ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Compliance and Risk

Cyber Complications for Vendor Risk Management

October 17, 2019
Reading Time: 3 mins read

By Emily Larkin

In a marketplace where data is shared and distributed at record speeds, third-party or vendor risk management is a challenge for most businesses. The banking industry is no stranger to this. The spotlight from federal and state regulators continues to shine on the use of third parties, and the pressure for those vendors to meet regulatory guidelines has greatly increased. This is especially challenging with cloud-based providers where cybersecurity concerns are even greater.

We are seeing banks moving to the cloud for a number of services ranging from core processing to lending. This movement to the cloud requires a robust vendor due diligence process and rigorous ongoing third party management that includes a focus on cybersecurity controls.

If your bank is considering partnering with a vendor, consider the following areas of cyber due diligence before signing a contract:

Establish a risk rating for your vendors. Just as risk ratings are a foundational element of sound lending decisions, creating a systematic approach to rate your prospective and current vendors based on the risk they pose to your business is essential for establishing the level of oversight they require. Ratings should be based on the risk they pose to the business. Helpful measures in determining that risk include the type of data you are sharing with the vendor, the ability to quickly replace that vendor, the vendor’s reputation in the market, and the amount of investment you are making with the vendor.

Understand the vendor’s financial stability. While this is not directly related to cybersecurity controls, it is imperative to acquire the necessary assurances that the vendor you are working with will be around in the long run. This is especially critical with cloud-based offerings, as they have control of the software or platform and if they go out of business, then your institution will not have the ability to run the solution internally.

Get it in writing. Whether it’s external audits, testing, or attestation, look for the vendor to provide external assurance regarding the state of their secure practices and governance. This includes system and organization controls, or SOC, reports, penetration/vulnerability assessments, and ISO certifications.

Know how many parties are involved. Just because you’re enlisting a third party doesn’t mean that’s where the parties end—there may be fourth and fifth parties involved. A number of solution providers build their environment within a cloud provider such as Amazon Web Services or Microsoft Azure and assume security is being managed. This is a big misconception. While AWS and Azure offer great options for businesses, they are not responsible for the security of the data. The vendor you are contracting with is responsible. Ensure that your vendors are layering the appropriate controls within their cloud provided solution and can share with you the steps they take to manage their cloud-based vendors. Vendors using AWS, Azure or other hosting providers should provide their own independent attestation of their security controls, not simply handing over an AWS or Azure SOC report.

Have transparency of internal controls. Banks should hold their vendors to the same level of regulatory guidance that they hold themselves. This means asking critical vendors to supply documentation affecting the security and protection of your data, including:

  • Policy documentation
  • Business continuity planning documentation
  • Proof of insurance
  • Details regarding their information security and cybersecurity programs
  • Vulnerability detection and management.

Thoroughly assess your contract. Ensure the appropriate cyber protections and terms are noted in the contract. Look for the vendor to highlight their cyber controls and commitment to follow regulations and laws within the contract. Ensure they are willing to assume a reasonable amount of liability and provide the appropriate notification and incident management procedures in the event of a data breach. Also, depending upon the type of vendor and their risk rating, look for service-level agreements with financial implications if they are not met.

In addition to initial vendor due diligence, organizations are required to follow an ongoing systematic approach to managing their third-party relationship. For some, this may be a spreadsheet approach, for others, it may be a third-party governance package. Whatever your institution chooses to tackle it, ensure that your approach is consistent and aligns with your vendor management policy. Regulators look for your management of vendors to be appropriate for the size, scope and complexity of your organization. This is intentionally vague and requires institutions to be thoughtful and intentional in maintaining their vendor management program and adjusting it when there are changes to the size, scope, and complexity of the organization.

Because of the number of vendors that are entering and exist in the financial space and the amount of data we share across these vendors, organizations have started to carve out dedicated roles and job descriptions to manage the vendor burden. Regardless of whether banks manage it internally or outsource it, the regulatory burden lies with the institution. It is critical that banks stay current with regulatory expectations and potential risks.

Emily Larkin is chief information security officer at Abrigo.

Tags: CybersecurityRisk managementThird-party risk
ShareTweetPin

Related Posts

International task force updates lists of countries with AML deficiencies

Treasury Department publishes reports on money laundering, digital assets

Compliance and Risk
March 9, 2026

The Treasury Department recently announced the publication of three reports on efforts to combat financial crimes. It also released a report to Congress on technologies that financial institutions use to counter illicit finance involving digital assets.

Supervisory tailoring bill introduced in Senate

FFIEC removes references to reputational risk in BSM/AML manual

Compliance and Risk
March 9, 2026

The Federal Financial Institutions Examination Council recently announced that it has removed all references to reputational risk in its Bank Secrecy Act/Anti-Money Laundering Examination Manual.

White House pushes state policymakers to restrict ‘junk fees’

White House releases national cybersecurity strategy

Compliance and Risk
March 6, 2026

The White House released its strategy for securing the nation’s infrastructure and private sector against cyber threats.

FS-ISAC issues framework for increasing fraud, cybersecurity team collaboration

Trump signs executive order to combat cybercrime

Compliance and Risk
March 6, 2026

President Trump signed an executive order directing federal law enforcement agencies to develop tools to better combat transnational criminal organizations responsible for cyber scams and fraud, and to establish a program to return seized or forfeited funds from...

FATF updates list of jurisdictions with anti-money laundering deficiencies

FATF updates list of jurisdictions with anti-money laundering deficiencies

Compliance and Risk
March 6, 2026

The Financial Action Task Force has updated its lists of jurisdictions with strategic deficiencies in countering anti-money laundering, the financing of terrorism and the financing of proliferation of weapons of mass destruction.

BIS seeks financial institutions for tokenized deposits project

Banking agencies release FAQ on capital treatment of tokenized securities

Compliance and Risk
March 5, 2026

Financial institutions should treat an eligible tokenized security in the same manner as the non-tokenized form of the security under the capital rule, the Federal Reserve, FDIC and OCC said in a new FAQ.

NEWSBYTES

New York Fed: Consumer short-term inflation expectations slip in February

March 9, 2026

Treasury Department publishes reports on money laundering, digital assets

March 9, 2026

FFIEC removes references to reputational risk in BSM/AML manual

March 9, 2026

SPONSORED CONTENT

How top agricultural lenders are approaching AI, automation and innovation in 2026

How top agricultural lenders are approaching AI, automation and innovation in 2026

March 2, 2026
Top 7 FP&A Trends in Banking for 2026

Top 7 FP&A Trends in Banking for 2026

March 1, 2026
How Instant Payments Can Accelerate B2B Payments Modernization

How Instant Payments Can Accelerate B2B Payments Modernization

February 3, 2026
Digital Banking: The Gateway to Customer Growth and Competitive Differentiation

Digital Banking: The Gateway to Customer Growth and Competitive Differentiation

February 1, 2026

PODCASTS

Podcast: How the SCAM Act would encourage platforms to go after scammers

February 4, 2026

A new kind of ‘community bank’ for small businesses

January 22, 2026

Podcast: A Lone Star banking perspective

January 15, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.