Member Login

THE MEMO

DAKOTA CREDIT UNION ASSOCIATION
  • Advocacy
    • Bill Tracking
    • Grassroots Action Center
    • Political Fundraising
  • Compliance
    • Compliance Resources
    • Compliance Solutions >
      • AffirmX
      • ComplySight
      • CU CMS
      • CU PolicyPro
      • InfoSight360
      • Jackson Lewis
      • PayLynxs
      • RecoveryPro
      • ViClarity
      • Training
    • The Memo: Compliance
  • Member Resources
    • DakCU Awards
    • Financial Well-Being for All
    • Professional Development >
      • Chapters
      • Emerging Leader Program
      • Sales CU Training
    • Strategic Partners >
      • CAP Program Directory
      • Compliance Solutions
      • Pee Wee and Friends®
    • SWAP: CU Awareness
  • News & Events
    • The Memo
    • Events Calendar
    • Annual Summit >
      • Agenda
      • Crashers
      • Presenters
      • Sponsors
    • GAC
    • Par for the PAC
    • Sales CU Training
  • About Us
    • Board of Directors
    • Contact Us
    • DakCU Foundation >
      • Donor Wall
      • Foundation Golf Scramble
      • Memorials
      • Foundation Sweepstakes
    • DakCU Health Benefits Trust

Third-Party Risk Management

8/22/2024

 
Picture
​As credit unions navigate the complexities of an increasingly digital and vendor-rich world, the imperative for robust TPRM is clear. 
As the financial services landscape becomes ever-more virtual, cybersecurity risk is looming larger than ever before. Much of this has to do with the added layer of third-party partnership. The more credit unions rely on a patchwork of fintech and other vendors to provide the best possible member experience, the larger the potential attack surface becomes. Indeed, Verizon’s latest investigation revealed 15% of all breaches this year involve a third-party, a whopping 68% increase from last year.

Essentially, this boils down to one hard-and-fast truth for credit unions today: Third-party risk management (TPRM) is no longer a cherry-on-top task; it’s an imperative.

What is Third-Party Risk Management?
TPRM is the identification and management of the risks that come with vendor relationships. It’s far from new; in fact, most tenured governance, risk and compliance (GRC) professionals have at least some exposure to the strategy.

What’s changing, however, is TPRM’s importance to examiners. The recent surge of digitalization, as well as the aforementioned reliance on more third parties, has heightened regulator interest.
It’s pretty clear why regulatory bodies are paying greater attention to TPRM. In addition to growing in number, TransUnion found that third-party data breaches are often more severe than a direct compromise of a credit union’s systems.

This may be due to the fact that vendors often allow attackers an easier way into their systems—which are often connected to the systems of their clients. That’s because large organizations—and especially those in the highly regulated field of financial services—have comprehensive cybersecurity protections in place. A smaller third party may not have the same culture of data protection and cybersecurity, and therefore, be easier to penetrate.

Two Key Tenets for Credit Union TPRM Programs
The first component to a successful TPRM program is a solid governance structure whereby the board and credit union executives are ultimately responsible for TPRM activities. The TPRM policy should be documented and reviewed periodically. Providing the board and executives with a comprehensive view of their TP universe, including metrics, is a key component. Ideally this documentation would be included in the board pack and present on the scheduled governance agenda.

Another key component to sound TPRM is maintaining an up-to-date vendor registry. Credit unions should assess their third parties from a risk and criticality perspective on an ongoing basis. Not all vendors will require the same frequency of check-in; criticality classification can drive the depth of ongoing due diligence. And it’s a step no credit union will want to miss. Segmenting criticality often makes TPRM more manageable, particularly for smaller management, risk and compliance teams.

TPRM Backed by Operational Resilience
Of course, the greatest protection against the fallout of a third-party incident is the development of sound operational resilience, encompassing plans for identifying, controlling for and swiftly responding to major incidents.
Credit unions should meticulously gauge their resilience to third-party disruptions, ensuring robust measures are in place to safeguard both their business operations and the interests of their members. Central to this concept is understanding the potential impact of various incidents along a risk spectrum, as well as defining the credit union’s overall risk tolerance.

The People Challenge of Managing Third-Party Risks
One of the main hurdles to effective TPRM programs is inexperience. Credit unions that lack GRC leadership with expertise in non-financial risks are at a disadvantage. What’s more, adding skilled risk and compliance staff, with the expertise, the know-how (and the chops) to successfully challenge inadequate vendor arrangements is not an easy task. These leaders have to have the backbone and assuredness of mind to effectively enforce appropriate oversight mechanisms with all kinds of vendors—from local office custodians to global core processors.

As credit unions navigate the complexities of an increasingly digital and vendor-rich world, the imperative for robust TPRM is clear. The rise in third-party breaches underscores the necessity of comprehensive TPRM strategies that not only identify and mitigate risks but also ensure operational resilience and regulatory compliance. By prioritizing TPRM, credit unions can better safeguard their operations and member interests, fortifying themselves against the evolving landscape of cybersecurity threats.
 
The Dakota Credit Union Association’s dues-supported compliance solution –  ViClarity – is a world leader in credit union compliance. If you have questions about establishing your members-only account with ViClarity, click here for detailed instructions or contact John Alexander in the DakCU office.
Picture

Comments are closed.

    The Memo

    The Memo is DakCU's newsletter that keeps
    ​credit union professionals updated on current news and information. ​

    Memo Home

    Want the Memo delivered straight to your inbox?
    Sign Up Now


    Archives

    May 2025
    April 2025
    March 2025
    February 2025
    January 2025
    December 2024
    November 2024
    October 2024
    September 2024
    August 2024
    July 2024
    June 2024
    May 2024
    April 2024
    March 2024
    February 2024
    January 2024
    December 2023
    November 2023
    October 2023
    September 2023
    August 2023
    July 2023
    June 2023
    May 2023
    April 2023
    March 2023
    February 2023
    January 2023
    December 2022
    November 2022
    October 2022
    September 2022
    August 2022
    July 2022
    June 2022
    May 2022
    April 2022
    March 2022
    February 2022
    January 2022
    December 2021
    November 2021
    October 2021
    September 2021
    August 2021
    July 2021
    June 2021
    May 2021
    April 2021
    March 2021
    February 2021
    January 2021


    Categories

    All
    Action Alert
    Advocacy
    Awards
    Awareness Campaign
    Compliance
    CUPAC/CULAC
    Dakota CUs Give Back
    Events
    Financial Well Being
    Foundation
    Fraud Alert
    Grants
    In The Spotlight
    Marketing Tips
    Member Solutions
    Miscellaneous
    ND Legislative Update
    News And Notes
    President's Perspective
    Press Releases
    SD Legislative Update
    Webinars

Copyright Dakota Credit Union Association.  All Rights Reserved.
2005 N Kavaney Dr - Suite 201 | Bismarck, North Dakota 58501
Phone: 
800-279-6328 | [email protected] | sitemap | privacy policy
Picture
Picture
Picture
Picture
  • Advocacy
    • Bill Tracking
    • Grassroots Action Center
    • Political Fundraising
  • Compliance
    • Compliance Resources
    • Compliance Solutions >
      • AffirmX
      • ComplySight
      • CU CMS
      • CU PolicyPro
      • InfoSight360
      • Jackson Lewis
      • PayLynxs
      • RecoveryPro
      • ViClarity
      • Training
    • The Memo: Compliance
  • Member Resources
    • DakCU Awards
    • Financial Well-Being for All
    • Professional Development >
      • Chapters
      • Emerging Leader Program
      • Sales CU Training
    • Strategic Partners >
      • CAP Program Directory
      • Compliance Solutions
      • Pee Wee and Friends®
    • SWAP: CU Awareness
  • News & Events
    • The Memo
    • Events Calendar
    • Annual Summit >
      • Agenda
      • Crashers
      • Presenters
      • Sponsors
    • GAC
    • Par for the PAC
    • Sales CU Training
  • About Us
    • Board of Directors
    • Contact Us
    • DakCU Foundation >
      • Donor Wall
      • Foundation Golf Scramble
      • Memorials
      • Foundation Sweepstakes
    • DakCU Health Benefits Trust