Last Reviewed: February, 2019
Credit unions today are benefiting widely from the use of vendors, which offer a variety of services. Data processing, lending services, ALM and Internet banking are just a few of the many services outsourced. Using third parties allows the credit union to expand its services and leverage the skills and expertise of others in a cost effective way.
Outsourcing demands a good business plan, however, one that includes a proper self assessment, due diligence of the vendor and proper controls. Here are some questions and answers that highlight the content of the NCUA’s recently issued letter to its examiners in evaluating a credit union’s third party relationships.
Q. Why are third party relationships under greater scrutiny today?
A: Third party relationships have always been a matter of concern to regulators. For example, NCUA guidance was issued back to 2001 covering risk management for outsourcing technology. Sharing a credit union’s member account information with data processors operating outside the credit union’s four walls was recognized as a riskier venture, but at the same time it was seen as logical, necessary and good business sense. That logic continues to apply today, but on a broader scale for both complex as well as less sophisticated credit unions. Unfortunately, the wider use of vendors has also led to situations where a more thorough approach in assessing strengths of the credit union as well as the third parties should have been employed to avoid what has resulted in troublesome situations for the credit unions involved — and for the share insurance fund.
Q. Has the NCUA issued guidance for an effective third party program?
A: Yes. In December 2007, the NCUA issued Letter to Credit Unions No. 07-CU-13, which contains guidance provided to its field examiners to use in assessing a credit union’s approach to using third parties. In early April, the NCUA also made available the questionnaire/checklist that the examiners will use to document the review. Both are readily available on the NCUA Web site and within the MCUL’s League InfoSight under the Board Responsibilities channel.
Q. How should a credit union organize its approach for an effective program?
A: The NCUA Letter outlines its guidance into three elements which should assist a credit union in organizing its own approach. The three elements are 1) Risk Assessment and Planning; 2) Effective Due Diligence; and 3) Risk Measurement, Monitoring and Control.
Q: What is Risk Assessment and Planning?
A: While most folks often jump right to the second element, Due Diligence, risk assessment and planning is actually the proper first step in the process. It is simply an assessment of the credit union itself. Questions such as whether the activity is critical to the mission of the credit union and its importance to the strategic business plan should be the starting point in any board discussion. Quickly thereafter is an assessment of the level of risk this activity presents in the usual risk-based examination categories (credit risk, interest rate risk, liquidity risk etc.). The presence of staff experience despite outsourcing is very important to ensure quality monitoring and a solid understanding of any reports provided by the vendor. Other dynamics include the impact on membership, a cost/benefit analysis, and an evaluation of costs involved with monitoring and support of the third party after the contract is implemented.
Q: What concerns are found under the second element, Due Diligence?
A: The focus of this step is primarily on the third party provider: its experience in providing the service being considered, its reputation, financial strength and compliance with any laws, regulations and licensure requirements. In addition, is its business model a sound one, or has the economy or technology passed it by? Is it viable for the term of the relationship and what alternatives are available should the relationship sour?
Q: The contract with the third party is important — what should it address?
A: The provisions of any service contract with a third party will depend in large part on the complexity of the relationship. It should always outline the scope of the arrangement and the responsibilities of both parties. Other issues to be addressed include service level and related measurement standards; penalties for lack of performance; ownership of the work product; audit rights; data security; provisions for business resumption and contingency planning; how member complaints will be handled; dispute resolution; and default, termination and escape clauses. To protect the interests of the credit union, important contracts, especially those offered by the vendor, should always be reviewed by the credit union’s own legal counsel.
Q: The final element is Risk Measurement, Monitoring and Control — what is important here?
A: The starting point is to have board-approved policies in place in dealing with third parties. The various risks have been assessed as part of the initial step and the credit union should have created controls to help mitigate these risks. This also means having knowledgeable staff assigned to monitor the relationship, receiving periodic reports from the vendor and providing reports to the board on activity and performance of the contract. Verification of third party reports is an important part of this element as well. Particular services will demand other types of monitoring and verification to address related risks.
Q: Will scope and complexity of the credit union be taken into consideration in the third party evaluation?
A: Yes, the NCUA letter states that examiners should ensure credit unions have addressed the three elements “in a manner commensurate with their size, complexity, and risk profile.” It also states, “Smaller and less complex credit unions may develop alternative methods of accomplishing due diligence, while credit unions utilizing a time tested third party relationship may already have addressed these considerations over time.” So there is room for flexibility in a credit union’s approach. But, as always, any approach needs to be thought through with the final decisions and rationale documented.
|