top of page

Has Vendor Management Become Too Front-loaded?

Writer: Tiffany Villagomez
Tiffany Villagomez
3 hours ago
5 min read

Guest Editorial by Tiffany Villagomez, solutions consultant for ViClarity


 

At a glance

 

  • Vendor risk evolves after onboarding. Waiting for the next formal review can leave meaningful changes unaddressed.

  • Ongoing monitoring doesn’t mean repeating due diligence every quarter. Start with one question: What has changed since we last looked?

  • The people closest to a vendor often see changes first. Bring their insights together, use risk tolerance to guide decisions and address issues along the way.

Tiffany Villagomez, solutions consultant for ViClarity.
Tiffany Villagomez, solutions consultant for ViClarity.

Credit unions put a lot of work into choosing a vendor. They complete due diligence, review contracts, collect documentation and get the relationship established. Then, in many cases, the vendor’s risk isn’t revisited until the first formal review.


I understand why that happens. Vendor management is a large and complex undertaking, and many credit unions are still working through who owns each part of it. But the question I keep coming back to is this: Has vendor management become too front-loaded?


When most of the risk management work happens upfront and meaningful changes go unaddressed until a formal review, I think the answer is yes.


A Familiar Vendor Management Challenge


In my nearly 15 years working in credit union compliance, risk and audit, I have heard from credit unions of all sizes about the vendor management challenges they face. I also experienced many of those challenges firsthand while managing a vendor management program at a small-but-mighty credit union in South Texas.


I know what it feels like to pull information from multiple people and places just to figure out where any given vendor relationship stands. Now, working with credit unions on the consulting and technology sides, I see how common that pain point continues to be today.


But here’s the deal. Ongoing monitoring does not have to mean a full due diligence review every quarter. The underlying purpose is to maintain enough visibility to recognize when something meaningful has changed. A credit union might have a midyear conversation about its critical vendors or periodic check-ins with the departments that own those relationships.

The discussion does not have to recreate the annual review. It can start with one question: What has changed since we last looked?

 

Recognizing Change Takes a Team and Good Judgment


A risk assessment completed during onboarding represents a single point in time. It may no longer reflect the full risk picture as the credit union and its vendors grow, scale and innovate. Someone needs to recognize those moments of change when they occur and be equipped to decide whether that change matters.


Some changes will come from the vendor; others will come from the credit union. Has the vendor’s performance declined? Has the credit union started relying on the service more heavily? Is the vendor accessing or using data differently? Has an issue come up that changes how the credit union views the relationship?


Recognizing those changes takes input from across the credit union. Deciding what to do about them requires a clear understanding of its risk tolerance.


One person may oversee vendor management, but that doesn’t mean they can manage it well in isolation. Department owners often know their vendor relationships best. IT may know about an outage or security concern. Compliance may identify a regulatory issue affecting the service. Finance may notice an unexpected cost. Those observations need to become part of the broader vendor risk picture.


Documented risk tolerance then helps answer the next question: What does the credit union do about it? The same change in risk may be acceptable to one credit union and outside another’s tolerance. Does the relationship need closer attention, an additional control or a conversation with leadership? Is the credit union still comfortable with its exposure?


Connecting the Dots Before the Annual Review


Cultivating vendor information and insights from across the credit union can be tricky. Typically, the details are sitting in different departments, spreadsheets, email chains — or even more troublesome — someone’s memory. If one department has noticed recurring service issues and another knows about an outage, those observations may look minor on their own. Together, they may tell a different story.


That is where centralized technology can help. It gives the credit union a place to bring together vendor ownership, criticality, contracts, reviews, outstanding issues and changes so everyone has access to the same story.


Technology also supports vendor management workflows really well. But it should be said that even the best software can never replace the people closest to the relationship. The department owner still has to speak up when service declines. IT still has to share what it knows about an incident. A centralized hub gives those observations somewhere to go and provides an automated audit trail to document what changed and how the credit union responded.


Automated workflows and reminders help teams capture that information as it occurs throughout the year. That way, when the annual review comes around, the team isn’t suddenly trying to reconstruct 12 months of activity from files, emails and memory. Issues have already been documented and addressed along the way. The formal review can be a deeper assessment of the relationship instead of a massive information-gathering exercise.


Start With A Few Practical Changes


  • Identify the relationships that warrant closer attention. Start with critical and higher-risk vendors rather than trying to monitor every relationship the same way. Consider operational dependency, access to member or credit union data, member impact, use of artificial intelligence or automated decision-making and how difficult the service would be to replace.

  • Establish periodic checkpoints. A mid-year or quarterly touchpoint with the departments that own key vendor relationships can be enough to surface changes in performance, incidents, service levels, data use or operational dependency.

  • Define what should trigger another look. A cybersecurity incident, recurring service issue, significant change in the vendor's operations, regulatory developments or a change in how the credit union uses the service may warrant revisiting the risk assessment before the next scheduled review.

  • Give department owners a way to report changes. The people closest to the vendor relationship are often the first to recognize when something is different. Make it clear what information should be escalated, where it should go and who is responsible for determining the appropriate response.

  • Revisit the risk, not necessarily the entire review. When something changes, the response does not always need to be another full due diligence exercise. The credit union can determine whether the change affects the vendor's risk profile, whether existing controls remain appropriate and whether additional monitoring or action is necessary.

 

Putting Full-Cycle Vendor Views Within Reach


No credit union can anticipate every vendor failure or cyber incident. Technology cannot guarantee that either. But it can help bring available information together so the credit union can address manageable issues while they are still manageable.


The people closest to the relationship have valuable insights. Technology provides a way to capture and share them throughout the year. With that knowledge and those tools available, vendor management is poised to move from front-loaded to full-cycle. The opportunity now is to make that approach standard practice.


Tiffany Villagomez, CUCE, is a solutions consultant for ViClarity, which provides governance, risk and compliance consulting, as well as the technology to manage these disciplines from a central hub, to credit unions and other highly regulated industries.

bottom of page