NASHVILLE—Credit unions can do a lot to improve their management of vendors, asserted a panel of experts who compared some CUs’ practices here to kids running a lemonade stand and a child playing with a gun.
During NAFCU’s annual meeting the panel of vendor management experts noted that it’s not just credit unions, but the majority of businesses that need to improve vendor management.
“In 2015 Verizon came out with a report stating that 70% of breaches investigated involved a third-party vendor. And Gartner found only 10% of companies have a vendor risk-management process,” said Joe Mitchell, senior systems engineer at BitSight.
The panelists addressed some common mistakes credit unions make in managing vendors and the contracts they sign with them.
“It can be like a kid playing with daddy’s handgun,” said John DeLoach—an attorney at the firm of Williams, Gautier, Gwynn, DeLoach & Sorenson—referring to how credit unions can follow vendor management letters sent out by NCUA and “check all the boxes” without understanding the true objective of NCUA’s instruction around properly managing vendor relationships.
Validate Pricing
Ben Mrva, EVP at Strategic Resource Management, said it is not unusual to see credit unions signing a 10-year contract without validating that the pricing in the contract they are about to sign is in line with today’s pricing.
“That’s OK to do that if you run lemonade stand, but it’s not OK if you run a credit union,” said Mrva.
Mrva said what can often lead to the bad practice is credit unions not being willing to go through a thorough competitive bidding process, due to the time that takes and due to the relationship they already have with the vendor.
“You have to make sure your contract prices are in line with today’s pricing and you can’t just sign the contract because the vendor told you it is a great deal,” said Mrva.
Meanwhile, Mitchell said additional issues related to CUs not properly managing their vendors include ensuring third parties are protecting members’ personal data.
“Security is not about four walls anymore,” said Mitchell. “You secured your organization, but what about the vendors you do business with who touch your sensitive data?”
Another mistake credit unions often make, according to Andy Vanderhoff, CEO of Quantitative, is mistakenly measuring vendor management success by audit findings.
“We will see credit unions deem themselves successful if they don’t have any audit findings around their vendor programs,” said Vanderhoff. “Yes, we want to keep the examiners happy, but the credit union needs to invest in vendor management so that it is a strategic advantage.”
Leverege Technology
In addition, Vanderhoff said he commonly sees credit unions not taking advantage of technology to help staff keep pace with the growing demands of vendor management.
Turning to what successful vendor management programs look like, Mitchell said that from a vendor security perspective credit unions that excel in the area form formal vendor risk teams.
“Once they have that team in place they establish specific contacts to address the topic of risk at each vendor,” Mitchell said. “So if there is an issue they know who to talk to at the company.”
That type of arrangement, said Mitchell, builds stronger, more open relationships with vendors around protecting member data.
“Greater transparency ultimately leads to less risk,” said Mitchell. “We will often hear credit unions say they don’t want their vendor to understand what their security risks are. But how are you going to fix the problem if the vendor does not know what the problems are?”
Mrva said another best practice in vendor oversight is making sure triggers are in place to alert the CU long before the contract is close to coming due, which provides more time to renegotiate—and ensuring they have the “right people” signing off on the contracts.
Mrva said he is aware of one credit union that had a contract in place for seven years, had no procedure in place to inform the CU the deal was maturing, and the contract basically auto-renewed.
“That gave the credit union a contract with pricing based on 14 years ago,” said Mrva. “The last conversation you want to have with your CEO is to tell him a contract that has not been managed for the last seven years just renewed and it was signed off by the same people who signed the original contract.”
