Vendor Management Program
A complete, board-adoptable vendor management program for smaller credit unions. Every vendor gets scored the same way, tiered automatically, and routed to the right review, from onboarding through the annual exam. Free, no account, no registration, direct download. Built from 45 years of banking experience.
What is inside
One ZIP file: an editable Word policy and five Excel workbooks, numbered in the order you use them. Nothing is locked, watermarked, or tied to a licence key.
00 START HERE
The working guide. Completion order, the full search and replace table for every bracketed placeholder, the items you fill in by hand, and which blanks to leave alone until you actually run a review.
Vendor Risk Worksheet
Your master vendor list with a weighted model that auto-assigns each vendor a Critical, Important, or Incidental tier.
The Vendor Risk Worksheet is the centre of the program. It holds your master vendor list and applies one weighted six factor model to every entry: spend, conversion cost, regulatory impact, data access, dependence, and member service exposure. Each vendor comes out with a documented score and an assigned tier of Critical, Important, or Incidental, which is what determines the review form it gets and how often. The workbook carries its own Assessment Metrics tab showing how the weights work, plus Critical and Important summary tabs that roll up automatically.
Placeholder names are shared with the continuity and incident response packages and the risk assessment workbooks, so an institution using several of them keeps one consistent audit trail.
Why use this
Every vendor scored the same way
One weighted model across spend, conversion cost, regulatory impact, data access, dependence, and member service exposure, so tiering rests on a documented score rather than a gut call you have to defend later.
Three review paths for Important vendors
Discretionary, Utility, and an Enhanced version for vendors with high member data access, so a card network and a payroll processor are not forced through an identical review.
One system, new and ongoing vendors
New Vendor Review and the Contract Review Checklist cover onboarding. Critical and Important Vendor Review cover every year after. All four are built on the same risk model and the same vendor list.
Guided from download to first review
The Start Here guide explains completion order, gives a search and replace table for every placeholder, and flags which blanks on the recurring forms to leave alone until you actually use them.
From download to your first completed review
The package
Vendor Management Package
The policy, the scoring model, and every review form, built to work together off one vendor list.
- Vendor Management Policy, board-adoptable, covering risk tiers, due diligence, contract standards, and ongoing oversight
- Vendor Risk Worksheet, your master vendor list with the six factor weighted model that auto-assigns each vendor a Critical, Important, or Incidental tier, plus metrics and summary tabs
- New Vendor Review and Contract Review Checklist, used together at onboarding
- Critical Vendor Review, the annual review form for your highest tier vendors, with its own instructions tab
- Important Vendor Review, three built-in versions on separate tabs: Discretionary, Utility, and an Enhanced version for high member data access, so review depth matches actual risk
- Start Here guide with completion order and full search and replace table
Important legal & exam disclaimers
This is a set of templates, provided free of charge, as-is, with no warranty and no support. It is a starting point, not a finished program, and it does not constitute legal, regulatory, or compliance advice.
No guarantee of regulatory acceptance
Expectations differ by charter, regulator, examiner, asset size, and geography, and may be supplemented by state law. No guarantee of regulatory acceptance, examiner approval, or legal sufficiency is expressed or implied.
Customization is required for compliance
These files provide a framework for due diligence and oversight. They do not evaluate any particular vendor and do not substitute for reviewing that vendor's actual contracts and controls. The scoring weights and tier thresholds are examples built around a hypothetical institution. Designed as a flexible framework, you must customize them to reflect your institution's specific risk appetite and vendor environment.
Counsel review recommended
Your institution is solely responsible for reviewing, adapting, and testing these documents before adoption. Review by qualified counsel or a compliance professional is strongly recommended before you rely on a completed review. Full terms are on the Terms of Use page and in the download.
Free to use, adapt, and share. Use these inside your institution, adopt your customized versions as your own, give them to your examiners and auditors, and pass a copy to a peer institution if it would help them. What you may not do is sell them or repackage them into something you sell. The full Terms of Use are short and are included in the download.
No support comes with these. No consulting, no customization, and no review of your completed vendor files. If you find an error or a broken file, info@mycurisk.com will read it, though no response time is promised.
If this saved your institution a weekend, a voluntary contribution is welcome and entirely optional. Nothing is withheld without it.

