Feature Third-Party Risk
Vendor Due Diligence KRIs: Missing Evidence, Overdue Reviews, and High-Risk Exceptions
Your TPRM program tracks vendor performance. These 6 KRIs track whether your due diligence process itself is working — review completion rates, evidence currency, exception handling, and the program health gaps examiners find most often.
Table of Contents
TL;DR
- Most TPRM programs track vendor performance. Fewer track whether the diligence program itself is functioning — whether reviews are happening on time, evidence is current, and exceptions are being resolved.
- Six program health KRIs — overdue review rate, missing evidence rate, exception aging, questionnaire return rate, high-risk exception documentation quality, and unreviewed new vendor rate — tell you if third-party oversight is real or theoretical.
- The 2023 Interagency Guidance on Third-Party Relationships requires ongoing monitoring proportional to risk; programs still running annual-only reviews for critical vendors are out of alignment with current examination expectations.
- American Express paid a $15 million civil penalty in 2023 for third-party oversight governance failures — the OCC has made clear that vendor oversight is not a checkbox activity.
The TPRM Program Health Problem
Most organizations with a TPRM program know which vendors are risky. They have a Tier 1 list, a review schedule, questionnaire templates, and a vendor inventory spreadsheet.
What fewer organizations have is a way to tell whether the program is actually being executed. Are reviews happening on time? Is the evidence collected current and substantive? Are exceptions being tracked to closure, or quietly left open from one review cycle to the next?
This matters because examiner expectations have shifted. The 2023 Interagency Guidance on Third-Party Relationships, issued jointly by the OCC, Federal Reserve, and FDIC, moved evaluation from “do you have a vendor list?” toward “show me your lifecycle governance.” The exam question is no longer “do you review vendors?” — it’s “how do you know your review program is actually working?”
Vendor due diligence KRIs answer that question. They measure the program’s own operational health: completion rates, evidence currency, exception handling, and coverage gaps. They’re distinct from vendor performance KRIs, which track what vendors are doing. These track what your team is doing.
Why This Is an Enforcement Issue, Not a Best-Practice Issue
In July 2023, following an OCC examination, American Express received a $15 million civil money penalty for failures in third-party relationship governance and oversight. The action focused on inadequate risk management practices for a specific third-party relationship — documentation gaps, oversight failures, and insufficient escalation of warning signs that were present but not acted on.
The Federal Reserve’s May 2024 TPRM supervisory report identified the most common deficiencies in examined institutions: inadequate documentation of initial due diligence, gaps in ongoing monitoring, and insufficient board-level oversight of critical vendor relationships. These are the findings that generate MRAs and, in repeated cases, formal enforcement actions.
Vendor due diligence KRIs are how you see these patterns in your own program before an examiner does.
The 6 Vendor Due Diligence KRIs
KRI 1: Overdue Periodic Review Rate
What it measures: The percentage of scheduled vendor reviews — annual assessments, SOC report evaluations, security questionnaire updates, financial statement reviews — not completed within the program’s defined window.
Overdue reviews are the most common TPRM finding across all institutional tiers. A review schedule that exists on paper but runs consistently behind is evidence that the program is theoretical, not operational. Examiners who find six of ten critical vendor reviews more than 60 days overdue treat it as a governance failure at the program level, not a timing inconvenience.
Segment by tier:
| Tier | Green | Amber | Red |
|---|---|---|---|
| Tier 1 (Critical) | 0% overdue | 1–5% with active remediation plan | >5%, or any Tier 1 review >60 days overdue |
| Tier 2 | <5% overdue | 5–15% | >15% |
| Tier 3 | <15% overdue | 15–30% | >30% |
Data source: TPRM tracker or vendor management system with scheduled review dates. Owner: TPRM Program Lead / Vendor Management.
KRI 2: Missing or Stale Evidence Rate
What it measures: The percentage of vendor files — particularly Tier 1 and 2 vendors — where required diligence artifacts are absent, expired, or listed as pending beyond a defined resolution window.
Evidence staleness is the gap between “we did a review” and “we have current documentation that supports the review conclusion.” A SOC 2 report from 28 months ago used to support a current risk conclusion tells you about the control environment from well before now. An examiner asking for evidence of vendor oversight who receives a stale report will question whether ongoing monitoring is actually occurring.
Standard staleness thresholds:
- SOC 2 reports: >12 months from issue date (bridge letters can extend currency)
- Security questionnaire responses: >12 months or after a material system/service change
- Financial statements: >18 months from fiscal year end
- Vendor penetration test summaries: >24 months
- Regulatory compliance certifications: >12 months or per certification standard
| Threshold | Criteria |
|---|---|
| Green | <5% of Tier 1/2 vendor files with stale or missing required evidence |
| Amber | 5–15% |
| Red | >15%, or any Tier 1 vendor missing a SOC 2 with no active remediation plan |
Owner: TPRM Analyst / Vendor Management.
KRI 3: Exception Aging — Open Remediation Commitments
What it measures: The count and age of open remediation commitments from vendor due diligence reviews — questionnaire deficiencies, SOC report exceptions, security gaps — that have not been resolved by the committed date.
When an assessment surfaces a deficiency and the vendor provides a remediation commitment, that commitment requires tracking to closure. The failure mode is common: commitments get logged, vendors say they’ll address the issue next quarter, and nobody follows up until the same finding appears in the following assessment cycle. Three consecutive annual reviews showing the same open SOC exception is not a minor documentation issue — it’s a governance finding.
| Dimension | Amber Trigger | Red Trigger |
|---|---|---|
| Open commitments by Tier 1 vendor | Any open commitment >90 days | Any critical finding commitment >60 days |
| On-time closure rate | <80% of commitments closed on schedule | <60% |
| Recurring exceptions | 1 recurring finding with active CAP | 2+ recurring findings, or any recurring finding without an active CAP |
Data source: Due diligence tracker with remediation tracking fields: date identified, committed close date, actual close date, and evidence of closure. Owner: TPRM / Compliance.
KRI 4: Questionnaire Return Rate and Completion Timeliness
What it measures: The percentage of vendor questionnaires returned complete within the required window — and the percentage requiring multiple follow-up rounds.
Questionnaire completion rate is a proxy for vendor engagement quality. A vendor that requires four follow-up cycles to return an incomplete questionnaire is a different risk profile than one that returns complete documentation in 10 business days. At the aggregate program level, a chronically low completion rate signals that your program lacks the relationship management capacity to actually execute its diligence obligations.
| Threshold | Criteria |
|---|---|
| Green | >85% of Tier 1/2 questionnaires returned complete within 15 business days |
| Amber | 70–85% return rate, or >15% requiring more than three follow-ups |
| Red | <70% return rate, or any Tier 1 questionnaire >30 business days outstanding without exemption |
Owner: TPRM Analyst.
The quality of what you send affects completion rate and evidence quality. If vendors are routinely returning incomplete questionnaires, the design of the questionnaire itself and what to verify when responses come back are foundational issues worth addressing before adjusting thresholds.
KRI 5: High-Risk Exception Volume and Documentation Quality
What it measures: The count and documentation completeness of high-risk or policy exceptions approved in vendor reviews — cases where a vendor was onboarded or continued despite failing one or more diligence criteria.
Exception approval is a legitimate governance decision when it’s made by the right authority, with documented rationale, defined monitoring conditions, and an expiration date. The problem is exceptions that accumulate without documentation, expire without review, or get tacitly renewed without going back through the approval process. An exception binder that contains eight “pending remediation” entries from 18 months ago is not a functioning exception program — it’s an evidence gap.
What this KRI captures:
- Count of open high-risk exceptions by tier and risk category
- Percentage of exceptions with complete documentation: rationale, approval authority, conditions, expiration date, monitoring requirement
- Average age of open exceptions (exceptions >12 months without formal renewal signal program drift)
- Percentage of expired exceptions explicitly renewed vs. silently continuing
| Threshold | Criteria |
|---|---|
| Green | All high-risk exceptions fully documented; no exceptions expired without renewal review in the quarter |
| Amber | Any exception missing one documentation element; >2 expired without formal renewal |
| Red | >3 undocumented Tier 1/2 exceptions; any exception where the approval authority doesn’t match documented thresholds |
Owner: TPRM / Compliance. Approval authority thresholds should be defined in the TPRM policy and mapped to vendor tier and exception severity.
KRI 6: Unreviewed New Vendor Rate
What it measures: The percentage of vendors activated in the period — particularly Tier 1 and 2 — that went live without completed pre-activation due diligence.
This KRI catches the gap between vendor contracting and vendor risk assessment. In organizations that move quickly, vendor contracts sometimes get signed and services go live before the TPRM team has completed its review. When that happens for a Tier 1 vendor, it is an immediate exam finding: the relationship was activated without documented risk review.
| Threshold | Criteria |
|---|---|
| Green | 0% of Tier 1 vendors activated without completed pre-activation diligence |
| Amber | Any new Tier 2 vendor activated with an in-progress (not completed) review and a documented remediation timeline |
| Red | Any Tier 1 vendor activated without completed diligence, or any vendor where review was waived without documented approval authority |
Owner: TPRM Program Lead, coordinating with Vendor Contracting and Procurement. Any Tier 1 red breach is an immediate CRO or CCO notification, not a monthly KRI report item.
What the 2023 Interagency Guidance Actually Requires
The 2023 Interagency Guidance covers five lifecycle stages: planning, due diligence, contracting, ongoing monitoring, and termination. Each stage has documentation expectations. The ongoing monitoring stage is where most programs fall short in exam settings — not because monitoring isn’t happening, but because it can’t be evidenced.
The guidance is explicit that ongoing monitoring should be proportionate to risk: more frequent and more intensive for critical vendors, lighter for low-risk relationships. For critical vendors, this means active KRI monitoring between annual assessments — tracking the program health metrics above, not just waiting for the annual cycle.
For EU-connected organizations, DORA — enforceable since January 2025 under Article 28 — imposes a similar continuous monitoring obligation for ICT third-party service providers. Organizations subject to both frameworks should map their due diligence KRIs to the specific documentation requirements of each.
The Federal Reserve’s May 2024 supervisory observations identified that institutions with the strongest TPRM programs shared a common trait: they could produce trend data and evidence chains on demand, not just point-in-time snapshots. That’s exactly what a due diligence KRI program produces — a documented trail showing which vendors were reviewed when, what evidence was collected and whether it was current, and how exceptions and deficiencies were handled.
How Diligence KRIs Complement Vendor Performance KRIs
Vendor due diligence KRIs and vendor performance KRIs measure different things and should be tracked in parallel.
Vendor performance KRIs (SLA compliance, incident rates, financial health signals) tell you if a vendor’s service delivery is deteriorating. The critical vendor KRI framework covers that tier in depth.
Vendor due diligence KRIs tell you if your oversight program is functioning as designed. A vendor can have a perfect SLA track record and still have a due diligence file with a two-year-old SOC 2, an open questionnaire, and three unresolved remediation commitments. Examiners review both — and a clean vendor track record doesn’t excuse a broken diligence program.
When both KRI sets are functioning, the combination produces the evidence chain regulators expect: here is the vendor’s performance trend, and here is our documented diligence trail confirming we were monitoring it throughout.
So What?
Vendor due diligence KRIs answer the question every TPRM program leader should be able to answer at any time: is the program actually being executed, or does it exist mainly on paper?
The six KRIs above — overdue review rate, missing evidence rate, exception aging, questionnaire completion, exception documentation quality, and unreviewed new vendor rate — provide that visibility. Each one surfaces a program health failure that is unlikely to appear on a vendor performance dashboard.
Before your next exam, test yourself against these KRIs. If you can’t pull the numbers within a day, the data infrastructure for this monitoring doesn’t exist — and that itself is a finding waiting to happen.
For teams building or upgrading vendor diligence tracking, the Third-Party Risk Management (TPRM) Kit includes a vendor review tracker, evidence collection templates, exception documentation structure, and a TPRM program health dashboard designed for both management and board reporting. Get it at buy.stripe.com/14A14g8Bd01dazP4mO6J204.
Related reading:
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is the difference between vendor performance KRIs and vendor due diligence KRIs?
What counts as 'overdue' for a periodic vendor review?
What does 'missing evidence' mean in vendor due diligence?
What did the 2023 Interagency Guidance change about vendor diligence expectations?
Do vendor due diligence KRIs apply to all vendors or just Tier 1?
How does DORA affect vendor due diligence KRI requirements?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Keep reading
Related posts.
Third-Party Risk
Third-Party Risk Management Lifecycle RACI: Fix the Handoffs Between Procurement, Security, Legal, Business Owners, and Risk
A TPRM lifecycle RACI that assigns clear ownership at each stage — planning, due diligence, contracting, onboarding, monitoring, and offboarding — so findings don't fall between functions.
Jul 24, 2026
Third-Party Risk
Vendor Due Diligence Without a SOC 2: What Evidence Can Actually Substitute
A vendor due diligence checklist for evaluating security evidence when a vendor has no SOC 2 report, with a risk-based substitution matrix.
Jul 23, 2026
Third-Party Risk
Three Vendors, One Existential Risk: What the OCC's Community Bank Core Provider RFI Actually Asked
The OCC published Bulletin 2025-39 asking community banks hard questions about their relationships with Fiserv, FIS, and Jack Henry. The questions reveal exactly what examiners are now checking — and what most TPRM programs haven't addressed.
Jul 23, 2026