Feature Third-Party Risk
Third-Party Risk Management Lifecycle RACI: Fix the Handoffs Between Procurement, Security, Legal, Business Owners, and Risk
A TPRM lifecycle RACI that assigns clear ownership at each stage — planning, due diligence, contracting, onboarding, monitoring, and offboarding — so findings don't fall between functions.
Table of Contents
TL;DR
- Most TPRM programs document the stages of the lifecycle but never define who owns each handoff. Findings fall between Procurement and Security, or between Legal and Risk, and nobody notices until an examiner asks.
- The 2023 interagency guidance (OCC/FDIC/Fed) requires lifecycle governance across planning, due diligence, contracting, monitoring, and termination — for all vendor relationships, not just critical ones.
- A working RACI names Responsible, Accountable, Consulted, and Informed for each stage and defines the specific artifact or decision that closes the handoff.
The most expensive sentence in a TPRM program is “I thought procurement handled that.”
Procurement thought security handled the risk assessment. Security thought legal was tracking the contract conditions. Legal thought the business owner was monitoring the relationship. The business owner thought Risk would flag anything serious. Nobody was wrong about what their function does in theory. But nobody owned the handoffs — the specific moments when one function finishes its work and another needs to pick it up.
A TPRM lifecycle RACI is the fix. Not a policy document describing the lifecycle in general terms — a matrix that names a Responsible party and an Accountable party for each activity at each stage, defines what “done” looks like, and specifies which artifact closes the handoff. This post builds that matrix.
What the 2023 interagency guidance actually requires
In June 2023, the OCC, FDIC, and Federal Reserve issued unified third-party risk management guidance (OCC Bulletin 2023-17; FDIC FIL-23-2023). It replaced the prior OCC guidance from 2013 and established a consistent standard across bank regulators.
The guidance covers any “business arrangement between a banking organization and another entity, by contract or otherwise.” The lifecycle it describes has five stages: planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination. Board and senior management oversight is required for material third-party relationships, and due diligence depth must be proportionate to the risk and criticality of the relationship.
What the guidance does not prescribe is a RACI. It says governance structures must be defined. It does not say who in your organization owns what. That mapping is yours to build — and the absence of a clear one is a common exam finding.
The six stages and where programs break
A practical TPRM lifecycle has six stages. Here is where each one typically breaks down.
Stage 1: Planning and intake
What it covers: Identifying that a new vendor relationship is being considered, initiating the intake process, determining the risk tier, and deciding what level of due diligence is required.
Where it breaks: Business units contact vendors, agree to pilots, and request IT access before Risk or Procurement is involved. By the time the TPRM intake form arrives, there is an implied commitment to proceed. The risk assessment becomes a ratification, not a decision.
What a working intake looks like: A defined trigger list — any new SaaS tool, any contract above a threshold, any vendor with access to customer data — that routes automatically to the TPRM intake process before procurement begins. The intake is the first artifact in the lifecycle; without it, you cannot enforce anything that follows.
Stage 2: Due diligence
What it covers: Security assessment, financial stability review, compliance and regulatory check, operational resilience review, and AI/privacy-specific evaluation for applicable vendors.
Where it breaks: The questionnaire goes out, it comes back, and then it sits. Nobody has a defined responsibility to review the responses, challenge incomplete answers, or translate findings into contract conditions. The due diligence artifact is treated as a checkbox rather than a risk input.
The FDIC’s community bank TPRM guide is explicit that for some vendors, when desired due-diligence information cannot be obtained, the bank may need to consider whether alternative information is adequate, whether customer-side controls compensate, or whether the relationship should not proceed. That judgment requires a defined reviewer — not just a form.
Stage 3: Contract negotiation
What it covers: Translating due diligence findings into contract conditions, ensuring required regulatory provisions are included (GLBA, BSA/AML notification, audit rights, data return or destruction on termination), and obtaining legal sign-off.
Where it breaks: Legal reviews the contract for commercial terms. Risk is not involved. Due diligence findings — flagged controls, missing certifications, open questions on data handling — are never reflected in the contract language. The vendor gets a clean contract, the finding disappears from the record, and nobody knows until the next periodic review.
Stage 4: Onboarding
What it covers: Access provisioning, data sharing setup, documentation of the relationship in the vendor inventory, and orientation of the business owner to their ongoing monitoring obligations.
Where it breaks: Access is provisioned before the contract is signed. The vendor inventory is updated weeks after go-live, with incomplete information. The business owner is not told what they are supposed to monitor or at what frequency. Nobody closes the handoff from security (access provisioned) to risk (monitoring plan in place).
Stage 5: Ongoing monitoring
What it covers: Periodic reassessment based on risk tier, continuous monitoring for critical vendors, tracking of contract renewal dates and required re-due-diligence, complaint monitoring, and fourth-party risk reviews.
Where it breaks: Monitoring is defined in policy — “annual reassessment for Tier 2 vendors” — but nobody owns the calendar. Review dates arrive with no process to trigger them. The vendor inventory has stale entries. Critical vendor relationships are not re-assessed because the business owner doesn’t flag a change and Risk doesn’t have a monitoring calendar.
Stage 6: Offboarding
What it covers: Termination decision, access revocation, data return or destruction confirmation, contract close-out, and removal from the active inventory.
Where it breaks: The business relationship ends informally. Access revocation is delayed or skipped. The vendor still holds data under GLBA or state privacy obligations. The inventory entry is marked “inactive” rather than formally closed. Examiners reviewing the inventory find relationships with no termination documentation, no access revocation record, and no data disposition confirmation.
The RACI matrix
The following matrix assigns Responsible (R), Accountable (A), Consulted (C), and Informed (I) for each stage. Functions used: Procurement (vendor contract and commercial management), Security (technical and InfoSec assessment), Legal (contract review and regulatory provisions), Business Owner (internal requestor; ongoing relationship owner), Risk/Compliance (regulatory and risk program), Central TPRM (program management, inventory, reporting).
Stage 1: Planning and intake
| Activity | Procurement | Security | Legal | Business Owner | Risk/Compliance | Central TPRM |
|---|---|---|---|---|---|---|
| Submit intake request | C | C | — | R | C | A |
| Determine risk tier | — | C | — | C | R | A |
| Decide due diligence scope | C | C | C | I | R | A |
Handoff artifact: Completed intake form with assigned risk tier and due diligence scope, reviewed by Central TPRM. Business Owner signs that they understand the review is required before proceeding.
Stage 2: Due diligence
| Activity | Procurement | Security | Legal | Business Owner | Risk/Compliance | Central TPRM |
|---|---|---|---|---|---|---|
| Send vendor questionnaire | C | R | — | I | C | A |
| Review financial stability | R | — | — | I | C | — |
| Review InfoSec responses | — | R | — | I | C | — |
| Review compliance/regulatory | — | C | C | I | R | — |
| Compile due diligence summary | — | C | C | I | R | A |
| Escalate open findings | — | C | C | C | R | A |
Handoff artifact: Due diligence summary with open findings listed, signed by Risk/Compliance, shared with Procurement and Legal before contract negotiation begins.
Stage 3: Contract negotiation
| Activity | Procurement | Security | Legal | Business Owner | Risk/Compliance | Central TPRM |
|---|---|---|---|---|---|---|
| Draft contract terms | R | — | C | — | — | — |
| Map due diligence findings to contract conditions | C | C | R | — | A | I |
| Review regulatory provisions | — | — | R | — | C | — |
| Final legal review and sign-off | — | — | R | — | C | — |
| Contract execution approval | R | I | C | I | A | I |
Handoff artifact: Executed contract with annotated provision checklist confirming that regulatory requirements (GLBA data use, audit rights, breach notification, data return on termination) are included and each due diligence finding has a corresponding contract condition or documented risk acceptance.
Stage 4: Onboarding
| Activity | Procurement | Security | Legal | Business Owner | Risk/Compliance | Central TPRM |
|---|---|---|---|---|---|---|
| Provision access | — | R | — | C | I | I |
| Update vendor inventory | — | I | — | I | C | R/A |
| Brief business owner on monitoring | — | — | — | R | C | A |
| Confirm monitoring plan in place | — | I | — | R | C | A |
Handoff artifact: Updated inventory entry with access provisioning confirmation and signed monitoring plan acknowledgment from Business Owner. This is the artifact that closes onboarding — not the access provisioning itself.
Stage 5: Ongoing monitoring
| Activity | Procurement | Security | Legal | Business Owner | Risk/Compliance | Central TPRM |
|---|---|---|---|---|---|---|
| Monitor contract renewal dates | R | — | C | — | I | C |
| Periodic reassessment (by risk tier) | C | C | — | C | R | A |
| Continuous monitoring (critical vendors) | — | R | — | C | C | A |
| Track complaints and incidents | — | I | — | R | C | I |
| Fourth-party disclosure review | — | R | — | I | C | A |
| Escalate material changes | — | C | C | R | C | A |
Cadence rule: Tier 1 (critical) vendors: continuous monitoring + annual reassessment. Tier 2 (high): semi-annual. Tier 3 (medium): annual. Tier 4 (low): biennial. Central TPRM owns the reassessment calendar and triggers the process; Risk/Compliance conducts it.
Stage 6: Offboarding
| Activity | Procurement | Security | Legal | Business Owner | Risk/Compliance | Central TPRM |
|---|---|---|---|---|---|---|
| Initiate termination | R | I | I | R | C | A |
| Revoke access | — | R | — | C | I | A |
| Confirm data return or destruction | — | C | R | — | C | A |
| Close contract | R | — | R | — | I | I |
| Archive inventory entry | — | — | — | I | I | R/A |
Handoff artifact: Offboarding closure checklist: access revocation confirmation, data disposition record (return or certified destruction), contract close-out confirmation, and inventory update. An inactive entry without these artifacts is not a closed relationship.
The three fixes that matter most
Running the full matrix improvement all at once is not realistic for most teams. If you can only fix three things:
Fix 1: Add an intake trigger. The most common TPRM failure is that business units contract with vendors before the risk process starts. Define a short list of triggers — any new vendor with data access, any contract above a dollar threshold, any cloud service processing customer information — and make the intake form a procurement prerequisite, not a post-facto filing.
Fix 2: Close the due-diligence-to-contract handoff. Require that the Risk/Compliance due diligence summary is reviewed by Legal before contract negotiation begins, and that every open finding either has a contract condition or a signed risk acceptance. If the finding disappeared between due diligence and the contract, it was not resolved — it was ignored.
Fix 3: Operationalize offboarding. Build the offboarding checklist and assign Central TPRM as the owner of all active terminations. Access revocation confirmation and data disposition records are the two artifacts examiners are most likely to ask for in a vendor termination review. If neither exists, the termination is not evidence.
A note on the business owner role
The business owner is frequently the least-defined role in a TPRM RACI. In the matrix above, the business owner is Responsible for initiating the intake, is Consulted during due diligence, signs the monitoring plan at onboarding, and owns the complaint and incident escalation path during monitoring. They are not a passive receiver of information — they are the person with the operational relationship with the vendor and the clearest view of whether the vendor is performing as expected.
The handoff that most often fails is at onboarding: the business owner is not told what they are expected to monitor, at what frequency, or when to escalate. Central TPRM should deliver a one-page monitoring summary at onboarding — what to watch, who to call, what constitutes a material change — so the business owner’s obligations are explicit rather than assumed.
Related reading
- Vendor Due Diligence Without a SOC 2: What Evidence Can Actually Substitute
- Fourth-Party Risk: The Synapse Bankruptcy and What Fintechs Missed in Their TPRM Programs
- Vendor Risk Tiering: How to Classify Vendors by Criticality (Without 200 Categories)
If you need the full vendor lifecycle in one place — intake, risk tiering, due diligence questionnaire, contract checklist, monitoring cadence, and offboarding checklist — the TPRM Kit covers all six stages, with templates built for OCC/FDIC interagency guidance compliance.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is a TPRM lifecycle RACI?
Which function should own the TPRM program overall?
What does the 2023 interagency TPRM guidance require for lifecycle governance?
Where do most TPRM programs fail?
What is the most commonly skipped stage of the TPRM lifecycle?
How should the TPRM RACI handle fourth-party risk?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Keep reading
Related posts.
Third-Party Risk
Vendor Due Diligence Without a SOC 2: What Evidence Can Actually Substitute
A vendor due diligence checklist for evaluating security evidence when a vendor has no SOC 2 report, with a risk-based substitution matrix.
Jul 23, 2026
Third-Party Risk
Three Vendors, One Existential Risk: What the OCC's Community Bank Core Provider RFI Actually Asked
The OCC published Bulletin 2025-39 asking community banks hard questions about their relationships with Fiserv, FIS, and Jack Henry. The questions reveal exactly what examiners are now checking — and what most TPRM programs haven't addressed.
Jul 23, 2026
Third-Party Risk
Fourth-Party Risk After Synapse: What OCC and FDIC Now Expect from Your Subcontractor Oversight Program
Synapse collapsed and 100,000+ customers lost access to $265M in deposits they thought were FDIC-insured. The cause wasn't fraud — it was middleware risk nobody was watching. Here's what OCC and FDIC now expect from your fourth-party and subcontractor oversight program.
Jul 20, 2026