Vendor Management Program
A complete, board-adoptable vendor management program built for smaller credit unions, finished in an afternoon, not a consulting engagement. Every vendor gets scored the same way, tiered automatically, and routed to the right review, from onboarding through the annual exam. Built from 45 years of banking experience.
Vendor Management Package
- Vendor Management Policy: board-adoptable, covering risk tiers, due diligence, contract standards, and ongoing oversight
- Vendor Risk Worksheet: your Master Vendor List, with a six-factor weighted scoring model that auto-assigns each vendor a Critical, Important, or Incidental tier
- New Vendor Review and Contract Review Checklist, used together at onboarding
- Critical Vendor Review: the annual review form for your highest-tier vendors
- Important Vendor Review: three built-in versions (Discretionary, Utility, and an Enhanced version for high member-data access) so review depth matches actual risk
- Start Here guide with completion order and full search-&-replace table
Every vendor scored the same way
The Vendor Risk Worksheet applies one weighted model, spend, conversion cost, regulatory impact, data access, dependence, and member-service exposure, so tiering decisions rest on a documented score, not a gut call.
Three review paths for Important vendors
Discretionary, Utility, and an Enhanced version for high member-data access, so a card network and a payroll processor aren’t forced through an identical review.
One system, new and ongoing vendors
New Vendor Review and the Contract Review Checklist cover onboarding; Critical and Important Vendor Review forms cover every year after, all built on the same risk model and vendor list.
Guided from download to first review
The Start Here guide explains completion order, gives a search-and-replace table for every placeholder, and flags which blanks on the recurring-use review forms to leave alone until you actually use them.
From purchase to your first completed review
These programs are templates that must be adapted to your institution. They provide a framework for due diligence and oversight; they do not evaluate any particular vendor and do not substitute for reviewing that vendor’s actual contracts, financial statements, SOC reports, insurance certificates, and control environment. No guarantee of regulatory acceptance, examiner approval, or compliance is expressed or implied. Your institution is solely responsible for reviewing, adapting, and testing these documents before adoption, and for confirming they reflect your current NCUA/FFIEC third-party risk expectations; review by qualified legal counsel or a compliance professional is recommended before reliance in an examination context.

