Kolena AI Agent

Vendor Due-Diligence Questionnaire Review

Turn a completed vendor due-diligence questionnaire and its evidence into a control-area coverage checklist, a gap log, and an overall risk rating - framed on the 2023 Interagency Third-Party Risk Management guidance, every value cited.

Banking / LendingCompliance Testing

Impact

Turns a completed vendor questionnaire and its evidence into a coverage checklist, a severity-ranked gap log, and a defensible risk rating - with every finding cited to the response or exhibit it came from

per vendor

Volume fit

Works best for

banks and lenders assessing dozens to hundreds of third parties across onboarding and periodic reassessment cycles

Too small for

a one-off review of a single low-risk, no-data-access vendor

Typical inputs

Documents

  • Completed vendor due-diligence questionnaire (DDQ)
  • SOC 1 / SOC 2 report and any bridge (gap) letter
  • Audited or interim financial statements
  • Certificates of insurance
  • Information security, business continuity, and disaster-recovery policies
  • Subcontractor / fourth-party list

Systems

  • Email
  • Vendor risk / GRC platform
  • Procurement system
  • Document repository

Output

A per-vendor due-diligence assessment - a profiled engagement, an inherent-risk / criticality tier, a control-area coverage checklist, SOC / financial / security / resilience / insurance / subcontractor / privacy / regulatory findings, a consolidated gap-and-exception log, and an overall residual-risk rating and recommendation, each value cited to the questionnaire response or evidence exhibit

Delivered to

  • Vendor risk / GRC platform
  • Vendor risk committee package
  • Contract-requirements memo

What it extracts

· 13 fields
  • Form

    Vendor Profile and Engagement Overview

    The identifying spine of the relationship - who the third party is, the service it provides, whether it accesses bank systems or customer data, and whether it supports a critical activity - so a reviewer can orient before reading the assessment.

  • Classification

    Inherent Risk and Criticality Tier

    The risk-based tier that sets how much diligence depth the engagement warrants, weighing criticality, data access, and consumer exposure per the risk-based posture of the 2023 Interagency guidance.

  • Table

    Due-Diligence Control-Area Coverage Checklist

    The backbone of the review - one row per required control area from the 2023 Interagency guidance's due-diligence factors, each marked Addressed / Partially / Not addressed with the evidence cited and the gap noted.

  • Form

    Financial Stability Assessment

    The third party's financial condition - statements provided, audit opinion, revenue and profitability trend, going-concern flags, and external ratings - because a distressed provider is more likely to fail or exit a critical activity.

  • Form

    Information Security Assessment

    The security program - certifications and frameworks claimed, encryption, access controls and MFA, vulnerability and penetration testing, and incident history - assessing whether claims are backed by evidence, not just named.

  • Form

    SOC Report Review

    The SOC attestation dissected - SOC 1 vs SOC 2, Type I vs II, trust-services criteria and period, currency and bridge letter, opinion and exceptions, CUECs, and carved-out subservice organizations - the most-relied-on diligence evidence.

  • Form

    Business Continuity and Disaster Recovery

    Operational resilience - whether BCP/DR plans exist, the RTO and RPO, the last test date and result, and backup / redundancy - treating an untested plan as a limitation, since a vendor resilience failure becomes the bank's.

  • Table

    Insurance Coverage Verification

    Coverage verified line by line - cyber, tech E&O, general liability, crime/fidelity, D&O, workers' comp - with limit vs required minimum, adequacy, expiration, and additional-insured status, flagging warranted coverage that is absent.

  • Table

    Subcontractor and Fourth-Party Risk

    The fourth-party map - each material subcontractor, its function, whether it touches bank data, how the vendor oversees it, and any concentration or offshore concern - because the bank's risk does not stop at its direct vendor.

  • Form

    Data Privacy and Protection

    How bank and customer data is handled and protected - data types, use limits, applicable privacy regimes (including GLBA safeguards), breach-notification timelines, subprocessors and cross-border transfer, and return / destruction on termination.

  • Form

    Regulatory and Compliance Posture

    The third party's regulatory standing - licenses, examinations and enforcement actions, litigation, complaint handling, BSA/AML and sanctions where relevant, and the compliance-management system - a named due-diligence factor in the guidance.

  • Table

    Gap and Exception Log

    The consolidated, actionable log - one row per gap, stale attestation, or unanswered item across the whole review, with severity, the guidance reference, and a concrete follow-up to close it.

  • Classification

    Overall Risk Rating and Recommendation

    The overall residual-risk rating and recommendation - approve, approve with conditions, escalate, or do not proceed - weighing the criticality tier against the open high-severity gaps, so criticality and controls are judged together.

Prerequisites

  • Your due-diligence questionnaire and the control areas your program requires
  • Your insurance minimums and SOC-currency expectations for the criticality tier
  • Any prior assessment of this vendor for comparison

Human review

A third-party risk analyst reviews the flagged gaps, the SOC and insurance findings, and the recommended rating before the assessment is finalized and sent to the vendor risk committee.

Where it fits

Third-party risk management (vendor due diligence)

Vendor onboarding / procurement - a prospective or existing third party returns a completed due-diligence questionnaire (DDQ) with supporting evidence (SOC reports, financial statements, insurance certificates, security and BCP/DR policies) by email, portal, or Drive folder

This step

Due-diligence review, gap identification, and risk rating

After

Vendor risk committee / approval decision
Contract negotiation (control and remediation requirements flow into the contract)
Ongoing monitoring and periodic reassessment

Who uses it

Third-Party Risk ManagerVendor Risk AnalystProcurement Risk OfficerInformation Security / GRC AnalystCompliance Officer

Grounded in

  • Interagency Guidance on Third-Party Relationships: Risk Management (OCC Bulletin 2023-17, FRB SR 23-4, FDIC FIL-29-2023; 88 FR 37920, June 9, 2023; final June 6, 2023)verified as of 2026-07-22
  • AICPA System and Organization Controls - SOC 2 (Trust Services Criteria, TSP Section 100) under SSAE No. 18verified as of 2026-07-22
  • AICPA System and Organization Controls - SOC 1 (ICFR) under SSAE No. 18, AT-C Section 320verified as of 2026-07-22
  • Gramm-Leach-Bliley Act, Section 501(b) - Interagency Guidelines Establishing Information Security Standards (service-provider oversight)verified as of 2026-07-22
  • FFIEC IT Examination Handbook - Outsourcing Technology Services / Architecture, Infrastructure, and Operations (supervisory expectations for third-party and BCP/DR oversight)verified as of 2026-07-22

Related agents

Browse all agents →

See Vendor Due-Diligence Questionnaire Review on your documents

We'll run it against a file of yours and walk through every cited field.