How Vendor Risk Management Actually Works Under FFIEC: The CFO Governance View

How Vendor Risk Management Actually Works Under FFIEC: The CFO Governance View
TL;DR
  • The 2023 Interagency Guidance on Third-Party Relationships, jointly issued by the Federal Reserve, FDIC, and OCC, unified prudential regulator expectations on vendor risk and substantially raised the bar from prior guidance.

  • The CFO question is not how the bank's procurement function handles vendors. It is how the bank's vendor risk management program operates as a continuing governance function with named accountability, board reporting, and integration with the bank's broader risk management.

  • A defensible program operates across the full vendor lifecycle: planning, due diligence, contract negotiation, ongoing monitoring, and termination. Banks that operate the lifecycle continuously, with documentation at each stage, produce the evidence the framework rewards. Banks that operate vendor management as a contracting function produce the findings the framework cites.

Why the 2023 Interagency Guidance Made Vendor Risk a CFO Governance Responsibility

A community bank CFO walking into a vendor risk conversation is rarely framed as a governance question. It arrives as a procurement issue, a contract renewal, a budget item, or a compliance-driven request from the qualified individual. The CFO addresses each as a discrete decision, and the broader question of vendor risk as a governance function is treated as resolved through the components.

The 2023 Interagency Guidance on Third-Party Relationships moved vendor risk explicitly into the governance domain, with board and senior management responsibilities named directly. The CFO who treats vendor risk as procurement is operating against the prior guidance. The CFO who treats it as governance is operating against the current guidance, and the difference shows up at the next exam.

That is the conversation worth having before the next renewal cycle or budget review.

 

The Five Substantive Shifts in the 2023 Interagency Guidance

The Interagency Guidance, finalized in mid-2023, replaced separate vendor-management guidance from each prudential regulator with a unified framework. The substantive shifts from prior guidance are recognizable.

The first shift is the explicit naming of board and senior management accountability for vendor risk. Prior guidance addressed vendor management at the operational level; the 2023 guidance moves it to the governance level. The board is expected to oversee the program, senior management is expected to operate it, and the documentation should reflect the engagement.

The second shift is the expansion of vendor lifecycle expectations. Prior guidance focused heavily on due diligence and contract terms. The 2023 guidance covers the full lifecycle: planning, due diligence, contract negotiation, ongoing monitoring, and termination, with specific expectations at each stage.

The third shift is the strengthened expectations on critical vendors. The guidance identifies vendors whose disruption would significantly impair the bank's operations as critical, and applies elevated oversight expectations. The bank should know which vendors are critical and operate the program at the appropriate intensity for each.

The fourth shift is the integration with broader risk management. Vendor risk is no longer a parallel track from operational, financial, or strategic risk. The guidance expects vendor risk to integrate with the bank's broader risk framework, with vendor-related risks visible in enterprise risk management.

The fifth shift is the emphasis on subcontractor risk. The guidance addresses the chain of relationships beyond the primary vendor, expecting the bank to understand and oversee the sub-processors handling its data or operations.

A program operating against the 2023 guidance looks different from a program operating against the prior guidance. CFOs sizing the program for current cycle should benchmark against the 2023 framework, not the prior versions.

 

The Five Vendor Lifecycle Stages a Defensible Program Must Operate

A defensible vendor risk program operates across five recognizable stages, with documentation and named accountability at each.

Planning is the first stage. Before engaging a vendor, the bank evaluates whether the relationship is necessary, what risks it introduces, what alternatives exist, and what oversight the relationship will require. Many banks do not formally document this stage, but the guidance expects it to occur and produce evidence. The CFO's role at planning is to ensure the strategic and financial implications are visible.

Due diligence is the second stage. The bank evaluates the candidate vendor's financial posture, control environment, regulatory standing, business continuity capability, and information security program. Critical vendors receive deeper diligence including independent audit reports, financial review, and reference checks. The discipline is that diligence happens before contract signing and produces documented evidence.

Contract negotiation is the third stage. The bank's contracts with vendors include specific terms reflecting the bank's regulatory requirements: GLBA Safeguards-equivalent terms (where applicable), audit rights, breach notification timelines, sub-processor flow-down, termination terms, and the bank's right to require remediation. Critical vendor contracts include additional terms commensurate with the elevated risk.

Ongoing monitoring is the fourth stage. The bank reviews each vendor on a cadence proportional to its tier. Critical vendors receive at least annual deep review. Lower-tier vendors receive lighter periodic review. Material changes (financial deterioration, control failures, ownership changes, incidents) trigger immediate review regardless of cycle.

Termination is the fifth stage. When a vendor relationship ends, the bank executes a documented offboarding sequence: access revocation, data return or destruction, evidence collection, and records update. Termination discipline matters because the residual exposure from departed vendors persists if not addressed.

Banks that operate all five stages with documentation produce the evidence the framework rewards. Banks that operate two or three stages well, with the others ad hoc, produce the findings the framework cites.

 

What the CFO Should Be Overseeing in the Vendor Risk Program

The CFO's specific responsibilities under the 2023 guidance, in practical terms, include several recognizable items.

The CFO should know which vendors are tiered as critical, what financial implications their disruption would carry, and what oversight the bank applies. Critical vendor decisions interact with capital planning, contingency funding, and operational risk in ways the finance function should be involved in.

The CFO should review the vendor risk program's recurring reporting, with attention to material changes in critical-vendor risk profile, incidents involving any vendor, and remediation actions in flight. The reporting should be substantive enough that the CFO can summarize program status to the board.

The CFO should ensure the program's budget supports the lifecycle the guidance expects. Programs operated on procurement budgets alone typically underfund the planning, monitoring, and termination stages.

The CFO should be sized into the board reporting on vendor risk, demonstrating finance-function engagement on a function the board increasingly oversees as a governance matter.

 

Why "Procurement and Compliance Handle It" No Longer Satisfies the Guidance

A community bank CFO will hear, somewhere in the program discussion, this argument: vendor management is the responsibility of the procurement and compliance functions, the CFO's role is to approve contracts financially, and additional finance-function engagement duplicates work the program already does.

That is a false choice, and the 2023 guidance has made it expensive to maintain. The guidance explicitly names senior management accountability, including the CFO function. Board reporting on vendor risk increasingly reflects financial implications the CFO uniquely understands. Critical vendor decisions interact with capital and contingency planning that procurement and compliance cannot frame independently.

The right framing is not whether the CFO duplicates procurement work. It is whether the CFO is engaged at the level the guidance expects, demonstrates finance-function oversight on the program, and ensures vendor risk integrates with the bank's broader risk management. The first framing produces a procurement-led program. The second framing produces a governance-led program the regulator recognizes.

 

The Program Review That Maps Vendor Risk to the 2023 Guidance

A community bank CFO should walk through a vendor risk program review against the 2023 Interagency Guidance, with the five lifecycle stages mapped to current operation and the gaps named explicitly. The exercise produces a one-page CFO summary for governance review, a remediation roadmap for closing material gaps, and a board reporting framework that demonstrates the engagement the guidance expects.

CFOs who complete this review describe the next exam as recognizably different. The vendor risk findings disappear, the program output is in the room when the examiner asks, and the conversation moves from "what are you doing about vendor risk" to "let's review the program's most recent reports."

That is the difference between a vendor risk function the bank operates and a vendor risk gap the regulator catches.

 

Fund the Governance Function, Not Just the Contract Review

A community bank CFO sizing the vendor risk program against the 2023 Interagency Guidance is not signing off on procurement spend. The CFO is funding a governance function with financial, regulatory, and operational implications that the regulator examines on the bank's books. Programs that operate the five lifecycle stages with documented cadence produce the evidence the regulator looks for. Programs that operate a subset of stages produce the findings the regulator cites.

If your bank has not produced a current-state benchmark of its vendor risk program against the 2023 Interagency Guidance in the last twelve months, that is the conversation worth having with your Tech-Operations partner before the next exam cycle.

Five Nines Technology Group is a Tech-Operations partner for community banks and credit unions. Translating regulatory frameworks into operating discipline at community bank scale is where our team focuses.

Frequently asked questions

Does the 2023 Interagency Guidance apply to credit unions?

NCUA has its own vendor management framework that closely parallels the 2023 Interagency Guidance. Credit unions should benchmark against both their NCUA-specific guidance and the principles in the Interagency Guidance.

What makes a vendor "critical" under the guidance?

Criticality is defined by the vendor's role in bank operations and the consequences of vendor failure. Common critical vendor categories include core processing, online banking platforms, major IT infrastructure, and specific service providers whose disruption would significantly impair the bank.

How often should the board review the vendor risk program?

At least annually for the full program review. Quarterly for material changes, including new critical vendors, vendor incidents, and regulatory updates. Reporting should be substantive enough to demonstrate informed oversight.

Do we need a separate program for sub-processors?

The bank's primary vendor is responsible for managing its own sub-processors, with the bank's contract requiring flow-down of equivalent safeguards. The bank does not directly manage the sub-processors, but should know which sub-processors handle bank data and have visibility into material changes.

How does the program interact with cyber insurance underwriting?

Cyber insurance carriers increasingly request evidence of the vendor risk program as part of underwriting. Mature programs receive better terms; weaker programs face elevated premiums or coverage challenges.

Can the bank engage a partner the vendor risk program?

The operational work, yes. The accountability, no. A Tech-Operations partner can run the inventory, due diligence, monitoring cadence, and documentation. The named program owner inside the bank, the board reporting, and the CFO governance remain internal.

What evidence does the regulator examine first?

The tiered inventory and a sample of due diligence files for critical vendors. If those exist and are current, the conversation moves to monitoring records and incident response. If they do not exist or are out of date, the conversation focuses there.

Related Blog Posts