Vendor Management is Business Management
Vendor Management Is Business Management
On September 11, the NCUA, Federal Reserve Board, FDIC, and OCC issued proposed interagency guidance on third-party risk management. The proposal reinforces an important point: vendor management is not one-size-fits-all, and having a system in place does not necessarily mean a credit union has effective vendor oversight. The expectation is that each credit union understands the risks its individual vendor relationships create and manages those relationships accordingly.
For most credit unions, vendors are not on the sidelines of the business—they are part of the business. Core processors, digital banking providers, payment networks, loan-servicing vendors, fraud tools, cybersecurity providers, card programs, insurance partners, and member-communication platforms all help deliver the products and services members use every day. If those relationships are not working well, the credit union’s ability to serve members is affected.
That is why vendor management should be treated as a business-management responsibility, not just an examination requirement. The question is not simply whether the credit union has the right documents in a system. It is whether management understands who its critical vendors are, what could happen if a vendor fails to perform, what data and services are affected, and how the credit union will respond when there is a disruption, breach, or other issue. The TruStage cybersecurity incident is a recent example of how quickly a problem at a third party can become a member-service, operational, information-security, and reputational issue for the credit unions that rely on that provider.
Examiners are increasingly asking questions that reflect this reality. They want to see that the credit union can explain why a vendor is rated the way it is, who owns the relationship, what management concluded from due diligence, how performance is tracked, what issues remain open, and what contingency plans exist. A vendor-management platform can help keep the work organized, but the system is only as good as the people using it and the oversight behind it.
Bottom Line
Effective vendor management requires more than a system and a document repository. Credit unions should have knowledgeable people responsible for formalizing and documenting the selection and vetting process; reviewing—not just collecting—due-diligence materials; monitoring vendor performance and contractual commitments; documenting and following up on concerns; supporting renewal decisions; and ensuring vendors are properly offboarded, including confirmation that credit union and member data has been returned or destroyed as required.
For credit unions that do not have the internal capacity to sustain that level of oversight, Crimson Oak Strategies provides fractional vendor-management support. Our vendor managers work alongside credit union management to help build, administer, and maintain a practical, risk-based process throughout the vendor relationship lifecycle.