Vendor Due-Diligence Questionnaire Review

Turn a completed vendor due-diligence questionnaire and its evidence into a control-area coverage checklist, a gap log, and an overall risk rating - framed on the 2023 Interagency Third-Party Risk Management guidance, every value cited.

Banking / Lending

Turns a completed vendor questionnaire and its evidence into a coverage checklist, a severity-ranked gap log, and a defensible risk rating - with every finding cited to the response or exhibit it came from

per vendor

What it extracts

13 extraction fields

Vendor Profile and Engagement Overview
The identifying spine of the relationship - who the third party is, the service it provides, whether it accesses bank systems or customer data, and whether it supports a critical activity - so a reviewer can orient before reading the assessment.
Inherent Risk and Criticality Tier
The risk-based tier that sets how much diligence depth the engagement warrants, weighing criticality, data access, and consumer exposure per the risk-based posture of the 2023 Interagency guidance.
Due-Diligence Control-Area Coverage Checklist
The backbone of the review - one row per required control area from the 2023 Interagency guidance's due-diligence factors, each marked Addressed / Partially / Not addressed with the evidence cited and the gap noted.
Financial Stability Assessment
The third party's financial condition - statements provided, audit opinion, revenue and profitability trend, going-concern flags, and external ratings - because a distressed provider is more likely to fail or exit a critical activity.
Information Security Assessment
The security program - certifications and frameworks claimed, encryption, access controls and MFA, vulnerability and penetration testing, and incident history - assessing whether claims are backed by evidence, not just named.
SOC Report Review
The SOC attestation dissected - SOC 1 vs SOC 2, Type I vs II, trust-services criteria and period, currency and bridge letter, opinion and exceptions, CUECs, and carved-out subservice organizations - the most-relied-on diligence evidence.
Business Continuity and Disaster Recovery
Operational resilience - whether BCP/DR plans exist, the RTO and RPO, the last test date and result, and backup / redundancy - treating an untested plan as a limitation, since a vendor resilience failure becomes the bank's.
Insurance Coverage Verification
Coverage verified line by line - cyber, tech E&O, general liability, crime/fidelity, D&O, workers' comp - with limit vs required minimum, adequacy, expiration, and additional-insured status, flagging warranted coverage that is absent.
Subcontractor and Fourth-Party Risk
The fourth-party map - each material subcontractor, its function, whether it touches bank data, how the vendor oversees it, and any concentration or offshore concern - because the bank's risk does not stop at its direct vendor.
Data Privacy and Protection
How bank and customer data is handled and protected - data types, use limits, applicable privacy regimes (including GLBA safeguards), breach-notification timelines, subprocessors and cross-border transfer, and return / destruction on termination.
Regulatory and Compliance Posture
The third party's regulatory standing - licenses, examinations and enforcement actions, litigation, complaint handling, BSA/AML and sanctions where relevant, and the compliance-management system - a named due-diligence factor in the guidance.
Gap and Exception Log
The consolidated, actionable log - one row per gap, stale attestation, or unanswered item across the whole review, with severity, the guidance reference, and a concrete follow-up to close it.
Overall Risk Rating and Recommendation
The overall residual-risk rating and recommendation - approve, approve with conditions, escalate, or do not proceed - weighing the criticality tier against the open high-severity gaps, so criticality and controls are judged together.

Where it fits

Third-party risk management (vendor due diligence)

Upstream

Vendor onboarding / procurement - a prospective or existing third party returns a completed due-diligence questionnaire (DDQ) with supporting evidence (SOC reports, financial statements, insurance certificates, security and BCP/DR policies) by email, portal, or Drive folder

This step

Due-diligence review, gap identification, and risk rating

Downstream

  • Vendor risk committee / approval decision
  • Contract negotiation (control and remediation requirements flow into the contract)
  • Ongoing monitoring and periodic reassessment

What it needs

Documents

  • Completed vendor due-diligence questionnaire (DDQ)
  • SOC 1 / SOC 2 report and any bridge (gap) letter
  • Audited or interim financial statements
  • Certificates of insurance
  • Information security, business continuity, and disaster-recovery policies
  • Subcontractor / fourth-party list

Systems

  • Email
  • Vendor risk / GRC platform
  • Procurement system
  • Document repository

Prerequisites

  • Your due-diligence questionnaire and the control areas your program requires
  • Your insurance minimums and SOC-currency expectations for the criticality tier
  • Any prior assessment of this vendor for comparison

What it produces

A per-vendor due-diligence assessment - a profiled engagement, an inherent-risk / criticality tier, a control-area coverage checklist, SOC / financial / security / resilience / insurance / subcontractor / privacy / regulatory findings, a consolidated gap-and-exception log, and an overall residual-risk rating and recommendation, each value cited to the questionnaire response or evidence exhibit

Delivered to

  • Vendor risk / GRC platform
  • Vendor risk committee package
  • Contract-requirements memo

Review model

A third-party risk analyst reviews the flagged gaps, the SOC and insurance findings, and the recommended rating before the assessment is finalized and sent to the vendor risk committee.

Who uses it

Third-Party Risk ManagerVendor Risk AnalystProcurement Risk OfficerInformation Security / GRC AnalystCompliance Officer

Volume fit

Works best for

banks and lenders assessing dozens to hundreds of third parties across onboarding and periodic reassessment cycles

Too small for

a one-off review of a single low-risk, no-data-access vendor

Grounded in

  • Interagency Guidance on Third-Party Relationships: Risk Management (OCC Bulletin 2023-17, FRB SR 23-4, FDIC FIL-29-2023; 88 FR 37920, June 9, 2023; final June 6, 2023)verified as of 2026-07-22
  • AICPA System and Organization Controls - SOC 2 (Trust Services Criteria, TSP Section 100) under SSAE No. 18verified as of 2026-07-22
  • AICPA System and Organization Controls - SOC 1 (ICFR) under SSAE No. 18, AT-C Section 320verified as of 2026-07-22
  • Gramm-Leach-Bliley Act, Section 501(b) - Interagency Guidelines Establishing Information Security Standards (service-provider oversight)verified as of 2026-07-22
  • FFIEC IT Examination Handbook - Outsourcing Technology Services / Architecture, Infrastructure, and Operations (supervisory expectations for third-party and BCP/DR oversight)verified as of 2026-07-22

Changelog

  • July 2026

based on a production deployment at a commercial equipment lender

Related agents

Browse all agents →

See Vendor Due-Diligence Questionnaire Review on your documents

We'll run it against a file of yours and walk through every cited field.