Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Third-Party Risk

Third-Party Risk Management Lifecycle RACI: Fix the Handoffs Between Procurement, Security, Legal, Business Owners, and Risk

A TPRM lifecycle RACI that assigns clear ownership at each stage — planning, due diligence, contracting, onboarding, monitoring, and offboarding — so findings don't fall between functions.

Table of Contents

TL;DR

  • Most TPRM programs document the stages of the lifecycle but never define who owns each handoff. Findings fall between Procurement and Security, or between Legal and Risk, and nobody notices until an examiner asks.
  • The 2023 interagency guidance (OCC/FDIC/Fed) requires lifecycle governance across planning, due diligence, contracting, monitoring, and termination — for all vendor relationships, not just critical ones.
  • A working RACI names Responsible, Accountable, Consulted, and Informed for each stage and defines the specific artifact or decision that closes the handoff.

The most expensive sentence in a TPRM program is “I thought procurement handled that.”

Procurement thought security handled the risk assessment. Security thought legal was tracking the contract conditions. Legal thought the business owner was monitoring the relationship. The business owner thought Risk would flag anything serious. Nobody was wrong about what their function does in theory. But nobody owned the handoffs — the specific moments when one function finishes its work and another needs to pick it up.

A TPRM lifecycle RACI is the fix. Not a policy document describing the lifecycle in general terms — a matrix that names a Responsible party and an Accountable party for each activity at each stage, defines what “done” looks like, and specifies which artifact closes the handoff. This post builds that matrix.

What the 2023 interagency guidance actually requires

In June 2023, the OCC, FDIC, and Federal Reserve issued unified third-party risk management guidance (OCC Bulletin 2023-17; FDIC FIL-23-2023). It replaced the prior OCC guidance from 2013 and established a consistent standard across bank regulators.

The guidance covers any “business arrangement between a banking organization and another entity, by contract or otherwise.” The lifecycle it describes has five stages: planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination. Board and senior management oversight is required for material third-party relationships, and due diligence depth must be proportionate to the risk and criticality of the relationship.

What the guidance does not prescribe is a RACI. It says governance structures must be defined. It does not say who in your organization owns what. That mapping is yours to build — and the absence of a clear one is a common exam finding.


The six stages and where programs break

A practical TPRM lifecycle has six stages. Here is where each one typically breaks down.

Stage 1: Planning and intake

What it covers: Identifying that a new vendor relationship is being considered, initiating the intake process, determining the risk tier, and deciding what level of due diligence is required.

Where it breaks: Business units contact vendors, agree to pilots, and request IT access before Risk or Procurement is involved. By the time the TPRM intake form arrives, there is an implied commitment to proceed. The risk assessment becomes a ratification, not a decision.

What a working intake looks like: A defined trigger list — any new SaaS tool, any contract above a threshold, any vendor with access to customer data — that routes automatically to the TPRM intake process before procurement begins. The intake is the first artifact in the lifecycle; without it, you cannot enforce anything that follows.

Stage 2: Due diligence

What it covers: Security assessment, financial stability review, compliance and regulatory check, operational resilience review, and AI/privacy-specific evaluation for applicable vendors.

Where it breaks: The questionnaire goes out, it comes back, and then it sits. Nobody has a defined responsibility to review the responses, challenge incomplete answers, or translate findings into contract conditions. The due diligence artifact is treated as a checkbox rather than a risk input.

The FDIC’s community bank TPRM guide is explicit that for some vendors, when desired due-diligence information cannot be obtained, the bank may need to consider whether alternative information is adequate, whether customer-side controls compensate, or whether the relationship should not proceed. That judgment requires a defined reviewer — not just a form.

Stage 3: Contract negotiation

What it covers: Translating due diligence findings into contract conditions, ensuring required regulatory provisions are included (GLBA, BSA/AML notification, audit rights, data return or destruction on termination), and obtaining legal sign-off.

Where it breaks: Legal reviews the contract for commercial terms. Risk is not involved. Due diligence findings — flagged controls, missing certifications, open questions on data handling — are never reflected in the contract language. The vendor gets a clean contract, the finding disappears from the record, and nobody knows until the next periodic review.

Stage 4: Onboarding

What it covers: Access provisioning, data sharing setup, documentation of the relationship in the vendor inventory, and orientation of the business owner to their ongoing monitoring obligations.

Where it breaks: Access is provisioned before the contract is signed. The vendor inventory is updated weeks after go-live, with incomplete information. The business owner is not told what they are supposed to monitor or at what frequency. Nobody closes the handoff from security (access provisioned) to risk (monitoring plan in place).

Stage 5: Ongoing monitoring

What it covers: Periodic reassessment based on risk tier, continuous monitoring for critical vendors, tracking of contract renewal dates and required re-due-diligence, complaint monitoring, and fourth-party risk reviews.

Where it breaks: Monitoring is defined in policy — “annual reassessment for Tier 2 vendors” — but nobody owns the calendar. Review dates arrive with no process to trigger them. The vendor inventory has stale entries. Critical vendor relationships are not re-assessed because the business owner doesn’t flag a change and Risk doesn’t have a monitoring calendar.

Stage 6: Offboarding

What it covers: Termination decision, access revocation, data return or destruction confirmation, contract close-out, and removal from the active inventory.

Where it breaks: The business relationship ends informally. Access revocation is delayed or skipped. The vendor still holds data under GLBA or state privacy obligations. The inventory entry is marked “inactive” rather than formally closed. Examiners reviewing the inventory find relationships with no termination documentation, no access revocation record, and no data disposition confirmation.


The RACI matrix

The following matrix assigns Responsible (R), Accountable (A), Consulted (C), and Informed (I) for each stage. Functions used: Procurement (vendor contract and commercial management), Security (technical and InfoSec assessment), Legal (contract review and regulatory provisions), Business Owner (internal requestor; ongoing relationship owner), Risk/Compliance (regulatory and risk program), Central TPRM (program management, inventory, reporting).

Stage 1: Planning and intake

ActivityProcurementSecurityLegalBusiness OwnerRisk/ComplianceCentral TPRM
Submit intake requestCCRCA
Determine risk tierCCRA
Decide due diligence scopeCCCIRA

Handoff artifact: Completed intake form with assigned risk tier and due diligence scope, reviewed by Central TPRM. Business Owner signs that they understand the review is required before proceeding.

Stage 2: Due diligence

ActivityProcurementSecurityLegalBusiness OwnerRisk/ComplianceCentral TPRM
Send vendor questionnaireCRICA
Review financial stabilityRIC
Review InfoSec responsesRIC
Review compliance/regulatoryCCIR
Compile due diligence summaryCCIRA
Escalate open findingsCCCRA

Handoff artifact: Due diligence summary with open findings listed, signed by Risk/Compliance, shared with Procurement and Legal before contract negotiation begins.

Stage 3: Contract negotiation

ActivityProcurementSecurityLegalBusiness OwnerRisk/ComplianceCentral TPRM
Draft contract termsRC
Map due diligence findings to contract conditionsCCRAI
Review regulatory provisionsRC
Final legal review and sign-offRC
Contract execution approvalRICIAI

Handoff artifact: Executed contract with annotated provision checklist confirming that regulatory requirements (GLBA data use, audit rights, breach notification, data return on termination) are included and each due diligence finding has a corresponding contract condition or documented risk acceptance.

Stage 4: Onboarding

ActivityProcurementSecurityLegalBusiness OwnerRisk/ComplianceCentral TPRM
Provision accessRCII
Update vendor inventoryIICR/A
Brief business owner on monitoringRCA
Confirm monitoring plan in placeIRCA

Handoff artifact: Updated inventory entry with access provisioning confirmation and signed monitoring plan acknowledgment from Business Owner. This is the artifact that closes onboarding — not the access provisioning itself.

Stage 5: Ongoing monitoring

ActivityProcurementSecurityLegalBusiness OwnerRisk/ComplianceCentral TPRM
Monitor contract renewal datesRCIC
Periodic reassessment (by risk tier)CCCRA
Continuous monitoring (critical vendors)RCCA
Track complaints and incidentsIRCI
Fourth-party disclosure reviewRICA
Escalate material changesCCRCA

Cadence rule: Tier 1 (critical) vendors: continuous monitoring + annual reassessment. Tier 2 (high): semi-annual. Tier 3 (medium): annual. Tier 4 (low): biennial. Central TPRM owns the reassessment calendar and triggers the process; Risk/Compliance conducts it.

Stage 6: Offboarding

ActivityProcurementSecurityLegalBusiness OwnerRisk/ComplianceCentral TPRM
Initiate terminationRIIRCA
Revoke accessRCIA
Confirm data return or destructionCRCA
Close contractRRII
Archive inventory entryIIR/A

Handoff artifact: Offboarding closure checklist: access revocation confirmation, data disposition record (return or certified destruction), contract close-out confirmation, and inventory update. An inactive entry without these artifacts is not a closed relationship.


The three fixes that matter most

Running the full matrix improvement all at once is not realistic for most teams. If you can only fix three things:

Fix 1: Add an intake trigger. The most common TPRM failure is that business units contract with vendors before the risk process starts. Define a short list of triggers — any new vendor with data access, any contract above a dollar threshold, any cloud service processing customer information — and make the intake form a procurement prerequisite, not a post-facto filing.

Fix 2: Close the due-diligence-to-contract handoff. Require that the Risk/Compliance due diligence summary is reviewed by Legal before contract negotiation begins, and that every open finding either has a contract condition or a signed risk acceptance. If the finding disappeared between due diligence and the contract, it was not resolved — it was ignored.

Fix 3: Operationalize offboarding. Build the offboarding checklist and assign Central TPRM as the owner of all active terminations. Access revocation confirmation and data disposition records are the two artifacts examiners are most likely to ask for in a vendor termination review. If neither exists, the termination is not evidence.


A note on the business owner role

The business owner is frequently the least-defined role in a TPRM RACI. In the matrix above, the business owner is Responsible for initiating the intake, is Consulted during due diligence, signs the monitoring plan at onboarding, and owns the complaint and incident escalation path during monitoring. They are not a passive receiver of information — they are the person with the operational relationship with the vendor and the clearest view of whether the vendor is performing as expected.

The handoff that most often fails is at onboarding: the business owner is not told what they are expected to monitor, at what frequency, or when to escalate. Central TPRM should deliver a one-page monitoring summary at onboarding — what to watch, who to call, what constitutes a material change — so the business owner’s obligations are explicit rather than assumed.


If you need the full vendor lifecycle in one place — intake, risk tiering, due diligence questionnaire, contract checklist, monitoring cadence, and offboarding checklist — the TPRM Kit covers all six stages, with templates built for OCC/FDIC interagency guidance compliance.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is a TPRM lifecycle RACI?
A TPRM lifecycle RACI defines who is Responsible, Accountable, Consulted, and Informed at each stage of the vendor relationship — from initial planning through offboarding. It is distinct from a general vendor management policy because it maps specific activities to specific functions (Procurement, Security, Legal, Business Owner, Risk/Compliance, Central TPRM) and defines who owns each handoff.
Which function should own the TPRM program overall?
A central TPRM function — typically housed in GRC, Risk, or the CISO's office — should be accountable for the program design, inventory, and reporting stack. Individual activities are distributed across functions (Procurement owns intake, Security owns technical assessment, Legal owns contract review), but one function must own the overall program to prevent distributed accountability from becoming no one's accountability.
What does the 2023 interagency TPRM guidance require for lifecycle governance?
The OCC/FDIC/Fed interagency guidance (OCC Bulletin 2023-17, FDIC FIL-23-2023, June 2023) requires banking organizations to manage third-party relationships across the full lifecycle: planning, due diligence, contract negotiation, ongoing monitoring, and termination. It also requires board-level oversight of material third-party relationships and risk-proportionate due diligence depth. The guidance does not prescribe a RACI but requires that governance structures are defined and documented.
Where do most TPRM programs fail?
The most common failures are at handoffs, not within individual stages. Specific failure points: (1) procurement onboards vendors before security or risk is consulted; (2) risk assessments are completed but findings are not tracked through to contract conditions; (3) monitoring is defined in policy but never operationalized; (4) offboarding is skipped or delayed, leaving former vendors with access and residual data obligations. Each of these is a RACI failure — no defined owner for the handoff.
What is the most commonly skipped stage of the TPRM lifecycle?
Offboarding. Most TPRM programs are built around onboarding and periodic reassessment. Offboarding is often included in policy but never operationalized. The result: vendors accumulate with no active oversight, access provisioned during onboarding is never revoked, and data destruction or return is not confirmed. Examiners increasingly ask for evidence of formal vendor terminations, including access revocation records and data disposition confirmations.
How should the TPRM RACI handle fourth-party risk?
Fourth-party risk — the risk introduced by your vendors' vendors — should sit with Security and Risk in the ongoing monitoring stage. The initial assessment should ask vendors to disclose material subcontractors. Contracts should include notification requirements for material subcontractor changes. The monitoring plan should track material fourth parties and include them in periodic reassessments for critical vendors.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Third-Party Risk Management (TPRM) Kit

Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.