Skip to content
The Vendor You've Never Heard Of
Third-Party Risk Management

The Vendor You've Never Heard Of

William C Hord
William C HordChief Strategy Officer - ERM Pilot

ERM Pilot | Third-Party Risk Management Series, by William Hord - Chief Strategy Officer

If you want a one-line summary of where examiners' heads are right now, the OCC gave it to you directly. Its Spring 2026 Semiannual Risk Perspective groups third-party risk with cyber threats and fraud as elevated, interconnected drivers of operational risk — not a slow-moving compliance topic, but something examiners are watching alongside credit and interest rate risk. If your 2026 risk agenda reflects what mattered two years ago, you're already behind.

Here's what's actually moved, and why the “fourth party” — the vendor behind your vendor — deserves its own line item on that agenda.

The Vendor You've Never Heard Of

In August 2025, a ransomware group got into Marquis Software Solutions through an unpatched SonicWall firewall. Marquis isn't a bank. Most bank customers have never heard of it. It's a marketing, analytics, and compliance-reporting vendor that serves more than 700 banks and credit unions. By the time disclosures finished rolling in, American Banker's tally put the damage at roughly 824,000 affected customers across at least 80 institutions.

A security engineer quoted on the incident put it well: a single mid-tier vendor sitting in the data flow of numerous banks can create a blast radius on a national scale. That's the fourth-party problem in one sentence. Your due diligence file probably has a folder on Marquis-type vendors; it almost certainly doesn't have one on the infrastructure or software those vendors depend on — the layer where this incident actually started.

What Bank-Fintech Partnerships Taught Everyone

The other formative event of this cycle is the Synapse Financial Technologies bankruptcy. Synapse sat as a middleware layer between roughly 100 fintech apps and their partner banks; when it collapsed in April 2024, a shortfall of up to $95 million opened up between what partner banks held and what fintech end users were owed, and the CFPB later pursued Synapse for failing to keep adequate records of where that money actually sat. Two partner banks felt the supervisory fallout directly: Evolve Bank & Trust drew a Federal Reserve cease-and-desist order, and Lineage Bank an FDIC consent order, both tied to board governance and BSA/AML weaknesses connected to the relationship.

Regulators didn't stop at individual enforcement. In July 2024, the OCC, Federal Reserve, and FDIC jointly reminded banks of their obligations around third-party deposit arrangements and opened a formal request for information on bank-fintech relationships. The FDIC followed in September 2024 with a proposed rule requiring banks holding custodial “for benefit of” accounts to keep daily-reconciled, standardized records identifying the actual owner of every dollar — a direct response to Synapse's own ledgers being too unreliable to answer that question when it mattered. That rule is still moving through the process, so if your institution runs any pooled or custodial structure for a fintech partner, it's worth tracking now, not after a final rule lands.

The Global Baseline Just Moved

Here's the piece I'd bet most U.S. compliance calendars haven't caught up to yet. On December 10, 2025, the Basel Committee on Banking Supervision published new Principles for the Sound Management of Third-Party Risk, replacing guidance that had stood since 2005. The timing matters less than the content: the new principles explicitly widen the lens from traditional outsourcing to a “more diverse and complex third- and nth-party ecosystem,” and they reframe supervisory attention as expanding from individual firms to shared infrastructure — treating concentration and substitutability across an entire ecosystem as central risks rather than edge cases.

U.S. banking agencies don't adopt Basel principles overnight, but they have a long track record of eventually translating Basel direction into domestic supervisory expectations. An institution that can already speak fluently about its nth-party exposure — not just its direct vendors — will be ahead of that curve rather than scrambling to catch it.

Closer to home, examiners already have a domestic version of this lens. The FFIEC's Development, Acquisition, and Maintenance booklet, revised in August 2024 for the first time since 2004, is used by examiners across the OCC, Federal Reserve, FDIC, and NCUA alike — one of the few documents that speaks to banks and credit unions in the same voice. It devotes real attention to the interconnectedness between an institution's systems and its third-party providers, and directs examiners to weigh whether management has addressed the risk that interconnection creates. If Basel is where the direction is heading, this booklet is where a U.S. examiner can already ask about it.

The AI Vendor Stack Adds a New Wrinkle

Fourth-party risk isn't just a legacy concentration problem — AI adoption is actively making it worse. NCUA updated its AI resources page in December 2025, and it's explicit that due diligence on an AI vendor should be treated as a third-party relationship question, pointing credit unions back to existing vendor-oversight guidance rather than writing a separate AI rulebook.

That framing understates how deep the chain actually runs. A single AI feature an institution licenses may sit on top of a foundation model provider, a cloud host, external data suppliers, and model-monitoring services — none of which the institution has a direct contract with, and most of which never appear in the vendor's own sales materials. When that AI vendor changes its underlying model, its data-handling practices, or its own subcontractors, the institution's risk profile can shift without a single line of its own contract changing. Treating “we assessed our AI vendor” as equivalent to “we understand our AI vendor's dependencies” is exactly the gap examiners are starting to probe.

Concentration Is Now a Systemic Risk Category

It's not just Basel. The Financial Stability Oversight Council's 2025 Annual Report names third-party service provider concentration as a systemic operational risk in its own right, warning that as institutions lean on a small number of critical cloud, data management, settlement, and custody providers, the failure of any single one could cascade across the financial system. Marquis is that dynamic playing out at a smaller scale: one vendor, eighty downstream institutions, one shared point of failure.

Credit Unions Are Playing a Different Game

If you sit on the credit union side, there's a structural wrinkle worth naming with your board. Unlike the OCC, FDIC, and Federal Reserve, the NCUA has no direct examination authority over third-party vendors or credit union service organizations (CUSOs). Its working guidance — Letter 07-CU-13, Evaluating Third-Party Relationships — asks credit unions to do the assessment themselves; NCUA can judge whether that due diligence was adequate, but it can't walk into your core processor and examine anything directly. NCUA's own reporting to Congress states plainly that its continuing policy is to seek that vendor authority, and both the GAO and FSOC have separately recommended Congress grant it. Credit union trade associations push back just as consistently, arguing NCUA already has sufficient tools through CUSO ownership disclosures and existing due-diligence rules. That fight has run for years without resolution — the gap is a planning assumption, not a temporary condition.

In the meantime, the NCUA has tightened what it expects credit unions to do on their own. Since September 2023, federally insured credit unions must notify the NCUA within 72 hours of reasonably believing a reportable cyber incident occurred — including incidents that originate at a third-party provider rather than at the credit union itself. NCUA's January 2026 supervisory priorities letter reinforces the point, telling examiners to specifically evaluate governance, vendor oversight, and security controls tied to payment systems. Put together, credit unions carry nearly all of the third-party accountability that banks carry, without the regulatory backstop banks have on the vendor side. That asymmetry is worth a paragraph in any credit-union-facing version of this conversation — it changes the “why” behind the diligence, even when the “what” looks similar to a bank's program.

What This Means for the Next Exam

Strip away the acronyms and the last three years point toward the same five expectations. This isn't a stretch interpretation — the 2023 U.S. interagency guidance itself specifically calls out subcontractor reliance and directs institutions to evaluate the additional risks that reliance creates, including concentration. The new Basel principles just say it louder and more globally.

One caution before the list: this doesn't mean building an exhaustive subcontractor tree behind every vendor you have. That's an administrative exercise, not a risk-management one. The discipline is materiality. A fourth party earns real scrutiny when its failure could disrupt a critical service, concentrate risk across vendors an institution otherwise considers diversified, compromise sensitive data, or push the institution outside its stated tolerance for disruption — categories like core processing, cloud infrastructure, payment and settlement services, identity and authentication, critical data providers, AI models and infrastructure, and any provider with genuinely limited substitutes.

That concentration point is worth sitting with — it's easy to miss even with a mature-looking program. Picture an institution with five seemingly independent critical vendors: core processing, digital banking, fraud monitoring, loan servicing, member communications. Each has its own contract, SOC report, and risk rating. If four of those five ultimately run on the same cloud infrastructure provider underneath, the institution doesn't have five independent points of resilience — it has one, wearing four different contracts. A vendor-by-vendor risk rating will never surface that; only a dependency-level view will.

With that in mind, here are the five expectations:

  • A risk-tiered vendor inventory that identifies which relationships are critical — and, for those critical relationships, names the material fourth parties behind them, not an exhaustive subcontractor list.
  • Due diligence completed before signing, not after, with documentation that goes beyond a vendor's own marketing or self-attestation.
  • Contract language with audit and termination rights that reach into the subcontractor layer for critical activities, plus a documented understanding of what happens if a key subcontractor fails.
  • Ongoing monitoring rather than an annual questionnaire — a program that would actually catch a change in a critical vendor's risk posture between review cycles, not just document that a review happened.
  • A portfolio-level view of concentration: not “is this vendor healthy,” but “what happens across our institution if this one shared provider goes down.”

None of this is exotic, and none of it requires waiting for a final rule. The institutions that handle the next exam calmly won't be the ones with the thickest vendor files. They'll be the ones who can answer, for any critical relationship, who's actually behind it — and what happens if that layer fails.

Sources

Ready to transform your risk management?

Discover how ERM Pilot can streamline your compliance, automate workflows, and provide real-time insights for your organization.

Stay Updated on ERM Pilot

Join our newsletter to receive the latest news, feature updates, and expert insights on all things risk related.

We respect your privacy. Unsubscribe at any time.