaire structure: the questions to ask, the documents to collect and the independent verification that turns answers into evidence.
Healthcare Third-Party Risk Management
The healthcare counterpart to this guide: HIPAA business associate obligations, vendor risk in clinical and payer settings, and how due diligence depth applies to healthcare third parties.
Third-party risk management in financial services: FAQs
What is third-party risk management in the banking sector?▼
What are the 5 phases of third-party risk management?▼
What are the best vendor risk management platforms for financial institutions?▼
What should bank vendor management software include?▼
What does the Interagency Guidance on Third-Party Relationships require?▼
Does DORA apply to US financial institutions?▼
How often should banks and credit unions reassess third-party vendors?▼
What is the difference between third-party risk management and vendor risk management in financial services?▼
What is fourth-party risk in financial services?▼
What is a critical third party under the UK CTP regime?▼
How does NYDFS Part 500 affect third-party risk management?▼
What should due diligence on a bank-fintech partnership include?▼
What is OSINT-enhanced vendor due diligence for financial institutions?▼
How do financial institutions manage concentration risk from cloud providers?▼
What triggers enhanced due diligence on a third party?▼
Which frameworks support third-party risk management in financial services?▼
What is the $3000 rule in banking?▼
Third-party vendor risk management for financial institutions: the bottom line
Third-party vendor risk management for financial institutions is now judged on evidence alongside the policy documents. The Interagency Guidance names the due diligence factors, DORA and the UK CTP regime add register and oversight obligations, and the 2024-2026 enforcement record shows the cost of relying on what vendors say about themselves.
The institutions that pass exams cleanly run the same play: tier every relationship, match due diligence depth to the tier, verify ownership and adverse media independently through enhanced due diligence, and monitor for change between reviews.
If your current vendor files stop at questionnaires and certificates, request a Neotas demo and see the delta on one of your own critical vendors.











