DENVER–One analyst who believes NCUA oversight over third party vendors is inevitable is encouraging credit unions to drive the process rather than letting regulators do so.
The same analyst cautioned credit unions to recognize that vendor management is going to look substantially different two years from now.
Tony Ferris, managing partner with the Rochdale Group, is calling for what he called an “enhanced partnership model” for vendor management with input from credit unions and vendors. ‘
“This is not a regulatory issue,” he said. “This is a competitive advantage issue.”
Ferris told the joint World Council’s World CU Conference/CUNA America’s CU Conference that the objective must be to ensure that credit unions’ competitive advantage remains and that the unique value proposition of CUs is leveraged.
“ I believe we have a HUGE opportunity, and Rochdale believes there is a competitive advantage if we’re willing to take it,” said Ferris. “There’s never been a greater opportunity since the inception of credit unions than today. We, along with Milliennials, we’re all looking for values in our lives. But we have to stop grasping at the banking model to distinguish ourselves from what’s going on.”
Ferris said he would address vendor management from a strategic standpoint, not from a granular compliance point of view.
Vendor management, he said, is something every CU is doing in some fashion. “I will tell you, however, it is not the vendor management that will exist two years from now,” he said. “What we’re doing today is paper management. Fed Chairman Janet Yellin has said that (regulatory oversight of vendors) is a top priority for the Federal Reserve…Each and every regulator has vendor management as a priority for the next two years.”
What the Numbers Show
When it comes to vendor problems, Ferris cited a survey showing:
- 67% of companies extensively rely on vendors.
- 63% of the 450 data breaches were due to vendor failures.
- 82% indicated that they expended less than 20% of resources on vendor management.
How many vendors to credit unions on average have? According to Ferris, the average is between 200-300 vendors. “That’s a lot of touchpoints. How much time do you spend managing those 200-300 vendors today? Probably not a lot.”
Who is considered a vendor? Ferris said it’s anybody that provides substantive services to the credit union. “How far will this go? That’s yet to be defined, but it will certainly be more extensive than it is today.”
The challenge in vendor management, said Ferris, is how it cascades. The credit union might have 200 vendors, but each of those vendors might have 200 more. How far will regulators demand CUs go down into that chain to define risk is the key question, observed Ferris.
“If we have 67% heavy reliance on third parties today, is that number going up or down in the future? It’s going up,” he said, pointing to the rapid increase in vendors just in the technology space. “Regulators are all concerned about the consequences of just one hole in a system. And let’s face it, the regulators have not always been the best at defining what all of this is going to look like or what it will entail. But I can tell you I think there is some opportunity inherent in this change, that there is a new way to look at it.”
'Big, Big Binders'
Ferris said that today credit unions spend considerable time just doing due-diligence.
“That means getting big, big binders from vendors on a regular basis,” he said, noting that in most cases CUs have only a passing familiarity with all the paper. “The problem is there is no value add. The problem is that this diligence, if we allow it, is going to be made even bigger by regulators. What we want to do is leverage that. How do we make vendor management more of a partnership. How do we risk-weight these efforts.
Ferris said a survey of 130 CUs conducted prior to the meeting that many felt they had little to no control over vendors.
All of this is the result of the last recession, with Ferris noting all the regulators are saying they need to be “more proactive. The lessons regulators learned is that early and forceful action is needed, that there needs to be forward-looking assessments of risk, and they need to consider risks from a broader financial system.”
A Big Prediction
Ferris predicted that “NCUA will absolutely get the authority to oversee third party vendors,” and said that even if the agency does not it can still “hammer a CEO over the head” about any vendor with which it has an issue.
“The issue right now is how do we determine what the true expectations will be for both vendors and credit unions,” he said. “I would argue that there will be little that will affect our ability to serve members over the next few years more than this issue. What it will look like is yet to be truly known, but we do know in speaking with insiders that it is coming.”
So where will regulators have increased expectations? According to Ferris:
- Business case justification
- Expanded definition of vendors.
- Heightened due-diligence and performance monitoring.
- Dedicated staff and expertise.
- Stronger contractual language
- Clearly defined performance metrics.
- Escalation and termination procedures.
- Comprehensive Risk Management (ERM)
- Continuity planning (interconnected)
- Visibility and transparency
- Strong understanding and control of data.
Ferris noted that there will be involved in all this new vendor management, and that credit unions that think they are already doing all of these types of vendor management are mistaken.
“Get ready to ID all the vendors, and find out whose responsible for all vendor relationships (within the CU),” said Ferris.
'Not a Regulatory Problem'
If you think about the problem from a different direction, it’s not a regulatory problem, Ferris said.
“What I am asking you to consider is a new paradigm to shift the thought process from vendor management to vendor partnership,” said Ferris. “These processes are in place, and, frankly, they should be in place. How do we make this a win/win proposition? They want these issues dealt with as much as we do. The one thing they also don’t want is inconsistency; all that does is raise costs. So how do we as vendors and credit unions leverage what we’re trying to go after?
A proactive approach, he said, should be:
- Strategy-driven.
- Risk-based.
- Progressively managed.
- Value-based.
“We have to find a way to drive standardization. If we as an industry sit and do nothing, someone is going to do it for us, and they are called the regulator,” said Ferris.
