Skip to content
BOL Conferences
Thread Options
#1884636 - 01/09/14 05:40 PM Vendor Risk Management
Doug Hendrickson Offline
Power Poster
Doug Hendrickson
Joined: Oct 2009
Posts: 3,927
For those of you who use products/services such as ChexSystems (for deposit accounts) or HART (for providing the risk-based notice based on credit information), what do you require from the vendor or review on an annual basis (e.g., SAS70 or equivalent, financials, etc.).
_________________________
I hear and I forget. I see and I remember. I do and I understand.--Confucius

Return to Top
Risk Management
#1889771 - 01/23/14 09:47 PM Re: Vendor Risk Management Doug Hendrickson
Carolina Blue Offline
Platinum Poster
Carolina Blue
Joined: Jul 2005
Posts: 961
Lost in a regulatory fog
Typically, if they handle/process customer information then they are a critical vendor and we require an annual review of financials and SAE-16/SAS70 or equivalent.

Return to Top
#1890936 - 01/27/14 11:11 PM Re: Vendor Risk Management Doug Hendrickson
Midnight Offline
Member
Midnight
Joined: Jun 2008
Posts: 69
Upper Mid West
Our annual reviews are only on our critical vendors. Our critical vendor list is short and consist of those vendors that we would be in trouble if they disappeared (i.e., core systems, online banking, network compancy) For critical vendors we look at SSAE16 (if applicable), financial information (once or twice a year reviews), disaster recovery plans or assurance they have one, inquire if they have any pending legal issues. For companies like Chex we do not do an annual review (they are important but not critical to our operations).

Return to Top
#1890940 - 01/27/14 11:21 PM Re: Vendor Risk Management Doug Hendrickson
Doug Hendrickson Offline
Power Poster
Doug Hendrickson
Joined: Oct 2009
Posts: 3,927
Thanks to both of you.
_________________________
I hear and I forget. I see and I remember. I do and I understand.--Confucius

Return to Top
#1900751 - 02/27/14 07:27 PM Re: Vendor Risk Management Doug Hendrickson
JackieN Offline
Junior Member
Joined: Mar 2004
Posts: 44
You may want to take a look at the OCC guidance that came out last October that provides a list of items that could be incorporated into ongoing monitoring/due diligence.

Return to Top
#1903343 - 03/07/14 05:14 PM Re: Vendor Risk Management Doug Hendrickson
Miss Comply Offline
Member
Joined: Mar 2012
Posts: 81
Who in your institution reviews the SSAE 16? Do they use a checklist, did they received outside training, etc.? We don't have anyone experienced in reviewing these and so I am thinking we should send someone to training, just not sure who and was curious how other Bank's are handling these reviews.

Thanks!
_________________________
The opinions I express are soley mine.

Return to Top
#1903387 - 03/07/14 05:58 PM Re: Vendor Risk Management Doug Hendrickson
Matt_B Offline
Diamond Poster
Matt_B
Joined: Sep 2011
Posts: 1,648
A CU, Where Regs Don't Apply
I review them. I wouldn't say I'm qualified, but it's better than nothing. I purchased training from a vendor and self-taught pretty much. I pulled together some review forms that I found from different sources, customized them a little bit, and that's what I go with.

I do have to consult with IT occasionally if there are exception findings in any of the testing that are over my head, to determine the severity/relevance of the finding as it applies to us. Exceptions and the complementary user-entity controls are areas I focus on a lot.

You definitely want someone with at least some technological savviness to be involved though!
_________________________
Someone's about to get horned!

Return to Top
#1903586 - 03/07/14 10:03 PM Re: Vendor Risk Management Doug Hendrickson
ahkcompliance Offline
Diamond Poster
Joined: Sep 2008
Posts: 2,474
Midwest
Like, Matt I review them and I wouldn't say I'm qualified. I go through to see the testing that was done and if there are any exceptions. I also will work with our IT if I don't understand the testing being done.

I am in the process of trying to create some sort of checklist for reviewing a SSAE 16 since examiners recommended it the last time they were in.

Return to Top
#1903588 - 03/07/14 10:29 PM Re: Vendor Risk Management Doug Hendrickson
califgirl Offline
Diamond Poster
califgirl
Joined: Mar 2002
Posts: 2,355
The O.C., California
_________________________
I can explain it to you. I can't understand it for you.

Return to Top
#1903975 - 03/10/14 09:28 PM Re: Vendor Risk Management Doug Hendrickson
Miss Comply Offline
Member
Joined: Mar 2012
Posts: 81
Thanks everyone! I will look over that Whitepaper, I appreciate you putting the link up.
_________________________
The opinions I express are soley mine.

Return to Top
#1917556 - 04/25/14 01:41 PM Re: Vendor Risk Management Doug Hendrickson
DD Regs Offline
Power Poster
DD Regs
Joined: Nov 2008
Posts: 4,132
Somewhere in the middle
Any one have a Vendor / Third Party Risk Assessment they would be willing to share?

Any checklist, resources etc.

Thanks
_________________________
I'm only responsible for what I say, not for what you understand.

Return to Top
#1928666 - 06/02/14 08:09 PM Re: Vendor Risk Management Doug Hendrickson
THEBANKERLADY Offline
100 Club
THEBANKERLADY
Joined: Nov 2013
Posts: 107
Yes, I was wondering the same thing. Does anyone have an actual Third Party Risk Management Policy or know where I might can buy one?

Return to Top
#1928669 - 06/02/14 08:13 PM Re: Vendor Risk Management Doug Hendrickson
manimal Offline
Diamond Poster
manimal
Joined: Feb 2008
Posts: 2,207
Deleted
_________________________
We're all here 'cause we've lost control.

Innerpartysystem

Return to Top

Moderator:  Andy_Z