Vendor Risk Management Doesn’t Get Its Own Exam Anymore

Vendor risk now surfaces inside lending, payment, and BSA exams for community banks and credit unions, not only the annual TPRM review.

Image décorative

Principaux enseignements

  • NCUA’s 2026 supervisory priorities fold third-party oversight into the lending and payment systems reviews, and cybersecurity now appears only as a footnote instead of its own category. (NCUA, Letter 26-CU-01)
  • The FFIEC retired its Cybersecurity Assessment Tool on August 31, 2025, and pointed institutions toward NIST CSF 2.0 instead. (FFIEC, CAT Sunset Statement)
  • Compliance team involvement in third-party risk management rose from 42% in 2023 to 88% in 2025, yet fewer than one in four programs call themselves highly coordinated. (Mitratech, 2025 TPRM Study)
  • Federal banking regulators built proportionality into community bank guidance, but the underlying obligation to manage third-party risk does not scale down with asset size. (Fed, FDIC, OCC, TPRM Guide for Community Banks, May 2024)
  • A vendor record split across lending, compliance, and IT risks three teams giving three different answers about the same vendor in the same exam cycle.
In This Article
  1. Why Vendor Risk Left Its Own Exam Section
  2. The FFIEC Retired the CAT for NIST CSF 2.0
  3. What a Split Vendor Record Costs You Now
  4. Where Examiners Are Concentrating Attention in 2026
  5. Does Being a Community Institution Lower the Bar?
  6. What to Fix Before Your Next Exam
  7. Ask Henry: Questions I Get About Vendor Risk Exams

An NCUA examiner opens the file on a credit union's indirect lending program. 15 minutes later, she is asking who services those loans after origination, not just who originated them. It is a third-party risk management question that used to wait for its own exam.

That is not a hypothetical exchange. It is where third-party risk management is heading for community banks and credit unions in 2026, and it changes who inside your institution needs a ready answer, and when.

Third-party risk used to have its own lane in an exam: one list, one set of assessments, one monitoring cadence, reviewed together, once a year. NCUA’s 2026 supervisory priorities no longer treat it that way. Vendor oversight now shows up inside the lending review and the payment systems review, and when outsourced functions touch monitoring or reporting, it is starting to surface inside the BSA review too.

The oversight did not get heavier. It got everywhere.

Third-party risk management (TPRM) covers how a bank or credit union identifies, assesses, and monitors the risk a vendor or servicer relationship introduces to lending, payments, and compliance. For community institutions, that management no longer happens once a year in a dedicated review. It happens continuously, inside whichever exam touches the outsourced function.

Why Vendor Risk Left Its Own Exam Section

NCUA’s January 2026 supervisory priorities letter (26-CU-01) tells examiners to assess third-party risk wherever a credit union outsources lending, servicing, or collection functions. The same letter folds vendor management into payment systems oversight too, naming governance, risk assessments, and security frameworks as review areas for the vendors behind a credit union’s payment operations, not just the core processor.

Cybersecurity tells a similar story. It carried its own heading in NCUA’s 2024 and 2025 priorities letters. In the 2026 letter, it drops to a single footnote reference. Cybersecurity did not get less important. NCUA folded it into the baseline expectation for every review area instead of calling it out as a separate one.

Credit unions have run on a version of this principle since 2007. NCUA Letter 07-CU-13 on evaluating third-party relationships still trains field examiners today, and the 2026 priorities letter cites it directly under its lending section.

Community banks answer to a newer, parallel track: the 2023 interagency guidance from the Federal Reserve, FDIC, and OCC, plus the May 2024 guide built to help community banks apply it. Different regulators, same direction. Third-party risk stopped being a single question and became a thread running through most of the others.

Exam Type What Draws In Vendor Risk What Examiners Ask For
Lending Indirect lending, servicing, collection functions Governance, risk assessments, monitoring cadence, NIST CSF 2.0 alignment
Payment Systems Core processor, ACH/RTP providers, subprocessors Governance, risk assessments, security frameworks, NIST CSF 2.0 alignment
BSA Vendors touching monitoring or reporting The same vendor record, consistently current, NIST CSF 2.0 alignment

The FFIEC Retired the CAT for NIST CSF 2.0

That footnote treatment traces back to one decision. The FFIEC retired its Cybersecurity Assessment Tool on August 31, 2025, and pointed institutions toward NIST CSF 2.0 instead, which builds governance and third-party risk into six functions banks and credit unions already work through: govern, identify, protect, detect, respond, and recover.

CAT had a narrow job. It measured cyber maturity on its own, once a year, the same way third-party risk used to get measured on its own, once a year. Regulators retired it for close to the same reason they folded vendor oversight into lending and payments exams. A single annual snapshot cannot keep pace with a risk that touches the business continuously.

NIST CSF 2.0 does not ask “how is your cybersecurity” as one question. It asks whether governance, vendor oversight, and incident response show up consistently across everything the institution does. I have sat in enough exit meetings to know that is a materially different standard to prepare for, not just a different form to fill out.

What a Split Vendor Record Costs You Now

The shift in this standard already changes who is in the room for third-party risk. Mitratech’s 2025 Third-Party Risk Management Study found compliance team involvement in vendor oversight jumped from 42% in 2023 to 88% in 2025, while fewer than one in four programs describe themselves as highly coordinated.

Close to half point to departmental silos as the reason, with infosec and risk owning strategy, procurement owning the vendor database, and business units managing the relationship day to day.

That split used to cost you one uncomfortable afternoon a year, during the TPRM review. It costs more now. If a lending examiner asks about your indirect auto servicer in March and a payments examiner asks about that same servicer’s subprocessor in September, both questions draw from the same underlying vendor file.

When lending’s answer and compliance’s answer do not match, you have not failed one exam question. You have raised a question about whether the institution knows its own vendor list at all.

Three teams holding three versions of the same vendor relationship was survivable when only one of them had to answer for it each year. It stops being survivable once two of those teams answer for the same vendor to two different examiners in the same year.

Where Examiners Are Concentrating Attention in 2026

That risk concentrates hardest in payment systems. NCUA’s 2026 priorities single out payment systems for direct examiner review, pointing to growing complexity across applications, interfaces, and security controls as consumer expectations shift toward instant access to funds. Examiners will assess governance, risk assessments, vendor management, and security frameworks for the vendors behind those payment rails, not only the core processor.

Real-time payments and ACH providers sit downstream of the core processing relationship most institutions already track closely. They get overlooked precisely because the core processor gets the attention. A vendor list that stops at the obvious names misses the providers examiners are now naming specifically.

The same logic extends past your direct vendors. A payments provider’s own subprocessors, and a servicer’s own vendors, carry risk your institution never directly assessed. The 2026 KPMG Global Third-Party Risk Management Survey has flagged Nth-party visibility as a priority precisely because most programs stop looking one layer too early.

Does Being a Community Institution Lower the Bar?

No. The underlying third-party risk obligation set by the 2023 interagency guidance those same agencies issued the year before does not scale down, even though the Federal Reserve, FDIC, and OCC built their May 2024 Third-Party Risk Management Guide, voluntary and scaled to size and complexity, specifically for banking organizations with $10 billion or less in consolidated assets.

Proportionality shapes how you build a program. It does not decide whether you need one. Whether an institution holds $400 million or $40 billion in assets, both answer to the same interagency guidance.

A larger regional bank usually has a dedicated TPRM function to point to when the question comes up mid-exam. Most community institutions do not, which is exactly why a vendor question showing up inside three exams instead of one matters more here than almost anywhere else in the industry.

Give Every Exam the Same Current Answer

Mitratech Prevalent keeps vendor evidence current through continuous monitoring, so lending, compliance, and IT are never working from three different files.

Explore Continuous Monitoring

Ask Henry Questions I Get About Vendor Risk Exams

GRC Answers from Henry Umney, Managing Director of GRC Strategy at Mitratech

Why is vendor risk showing up in exams that aren't about vendors?
“Because the underlying activity, lending, payments, collections, almost always runs through a vendor somewhere. Examiners used to pull that thread out and review it on its own. Now they follow it inside whatever exam they’re already running. If your indirect lending program relies on a servicer, expect the lending examiner to ask about that servicer directly.”
Does the FFIEC retiring the CAT tool actually change anything for credit unions, since NCUA runs its own cybersecurity program?
“It changes the framework examiners point to, even where NCUA runs its own assessment. NIST CSF 2.0 folds third-party and supply chain risk into the same six functions used for governance and incident response. That is a broader standard than CAT ever asked for, and it’s the one your board should hear you’re already working from.”
Do smaller institutions get more time or a lighter standard because they have fewer resources?
“The guidance scales to your size and complexity. The underlying obligation to manage third-party risk does not. Whether you hold $300 million or $30 billion in assets, you answer to the same interagency guidance. The smaller institution just has fewer people to answer with, which is exactly why one shared vendor record matters more there, not less.”
What's the fastest way to know if our vendor program would hold up across three different exam areas?
“Pick one high-risk vendor and ask three teams, lending, compliance, and IT, what they know about it. If you get three different last-review dates or three different risk ratings back, you already have your answer, and it isn’t the one you want an examiner to find first.”
Should we be worried about vendors we don't directly manage, like our processor's subprocessors?
“Worried is the wrong word. Aware is the right one. Your vendor can be in great shape and still be sitting on someone else’s infrastructure that isn’t. If that fourth party has a bad week, you inherit the problem vicariously, whether you ever assessed them directly or not. It’s a documented gap in most TPRM programs, and it’s exactly the kind of concentration risk that shows up when a single subprocessor serves half your peer group at once.”
How much manual work does producing that evidence actually take?
“Less than most teams assume once the record exists. A vendor uploads its standard documentation once, and the system checks it against the controls you actually asked about, flagging what’s missing or out of date instead of leaving someone to read a stack of PDFs by hand. That’s a different job than the one most compliance analysts have today, and it’s the only way this scales past a handful of high-risk vendors.”
What's the one thing you would tell a CRO or head of TPRM at a community bank to fix first?
“Stop treating your vendor list as something you update for the annual review. Build it once, tier it by risk, and let the highest-risk relationships get watched continuously. Everything examiners are asking for now assumes that record already exists before they walk in the door.”
What does NCUA's 2026 supervisory letter require for third-party risk?
“Letter 26-CU-01 tells examiners to check third-party risk inside the lending review and the payment systems review, not in a standalone section. For payment rails specifically, that means governance, risk assessments, and security frameworks for the vendors behind the credit union’s operations, not just the core processor.”
What replaced the FFIEC's Cybersecurity Assessment Tool?
“NIST CSF 2.0. The FFIEC retired the CAT on August 31, 2025. CAT scored cyber maturity once a year, on its own. NIST CSF 2.0 builds third-party risk into the same six functions used for governance and incident response, so it’s a continuous standard instead of an annual score.”

Comment Mitratech peut aider

Most of what examiners are asking for now assumes an institution can already produce one current vendor record. Most community banks and credit unions cannot, not because the teams aren’t capable, but because the record itself has never been unified. Mitratech Prevalent builds that record once. Its Framework Mapping capability runs a single assessment against a library of standard questionnaires and maps the results to NIST CSF 2.0, the interagency guidance, and dozens of other frameworks examiners recognize. Continuous monitoring keeps the evidence behind the highest-risk vendors current instead of letting it age for a year between reviews, and the same visibility extends to the vendors those vendors depend on. Lending, compliance, and IT end up working from the same file, so the answer does not change depending on which exam asks first. Explore Mitratech Prevalent.