top of page
Search

Third-Party Risk Management: Building a Risk-Based Vendor Inventory and Tiering Framework

Third-party relationships have become integral to how financial institutions deliver products, operate technology, serve customers, and manage critical business processes. As the number and complexity of these relationships grow, maintaining a list of vendors is no longer sufficient. Institutions need a reliable way to understand which relationships create the greatest risk, why they matter, and how the level of oversight should change as circumstances evolve.

A risk-based vendor inventory provides the foundation for that process. It creates a common view of the institution's third-party relationships, the activities and systems they support, the information they access, and the risks they introduce. A well-designed tiering framework then translates that information into differentiated oversight allowing management to devote greater due diligence, monitoring, governance, and contingency planning to relationships that present greater risk.

The regulatory framework supports this risk-based approach. The federal banking agencies' 2023 Interagency Guidance on Third-Party Relationships: Risk Management states that banking organizations should maintain a complete inventory of third-party relationships and tailor risk-management practices to the institution's size, complexity, risk profile, and the nature of the particular relationship.

This article explains how financial institutions can build an inventory and tiering framework that is complete, consistent, and operationally useful. It also explains where more specialized guidance applies. In particular, SR 26-2 (the agencies' revised guidance on model risk management) becomes relevant when a third-party relationship involves a model, but it should not be treated as the primary regulatory framework for third-party risk management generally.

Table of Contents

Why the Vendor Inventory Is the Foundation of TPRM

A third-party risk management framework depends on a sufficiently comprehensive inventory. An institution cannot effectively tier, monitor, or manage relationships it does not know exist. The inventory serves as the single source of truth for the entire third-party lifecycle, and its completeness provides an important foundation for credible risk assessment. A fragmented or incomplete view can leave significant risks unidentified or inadequately managed.

What Belongs in the Inventory

The first step is to establish a broad definition of a “third-party relationship.” Limiting the inventory to vendors processed through a central procurement function is a common but critical mistake. The inventory should capture business arrangements involving another entity that fall within the institution’s definition of a third-party relationship, including:

  • Traditional Vendors and Service Providers: Core processors, IT managed service providers, cloud hosting services, and call centers.

  • Fintech Partners: Banking-as-a-Service (BaaS) platform providers, payment processors, and digital account opening solution providers.

  • Professional Services: Consultants, external legal counsel, accounting firms, and independent contractors who have access to sensitive information or systems.

  • Affiliates and Subsidiaries: Relationships with affiliated entities that provide services or support critical operations.

  • Other Arrangements: Any relationship that may exist without a conventional procurement contract, such as joint ventures, referral partners, or data aggregators.

The inventory should also document known critical fourth parties and subcontractors. While an institution does not directly manage its vendors’ suppliers, understanding these dependencies is essential for assessing concentration risk and developing realistic contingency plans.

The Risks of an Incomplete Inventory

Failing to maintain a complete inventory creates significant blind spots that undermine the entire TPRM framework. These unmanaged risks often manifest during a crisis, such as a cybersecurity incident or a sudden service disruption. Common consequences include:

  • Unmanaged Relationships: Business units may engage third parties without proper vetting, leaving the institution exposed to operational, compliance, and reputational damage.

  • Fragmented Records: Without a central inventory, contracts, risk assessments, and performance data become scattered across the organization, making holistic oversight impossible.

  • Hidden Concentration Risk: An institution may unknowingly rely on the same fourth-party provider (e.g., a common cloud service or data center) through multiple, seemingly unrelated vendors.

  • Unsupported Critical Activities: A critical business process may depend on a third party that has not been identified as such, meaning it lacks the appropriate level of due diligence, contract provisions, and oversight.

Designing a Risk-Based Vendor Inventory

A functional inventory is more than a simple list; it is a structured data set that enables risk analysis and reporting. Building it requires establishing a common data model and clear governance processes that define accountability for keeping the information accurate and current.

Establishing a Common Data Model

To be effective, the inventory must capture consistent data points for every third-party relationship. While the exact fields may vary based on institutional complexity, a minimum data set provides the necessary foundation for risk tiering and analysis. Key data attributes include:

  • Unique Identifier: A consistent ID for each third-party entity.

  • Relationship Details: Legal name, DBA, address, and primary contacts.

  • Internal Business Owner: The executive or manager accountable for the relationship.

  • Service Description: A clear and concise summary of the products or services provided.

  • Criticality Assessment: A determination of whether the third party supports a critical activity.

  • Data Access: A classification of the type of institutional or customer data the third party accesses, processes, or stores (e.g., NPI, PII, confidential).

  • System Integration: A description of how the third party's systems connect to the institution's network.

  • Contract Information: Key dates (execution, renewal, expiration) and a link to the contract repository.

  • Current Risk Tier: The assigned risk level (e.g., Critical, High, Moderate, Low).

Establishing Inventory Governance

Data quality degrades quickly without clear ownership. A governance framework ensures that the inventory remains a reliable resource. This involves assigning specific responsibilities to different functions across the enterprise:

  • Business Units: Responsible for identifying new third-party relationships, providing initial information on the services provided, and acting as the primary relationship owner.

  • Procurement/Sourcing: Responsible for initiating the inventory record for new vendors and capturing key contractual and commercial data.

  • Information Security: Responsible for assessing and documenting data access, system integration, and cybersecurity-related risks.

  • Compliance and Legal: Responsible for evaluating regulatory implications, data privacy considerations, and ensuring contract terms are properly recorded.

  • TPRM Function: Responsible for owning the inventory process, validating data completeness, performing risk tiering, and ensuring the overall integrity of the framework.

Third party risk management framework

Building a Defensible Risk-Tiering Framework

Once a complete inventory is established, the tiering framework translates that information into a risk-based hierarchy. This process moves beyond a simple "critical vendor" designation to a more nuanced system that drives differentiated oversight. A defensible framework is built on objective risk factors that are applied consistently across the third-party portfolio.

Risk Factors

Risk tiering should be based on a multi-factor assessment of the inherent risks associated with each relationship. The goal is to evaluate the potential impact on the institution if the third party fails to perform, experiences a security breach, or otherwise introduces risk. Core risk factors include:

  • Operational Impact: The degree to which a service disruption would affect business operations, including the ability to serve customers or execute transactions. Does the third party support a critical activity?

  • Data Sensitivity: The level of access to sensitive data, particularly non-public personal information (NPI) or confidential institutional information.

  • Financial Impact: The potential for direct financial loss, including contract value, potential fines, or remediation costs.

  • Regulatory and Compliance Impact: The extent to which the third party's activities are subject to specific laws or regulations (e.g., BSA/AML, fair lending) and the potential for compliance failures.

  • Reputational Impact: The potential for negative public perception, loss of customer trust, or brand damage resulting from a third-party failure.

  • Geographic and Political Risk: Risks associated with the vendor’s location, including political instability or different legal and regulatory environments.

From Risk Factors to Tiering

These factors are typically weighted and combined into a scoring methodology to produce a final risk tier. A common approach uses a four-tier structure:

  • Tier 1 (Critical): Relationships presenting the highest level of inherent risk, typically involving critical activities, significant customer impact, extensive access to sensitive information or systems, or limited substitutability.

  • Tier 2 (High): Relationships presenting significant risk but not meeting the institution's criteria for Tier 1.

  • Tier 3 (Moderate): Relationships presenting moderate risk that can generally be managed through standard due diligence and monitoring.

  • Tier 4 (Low): Relationships presenting limited inherent risk and generally supporting non-critical activities with readily available alternatives.

Making Tiering Operational

The value of tiering lies in its ability to drive differentiated risk management activities. Higher-risk tiers should trigger more intensive oversight throughout the third-party lifecycle. For example:

  • Due Diligence: Tier 1 vendors require extensive, in-depth due diligence covering financials, security controls (e.g., SOC reports), business continuity plans, and compliance programs. Tier 4 may only require basic corporate vetting.

  • Contracting: Tier 1 contracts demand robust provisions for right-to-audit, security breach notification, data ownership, and liability.

  • Monitoring: Tier 1 vendors generally warrant more frequent and comprehensive monitoring, with the specific frequency and scope determined by the risks presented by the relationship.

  • Contingency Planning: Comprehensive and tested exit strategies are essential for Tier 1 relationships; they are less critical for lower-tier vendors with many market alternatives.

This risk-based approach allows an institution to focus its limited resources on the relationships that pose the greatest threat, creating a more efficient and effective enterprise risk management program.

Keeping the Inventory and Tiering Current

Risk is not static. A third-party relationship that is low-risk today could become high-risk tomorrow due to changes in service scope, data access, or the external environment. Therefore, the inventory and its associated risk tiers must be dynamic, with processes for both periodic and event-driven reassessment.

Trigger-Based Reassessment

Relying solely on an annual review cycle is insufficient for managing high-risk relationships. The TPRM framework should define specific events that automatically trigger a reassessment of a third party’s risk tier. Common triggers include:

  • Contract Renewal or Amendment: Any change to the scope of services or terms should prompt a review.

  • Significant Service Change: A vendor taking on new responsibilities or accessing new types of data requires an immediate reassessment.

  • Security or Service Incident: A data breach or significant operational failure at the third party necessitates a review of its control environment and risk tier.

  • Merger or Acquisition: A change in the third party's ownership can introduce new risks related to governance, financial stability, or strategic direction.

  • Negative News or Regulatory Action: Public reports of legal or regulatory trouble involving the third party should trigger a re-evaluation.

Portfolio-Level Risk

Beyond individual vendor changes, the framework must also consider portfolio-level risk. The TPRM function should periodically analyze the entire inventory to identify emerging concentration risks. For example, an analysis might reveal that a growing number of critical vendors all rely on the same cloud provider or are located in the same geographic region, creating a single point of failure that was not apparent when looking at each vendor in isolation.

Where SR 26-2 Fits... and Where It Does Not

It is crucial to place specialized regulatory guidance in its proper context. The interagency guidance on model risk management, SR 26-2, is highly relevant to third-party risk management, but only when a third-party relationship involves the use of a "model." It is not, and should not be treated as, the foundational framework for all TPRM activities.

SR 26-2 Is Model Risk Guidance

Issued on April 17, 2026, by the Federal Reserve, OCC, and FDIC, SR 26-2 (which supersedes SR 11-7 and SR 21-8) provides detailed supervisory expectations for managing model risk. This guidance is non-binding and advisory. Its principles are most relevant for banking organizations with over $30 billion in total assets, though it notes that smaller institutions with significant exposure to model risk may also find it applicable. The guidance covers the entire model lifecycle, from development and validation to implementation and ongoing monitoring.

Third-Party Models

When an institution uses a model developed or provided by a third party—such as a credit scoring model, an AML transaction monitoring system, or a fraud detection algorithm—the principles of SR 26-2 apply. When a third party provides a model, the institution should apply model risk management practices appropriate to the model's risk, including appropriate validation, ongoing monitoring, and outcome analysis. Reliance on a vendor does not eliminate the institution's responsibility to understand and manage the associated model risk. An institution cannot delegate its responsibility for model risk management simply because the model is a "black box" or its inner workings are proprietary.

Generative and Agentic AI

The guidance explicitly excludes generative and agentic artificial intelligence systems from its definition of a "model." However, this exclusion does not mean these technologies are without risk. The agencies direct institutions to apply appropriate governance and controls through their broader risk management frameworks, including TPRM. When engaging a vendor for generative or agentic AI services, an institution should apply due diligence, ongoing monitoring, and other controls appropriate to the risks presented by the technology and the particular third-party relationship.

From Inventory to Management Information

The ultimate purpose of a robust inventory and tiering framework is to produce decision-useful information for senior management and the Board of Directors. Raw data on hundreds or thousands of vendors is not helpful; it must be aggregated and synthesized into clear, risk-focused reporting. Effective management information should provide insights into:

  • Portfolio Composition: The number of third-party relationships by risk tier, business unit, and risk category.

  • Concentration Risk: Identification of over-reliance on single providers, geographic regions, or critical fourth parties.

  • Risk and Control Status: The number of high-risk vendors with overdue risk assessments, unresolved issues, or expiring contracts.

  • Emerging Risks: Trends identified from portfolio-level analysis, such as increasing reliance on a new technology or a specific type of fintech partner.

This level of reporting elevates the TPRM function from an administrative task to a strategic partner, enabling leadership to make informed decisions about risk appetite and resource allocation. Strong reporting is also a cornerstone of regulatory examination readiness, demonstrating a mature and proactive approach to risk oversight.

Executive Takeaways for Board and Senior Management

  • A sufficiently comprehensive third-party inventory provides the foundation for effective TPRM and enables consistent risk assessment and oversight. Oversight must extend beyond vendors managed by Procurement to include all business arrangements.

  • Risk tiering should be a dynamic process driven by objective factors. It allows the institution to apply differentiated oversight, focusing the most rigorous controls on the relationships that pose the greatest risk.

  • The TPRM framework must account for changes in risk over time. Event-driven triggers for reassessment help ensure risk ratings remain current as relationships, services, and external conditions change.

  • SR 26-2 provides relevant model risk management guidance when a third-party relationship involves a model, but it is not the primary framework for managing third-party relationships generally.

  • The inventory and tiering framework is only as valuable as the management information it produces. Reporting to the Board should focus on portfolio-level insights, concentration risks, and emerging trends.

How Versapien Can Help

Versapien helps financial institutions design and implement practical, defensible third-party risk management frameworks. Our senior-led advisory teams provide implementation-focused guidance on building comprehensive vendor inventories, developing risk-based tiering methodologies, and creating effective governance and reporting structures that align with supervisory expectations and support strategic business objectives.

 
 
 

Comments


  • LinkedIn

Tel. 704.931.8430

 Charlotte, NC  U.S.A.

© 2025 by Versapien, LLC.  All Rights Reserved. Powered and secured by Wix

bottom of page