Kolena AI Agent
Vendor Due-Diligence Questionnaire Review
Turn a completed vendor due-diligence questionnaire and its evidence into a control-area coverage checklist, a gap log, and an overall risk rating - framed on the 2023 Interagency Third-Party Risk Management guidance, every value cited.
Impact
Turns a completed vendor questionnaire and its evidence into a coverage checklist, a severity-ranked gap log, and a defensible risk rating - with every finding cited to the response or exhibit it came from
per vendor
Volume fit
Works best for
banks and lenders assessing dozens to hundreds of third parties across onboarding and periodic reassessment cycles
Too small for
a one-off review of a single low-risk, no-data-access vendor
Typical inputs
Documents
- Completed vendor due-diligence questionnaire (DDQ)
- SOC 1 / SOC 2 report and any bridge (gap) letter
- Audited or interim financial statements
- Certificates of insurance
- Information security, business continuity, and disaster-recovery policies
- Subcontractor / fourth-party list
Systems
- Vendor risk / GRC platform
- Procurement system
- Document repository
Output
A per-vendor due-diligence assessment - a profiled engagement, an inherent-risk / criticality tier, a control-area coverage checklist, SOC / financial / security / resilience / insurance / subcontractor / privacy / regulatory findings, a consolidated gap-and-exception log, and an overall residual-risk rating and recommendation, each value cited to the questionnaire response or evidence exhibit
Delivered to
- Vendor risk / GRC platform
- Vendor risk committee package
- Contract-requirements memo
What it extracts
· 13 fields
- Form
Vendor Profile and Engagement Overview
The identifying spine of the relationship - who the third party is, the service it provides, whether it accesses bank systems or customer data, and whether it supports a critical activity - so a reviewer can orient before reading the assessment.
- Classification
Inherent Risk and Criticality Tier
The risk-based tier that sets how much diligence depth the engagement warrants, weighing criticality, data access, and consumer exposure per the risk-based posture of the 2023 Interagency guidance.
- Table
Due-Diligence Control-Area Coverage Checklist
The backbone of the review - one row per required control area from the 2023 Interagency guidance's due-diligence factors, each marked Addressed / Partially / Not addressed with the evidence cited and the gap noted.
- Form
Financial Stability Assessment
The third party's financial condition - statements provided, audit opinion, revenue and profitability trend, going-concern flags, and external ratings - because a distressed provider is more likely to fail or exit a critical activity.
- Form
Information Security Assessment
The security program - certifications and frameworks claimed, encryption, access controls and MFA, vulnerability and penetration testing, and incident history - assessing whether claims are backed by evidence, not just named.
- Form
SOC Report Review
The SOC attestation dissected - SOC 1 vs SOC 2, Type I vs II, trust-services criteria and period, currency and bridge letter, opinion and exceptions, CUECs, and carved-out subservice organizations - the most-relied-on diligence evidence.
- Form
Business Continuity and Disaster Recovery
Operational resilience - whether BCP/DR plans exist, the RTO and RPO, the last test date and result, and backup / redundancy - treating an untested plan as a limitation, since a vendor resilience failure becomes the bank's.
- Table
Insurance Coverage Verification
Coverage verified line by line - cyber, tech E&O, general liability, crime/fidelity, D&O, workers' comp - with limit vs required minimum, adequacy, expiration, and additional-insured status, flagging warranted coverage that is absent.
- Table
Subcontractor and Fourth-Party Risk
The fourth-party map - each material subcontractor, its function, whether it touches bank data, how the vendor oversees it, and any concentration or offshore concern - because the bank's risk does not stop at its direct vendor.
- Form
Data Privacy and Protection
How bank and customer data is handled and protected - data types, use limits, applicable privacy regimes (including GLBA safeguards), breach-notification timelines, subprocessors and cross-border transfer, and return / destruction on termination.
- Form
Regulatory and Compliance Posture
The third party's regulatory standing - licenses, examinations and enforcement actions, litigation, complaint handling, BSA/AML and sanctions where relevant, and the compliance-management system - a named due-diligence factor in the guidance.
- Table
Gap and Exception Log
The consolidated, actionable log - one row per gap, stale attestation, or unanswered item across the whole review, with severity, the guidance reference, and a concrete follow-up to close it.
- Classification
Overall Risk Rating and Recommendation
The overall residual-risk rating and recommendation - approve, approve with conditions, escalate, or do not proceed - weighing the criticality tier against the open high-severity gaps, so criticality and controls are judged together.
Prerequisites
- Your due-diligence questionnaire and the control areas your program requires
- Your insurance minimums and SOC-currency expectations for the criticality tier
- Any prior assessment of this vendor for comparison
Human review
A third-party risk analyst reviews the flagged gaps, the SOC and insurance findings, and the recommended rating before the assessment is finalized and sent to the vendor risk committee.
Where it fits
Third-party risk management (vendor due diligence)
Vendor onboarding / procurement - a prospective or existing third party returns a completed due-diligence questionnaire (DDQ) with supporting evidence (SOC reports, financial statements, insurance certificates, security and BCP/DR policies) by email, portal, or Drive folder
This step
Due-diligence review, gap identification, and risk rating
After
Who uses it
Grounded in
- Interagency Guidance on Third-Party Relationships: Risk Management (OCC Bulletin 2023-17, FRB SR 23-4, FDIC FIL-29-2023; 88 FR 37920, June 9, 2023; final June 6, 2023)verified as of 2026-07-22
- AICPA System and Organization Controls - SOC 2 (Trust Services Criteria, TSP Section 100) under SSAE No. 18verified as of 2026-07-22
- AICPA System and Organization Controls - SOC 1 (ICFR) under SSAE No. 18, AT-C Section 320verified as of 2026-07-22
- Gramm-Leach-Bliley Act, Section 501(b) - Interagency Guidelines Establishing Information Security Standards (service-provider oversight)verified as of 2026-07-22
- FFIEC IT Examination Handbook - Outsourcing Technology Services / Architecture, Infrastructure, and Operations (supervisory expectations for third-party and BCP/DR oversight)verified as of 2026-07-22
Related agents
Browse all agents →Third-Party Process Compliance Review
Review a vendor's process documents, SOPs, and scripts for a consumer-facing activity against your business process and consumer financial services law - process-alignment, control coverage, UDAAP, and regulatory exposure into a severity-ranked findings register, a corrective-action tracker, and an overall compliance determination, every observation cited.
Appraisal Review
Run every appraisal through a productized USPAP review and classify it Accept, Accept-with-conditions, or Reject, with each finding cited to the report.
Change-in-Terms & Cardholder-Agreement Review
Test a credit card change-in-terms notice against Regulation Z: every changed term summarized, the 45-day advance-notice window and right-to-reject verified, penalty rate increases justified and reevaluation-eligible, and every required disclosure present and cited.
See Vendor Due-Diligence Questionnaire Review on your documents
We'll run it against a file of yours and walk through every cited field.