Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Third-Party Risk

Vendor Due Diligence KRIs: Missing Evidence, Overdue Reviews, and High-Risk Exceptions

Your TPRM program tracks vendor performance. These 6 KRIs track whether your due diligence process itself is working — review completion rates, evidence currency, exception handling, and the program health gaps examiners find most often.

Table of Contents

TL;DR

  • Most TPRM programs track vendor performance. Fewer track whether the diligence program itself is functioning — whether reviews are happening on time, evidence is current, and exceptions are being resolved.
  • Six program health KRIs — overdue review rate, missing evidence rate, exception aging, questionnaire return rate, high-risk exception documentation quality, and unreviewed new vendor rate — tell you if third-party oversight is real or theoretical.
  • The 2023 Interagency Guidance on Third-Party Relationships requires ongoing monitoring proportional to risk; programs still running annual-only reviews for critical vendors are out of alignment with current examination expectations.
  • American Express paid a $15 million civil penalty in 2023 for third-party oversight governance failures — the OCC has made clear that vendor oversight is not a checkbox activity.

The TPRM Program Health Problem

Most organizations with a TPRM program know which vendors are risky. They have a Tier 1 list, a review schedule, questionnaire templates, and a vendor inventory spreadsheet.

What fewer organizations have is a way to tell whether the program is actually being executed. Are reviews happening on time? Is the evidence collected current and substantive? Are exceptions being tracked to closure, or quietly left open from one review cycle to the next?

This matters because examiner expectations have shifted. The 2023 Interagency Guidance on Third-Party Relationships, issued jointly by the OCC, Federal Reserve, and FDIC, moved evaluation from “do you have a vendor list?” toward “show me your lifecycle governance.” The exam question is no longer “do you review vendors?” — it’s “how do you know your review program is actually working?”

Vendor due diligence KRIs answer that question. They measure the program’s own operational health: completion rates, evidence currency, exception handling, and coverage gaps. They’re distinct from vendor performance KRIs, which track what vendors are doing. These track what your team is doing.


Why This Is an Enforcement Issue, Not a Best-Practice Issue

In July 2023, following an OCC examination, American Express received a $15 million civil money penalty for failures in third-party relationship governance and oversight. The action focused on inadequate risk management practices for a specific third-party relationship — documentation gaps, oversight failures, and insufficient escalation of warning signs that were present but not acted on.

The Federal Reserve’s May 2024 TPRM supervisory report identified the most common deficiencies in examined institutions: inadequate documentation of initial due diligence, gaps in ongoing monitoring, and insufficient board-level oversight of critical vendor relationships. These are the findings that generate MRAs and, in repeated cases, formal enforcement actions.

Vendor due diligence KRIs are how you see these patterns in your own program before an examiner does.


The 6 Vendor Due Diligence KRIs

KRI 1: Overdue Periodic Review Rate

What it measures: The percentage of scheduled vendor reviews — annual assessments, SOC report evaluations, security questionnaire updates, financial statement reviews — not completed within the program’s defined window.

Overdue reviews are the most common TPRM finding across all institutional tiers. A review schedule that exists on paper but runs consistently behind is evidence that the program is theoretical, not operational. Examiners who find six of ten critical vendor reviews more than 60 days overdue treat it as a governance failure at the program level, not a timing inconvenience.

Segment by tier:

TierGreenAmberRed
Tier 1 (Critical)0% overdue1–5% with active remediation plan>5%, or any Tier 1 review >60 days overdue
Tier 2<5% overdue5–15%>15%
Tier 3<15% overdue15–30%>30%

Data source: TPRM tracker or vendor management system with scheduled review dates. Owner: TPRM Program Lead / Vendor Management.


KRI 2: Missing or Stale Evidence Rate

What it measures: The percentage of vendor files — particularly Tier 1 and 2 vendors — where required diligence artifacts are absent, expired, or listed as pending beyond a defined resolution window.

Evidence staleness is the gap between “we did a review” and “we have current documentation that supports the review conclusion.” A SOC 2 report from 28 months ago used to support a current risk conclusion tells you about the control environment from well before now. An examiner asking for evidence of vendor oversight who receives a stale report will question whether ongoing monitoring is actually occurring.

Standard staleness thresholds:

  • SOC 2 reports: >12 months from issue date (bridge letters can extend currency)
  • Security questionnaire responses: >12 months or after a material system/service change
  • Financial statements: >18 months from fiscal year end
  • Vendor penetration test summaries: >24 months
  • Regulatory compliance certifications: >12 months or per certification standard
ThresholdCriteria
Green<5% of Tier 1/2 vendor files with stale or missing required evidence
Amber5–15%
Red>15%, or any Tier 1 vendor missing a SOC 2 with no active remediation plan

Owner: TPRM Analyst / Vendor Management.


KRI 3: Exception Aging — Open Remediation Commitments

What it measures: The count and age of open remediation commitments from vendor due diligence reviews — questionnaire deficiencies, SOC report exceptions, security gaps — that have not been resolved by the committed date.

When an assessment surfaces a deficiency and the vendor provides a remediation commitment, that commitment requires tracking to closure. The failure mode is common: commitments get logged, vendors say they’ll address the issue next quarter, and nobody follows up until the same finding appears in the following assessment cycle. Three consecutive annual reviews showing the same open SOC exception is not a minor documentation issue — it’s a governance finding.

DimensionAmber TriggerRed Trigger
Open commitments by Tier 1 vendorAny open commitment >90 daysAny critical finding commitment >60 days
On-time closure rate<80% of commitments closed on schedule<60%
Recurring exceptions1 recurring finding with active CAP2+ recurring findings, or any recurring finding without an active CAP

Data source: Due diligence tracker with remediation tracking fields: date identified, committed close date, actual close date, and evidence of closure. Owner: TPRM / Compliance.


KRI 4: Questionnaire Return Rate and Completion Timeliness

What it measures: The percentage of vendor questionnaires returned complete within the required window — and the percentage requiring multiple follow-up rounds.

Questionnaire completion rate is a proxy for vendor engagement quality. A vendor that requires four follow-up cycles to return an incomplete questionnaire is a different risk profile than one that returns complete documentation in 10 business days. At the aggregate program level, a chronically low completion rate signals that your program lacks the relationship management capacity to actually execute its diligence obligations.

ThresholdCriteria
Green>85% of Tier 1/2 questionnaires returned complete within 15 business days
Amber70–85% return rate, or >15% requiring more than three follow-ups
Red<70% return rate, or any Tier 1 questionnaire >30 business days outstanding without exemption

Owner: TPRM Analyst.

The quality of what you send affects completion rate and evidence quality. If vendors are routinely returning incomplete questionnaires, the design of the questionnaire itself and what to verify when responses come back are foundational issues worth addressing before adjusting thresholds.


KRI 5: High-Risk Exception Volume and Documentation Quality

What it measures: The count and documentation completeness of high-risk or policy exceptions approved in vendor reviews — cases where a vendor was onboarded or continued despite failing one or more diligence criteria.

Exception approval is a legitimate governance decision when it’s made by the right authority, with documented rationale, defined monitoring conditions, and an expiration date. The problem is exceptions that accumulate without documentation, expire without review, or get tacitly renewed without going back through the approval process. An exception binder that contains eight “pending remediation” entries from 18 months ago is not a functioning exception program — it’s an evidence gap.

What this KRI captures:

  • Count of open high-risk exceptions by tier and risk category
  • Percentage of exceptions with complete documentation: rationale, approval authority, conditions, expiration date, monitoring requirement
  • Average age of open exceptions (exceptions >12 months without formal renewal signal program drift)
  • Percentage of expired exceptions explicitly renewed vs. silently continuing
ThresholdCriteria
GreenAll high-risk exceptions fully documented; no exceptions expired without renewal review in the quarter
AmberAny exception missing one documentation element; >2 expired without formal renewal
Red>3 undocumented Tier 1/2 exceptions; any exception where the approval authority doesn’t match documented thresholds

Owner: TPRM / Compliance. Approval authority thresholds should be defined in the TPRM policy and mapped to vendor tier and exception severity.


KRI 6: Unreviewed New Vendor Rate

What it measures: The percentage of vendors activated in the period — particularly Tier 1 and 2 — that went live without completed pre-activation due diligence.

This KRI catches the gap between vendor contracting and vendor risk assessment. In organizations that move quickly, vendor contracts sometimes get signed and services go live before the TPRM team has completed its review. When that happens for a Tier 1 vendor, it is an immediate exam finding: the relationship was activated without documented risk review.

ThresholdCriteria
Green0% of Tier 1 vendors activated without completed pre-activation diligence
AmberAny new Tier 2 vendor activated with an in-progress (not completed) review and a documented remediation timeline
RedAny Tier 1 vendor activated without completed diligence, or any vendor where review was waived without documented approval authority

Owner: TPRM Program Lead, coordinating with Vendor Contracting and Procurement. Any Tier 1 red breach is an immediate CRO or CCO notification, not a monthly KRI report item.


What the 2023 Interagency Guidance Actually Requires

The 2023 Interagency Guidance covers five lifecycle stages: planning, due diligence, contracting, ongoing monitoring, and termination. Each stage has documentation expectations. The ongoing monitoring stage is where most programs fall short in exam settings — not because monitoring isn’t happening, but because it can’t be evidenced.

The guidance is explicit that ongoing monitoring should be proportionate to risk: more frequent and more intensive for critical vendors, lighter for low-risk relationships. For critical vendors, this means active KRI monitoring between annual assessments — tracking the program health metrics above, not just waiting for the annual cycle.

For EU-connected organizations, DORA — enforceable since January 2025 under Article 28 — imposes a similar continuous monitoring obligation for ICT third-party service providers. Organizations subject to both frameworks should map their due diligence KRIs to the specific documentation requirements of each.

The Federal Reserve’s May 2024 supervisory observations identified that institutions with the strongest TPRM programs shared a common trait: they could produce trend data and evidence chains on demand, not just point-in-time snapshots. That’s exactly what a due diligence KRI program produces — a documented trail showing which vendors were reviewed when, what evidence was collected and whether it was current, and how exceptions and deficiencies were handled.


How Diligence KRIs Complement Vendor Performance KRIs

Vendor due diligence KRIs and vendor performance KRIs measure different things and should be tracked in parallel.

Vendor performance KRIs (SLA compliance, incident rates, financial health signals) tell you if a vendor’s service delivery is deteriorating. The critical vendor KRI framework covers that tier in depth.

Vendor due diligence KRIs tell you if your oversight program is functioning as designed. A vendor can have a perfect SLA track record and still have a due diligence file with a two-year-old SOC 2, an open questionnaire, and three unresolved remediation commitments. Examiners review both — and a clean vendor track record doesn’t excuse a broken diligence program.

When both KRI sets are functioning, the combination produces the evidence chain regulators expect: here is the vendor’s performance trend, and here is our documented diligence trail confirming we were monitoring it throughout.


So What?

Vendor due diligence KRIs answer the question every TPRM program leader should be able to answer at any time: is the program actually being executed, or does it exist mainly on paper?

The six KRIs above — overdue review rate, missing evidence rate, exception aging, questionnaire completion, exception documentation quality, and unreviewed new vendor rate — provide that visibility. Each one surfaces a program health failure that is unlikely to appear on a vendor performance dashboard.

Before your next exam, test yourself against these KRIs. If you can’t pull the numbers within a day, the data infrastructure for this monitoring doesn’t exist — and that itself is a finding waiting to happen.

For teams building or upgrading vendor diligence tracking, the Third-Party Risk Management (TPRM) Kit includes a vendor review tracker, evidence collection templates, exception documentation structure, and a TPRM program health dashboard designed for both management and board reporting. Get it at buy.stripe.com/14A14g8Bd01dazP4mO6J204.

Related reading:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is the difference between vendor performance KRIs and vendor due diligence KRIs?
Vendor performance KRIs measure what vendors are doing — SLA compliance, incident frequency, uptime, customer complaints. Vendor due diligence KRIs measure what your TPRM program is doing — whether reviews are being completed on schedule, whether evidence is current, whether exceptions are documented and resolved. Both are necessary. One tells you if vendors are performing; the other tells you if your oversight program is functioning.
What counts as 'overdue' for a periodic vendor review?
Most programs define an annual review as overdue when not completed within 30 days of the scheduled anniversary date. Measure as a percentage of scheduled reviews: <5% overdue for Tier 1 (critical) vendors is typically green. >15% overdue for Tier 1 vendors should trigger immediate management escalation and remediation.
What does 'missing evidence' mean in vendor due diligence?
Missing evidence means a vendor has been assessed, but key diligence artifacts — SOC 2 report, security questionnaire response, financial statement, or regulatory compliance certificate — are absent, stale (typically >12 months for annual documents), or marked as pending without a resolution date. An examiner who finds no documented evidence of a vendor review will treat the review as if it never happened.
What did the 2023 Interagency Guidance change about vendor diligence expectations?
The 2023 Interagency Guidance on Third-Party Relationships (OCC, FDIC, Federal Reserve) shifted expectations from periodic snapshot reviews toward continuous monitoring proportional to risk. For critical vendors, this means active KRI-based monitoring between annual assessments — not just an annual questionnaire cycle. Programs relying solely on annual reviews for critical relationships are increasingly out of alignment with current examination standards.
Do vendor due diligence KRIs apply to all vendors or just Tier 1?
These KRIs apply to all tiers, but thresholds and escalation consequences differ by tier. A 5% overdue review rate for Tier 1 vendors should escalate to management immediately; the same rate for Tier 3 vendors may be amber rather than red. Segment the KRIs by tier so that critical vendor coverage isn't masked by large volumes of lower-risk vendor reviews.
How does DORA affect vendor due diligence KRI requirements?
DORA, enforceable since January 2025, requires ongoing monitoring of ICT third-party service providers under Article 28, with specific KPI and KRI documentation requirements in the EBA ICT risk guidelines. For US-based firms with EU operations or EU-connected clients, between-assessment monitoring KRIs for ICT vendors are a regulatory requirement, not an optional enhancement to the annual review cycle.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Third-Party Risk Management (TPRM) Kit

Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.