Beyond the Checklist: What Your Board Needs to Know About Vendor Risk

By Roberta Rodgers

At some point in nearly every credit union board meeting, a director gets handed a due diligence summary. SOC 2 reports have been reviewed, insurance certificates are on file, financial statements are current. It is meant to be reassuring, and often it is, because paperwork feels like proof of protection. 

The NCUA’s own numbers say otherwise. In its October 2024 letter to credit union boards on cyber incident reporting (24-CU-02), the agency found that roughly seven out of 10 reported incidents involved a third party. The 2026 Verizon Data Breach Investigations Report shows the same pattern industrywide, with third-party involvement in breaches climbing from 30 percent to 48 percent in a single year. The paperwork was likely in order, and the exposure showed up anyway, through a channel no certification review was built to catch.

A Distinction Often Blurred

That gap comes down to one distinction boards often blur. Due diligence and risk assessment are not the same thing. Only one of them is genuinely the board’s job to confirm.

Due diligence is the collection of information about a vendor. It covers certifications, audits, financial health, and security questionnaires, and it answers the question of whether a vendor has controls in place. 

A risk assessment goes further and asks what those controls actually mean against your credit union’s own systems, risk appetite, and control environment. A vendor can hold a flawless SOC 2 report while your credit union remains exposed if nobody examines the gap between what the vendor’s controls cover and what your institution actually needs covered.

The NCUA has held some version of this position since 2007, when its foundational guidance on evaluating third-party relationships, Letter 07-CU-13, established that credit unions need ongoing risk assessment and monitoring for the life of a vendor relationship rather than a one-time document check at signing. 

Sharpening Expectations

The 2024 cybersecurity letter sharpened that expectation considerably for directors specifically, stating that boards are responsible for setting clear expectations around vendor due diligence and for approving a security program that includes actual risk assessments, not a due diligence file standing in for one.

None of that requires a board to perform risk assessments itself. It requires confirming that one is genuinely happening, and a handful of questions get at that for each area where vendor risk tends to hide.

Compliance exposure is not settled by a vendor’s general certification alone. A vendor can be broadly compliant with industry standards and still be a poor regulatory fit for one specific institution. Directors should confirm that management has checked whether a vendor’s data retention and reporting practices meet the credit union’s specific regulatory obligations, rather than just its general reputation for compliance.

A Harder Question

Financial exposure shows up in a harder question than whether a vendor is solvent today. The real question is what happens to the credit union if that vendor fails tomorrow. IBM’s 2025 Cost of a Data Breach Report puts the average breach cost for a financial institution at $5.56 million, and that figure does not include the costs of service disruption in lost revenue or member trust. Directors should confirm that contract termination provisions genuinely protect the institution, that insurance coverage is adequate, and that someone has modeled how a disruption would affect revenue and member service. A vendor’s balance sheet only tells half of that story.

Reputational exposure surfaces at the seam between a vendor’s incident response plan and the credit union’s own member communication strategy. Whether a vendor’s misstep becomes a footnote or a genuine crisis usually comes down to how prepared the institution is to respond, not how prepared the vendor is.

Strategic exposure gets missed when nobody revisits a vendor relationship in light of where the credit union is actually headed. A vendor that made sense against a strategic plan three years ago may not make sense against the one the board approved last quarter, and periodic strategic review of vendor relationships, not only periodic compliance review, is what catches that kind of drift.

Where Technical Details Aren’t Needed

Technology and transaction exposure is the one area where a board genuinely does not need the technical detail itself. Directors do not need to understand data handoff points or exception handling procedures firsthand. They do need confirmation that someone with the expertise to evaluate those details is actually doing so, and that the findings come back to the board in terms directors can act on, rather than being buried in a technical appendix nobody reads.

The next time a due diligence summary lands on the board table, ask the harder question. Not whether the file is complete, but whether anyone has actually assessed what it means for this credit union’s particular exposure. That is the difference between checking a box and fulfilling an oversight duty.

Roberta Rodgers is vice president of compliance with Rochdale.

Facebook
Twitter
LinkedIn

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.