Under FFIEC guidance, a bank or credit union cannot outsource its regulatory responsibility along with the function itself. If a core processor, cloud provider, or fintech partner fails — operationally or on security — the examiner's questions go to the institution's own oversight process, not just the vendor's contract terms. That's the single most important thing to understand walking into an exam: the vendor relationship is evaluated as an extension of the institution's own risk management, not a separate category.
Examiners look for documented evidence that the institution assessed a vendor's financial condition, security posture, business continuity capability, and legal/regulatory standing before onboarding — not just a sales conversation and a signature. If the file shows no pre-contract risk assessment, that's a finding regardless of how the vendor has actually performed since.
Not every vendor needs the same scrutiny. Examiners expect institutions to classify vendors by criticality — a core banking platform and an office-supplies vendor don't belong in the same review cycle — and apply oversight intensity accordingly.
Examiners look for specific clauses: defined performance standards, the institution's right to audit, data security and breach-notification obligations, subcontracting/fourth-party disclosure, and clear termination and data-return terms. A contract that's silent on these is treated as a gap, even if the relationship has been trouble-free.
Annual or periodic reassessment — financial health checks, SOC 2 or equivalent report review, incident history — is expected for critical vendors. A due-diligence file that hasn't been touched since onboarding is a common exam finding.
Examiners expect evidence that vendor risk is reported at a governance level appropriate to its materiality — critical vendor relationships should appear in board or senior-management risk reporting, not live only in a procurement folder.
What happens if the vendor fails, is acquired, or has to be replaced quickly? Examiners look for a documented contingency plan for critical relationships, not an assumption that switching would be straightforward if it ever came to that.
In practice, the gap is rarely the absence of a vendor management policy — most institutions have one. It's inconsistent execution: pre-contract diligence that isn't repeated on renewal, criticality tiers that were set once and never revisited as usage grew, and contract files missing the specific clauses examiners look for. A structured, independent review of vendor contracts and oversight documentation before an exam — not during one — is the most reliable way to close those gaps. This is the kind of review MALA runs as part of a technology reality assessment, at zero upfront cost, for institutions that want an outside set of eyes on vendor risk before an examiner provides one.