What FFIEC Examiners Actually Look for in Vendor Management
The institution is accountable, not just the vendor
Under FFIEC guidance, a bank or credit union cannot outsource its regulatory responsibility along with the function itself. If a core processor, cloud provider, or fintech partner fails — operationally or on security — the examiner's questions go to the institution's own oversight process, not just the vendor's contract terms. That's the single most important thing to understand walking into an exam: the vendor relationship is evaluated as an extension of the institution's own risk management, not a separate category.
What examiners actually check
Due diligence before the contract was signed
Examiners look for documented evidence that the institution assessed a vendor's financial condition, security posture, business continuity capability, and legal/regulatory standing before onboarding — not just a sales conversation and a signature. If the file shows no pre-contract risk assessment, that's a finding regardless of how the vendor has actually performed since.
Risk-tiering proportional to criticality
Not every vendor needs the same scrutiny. Examiners expect institutions to classify vendors by criticality — a core banking platform and an office-supplies vendor don't belong in the same review cycle — and apply oversight intensity accordingly.
Contract provisions, specifically
Examiners look for specific clauses: defined performance standards, the institution's right to audit, data security and breach-notification obligations, subcontracting/fourth-party disclosure, and clear termination and data-return terms. A contract that's silent on these is treated as a gap, even if the relationship has been trouble-free.
Ongoing monitoring, not a one-time review
Annual or periodic reassessment — financial health checks, SOC 2 or equivalent report review, incident history — is expected for critical vendors. A due-diligence file that hasn't been touched since onboarding is a common exam finding.
Board and senior management oversight
Examiners expect evidence that vendor risk is reported at a governance level appropriate to its materiality — critical vendor relationships should appear in board or senior-management risk reporting, not live only in a procurement folder.
Contingency and exit planning
What happens if the vendor fails, is acquired, or has to be replaced quickly? Examiners look for a documented contingency plan for critical relationships, not an assumption that switching would be straightforward if it ever came to that.
Where institutions most often fall short
In practice, the gap is rarely the absence of a vendor management policy — most institutions have one. It's inconsistent execution: pre-contract diligence that isn't repeated on renewal, criticality tiers that were set once and never revisited as usage grew, and contract files missing the specific clauses examiners look for. A structured, independent review of vendor contracts and oversight documentation before an exam — not during one — is the most reliable way to close those gaps. This is the kind of review MALA runs as part of a technology reality assessment, at zero upfront cost, for institutions that want an outside set of eyes on vendor risk before an examiner provides one.
-2.png?width=577&height=234&name=logo-01%20(4)-2.png)