2 Oct 2026
Third-Party Risk Assessment for Vendors: What Banks Actually Ask, What Evidence They Expect, and How to Prepare Before the Questionnaire Arrives
The questions banks tend to ask vendors, the evidence behind them, and a practical workflow to prepare before the questionnaire arrives.

Last reviewed: 2 October 2026. Examples reflect common assessment practice, not a fixed questionnaire used by every bank.
Quick answer
A bank's third-party risk assessment asks whether a supplier can deliver the agreed service while the bank understands and manages the resulting security, operational, legal and concentration risks. The questionnaire is one input. Reviewers may also examine independent reports, policies, operating records, contract terms, incidents, subcontractors and exit options. Prepare the evidence and its owners before the form arrives, then answer against the bank's exact service scope.
The 2023 US interagency guidance describes planning, due diligence, contracting, ongoing monitoring and termination as parts of one lifecycle. Its due diligence guidance is risk-based and tailored to the activity. That is why two banks—or two services at the same bank—can ask different questions.
The questions behind the questionnaire
| Bank concern | What the vendor may be asked | Evidence that helps answer |
|---|---|---|
| Service criticality | What breaks if your service is unavailable? | Architecture and dependency diagram; tested recovery objectives and escalation contacts. |
| Information security | How do you restrict access, encrypt data and manage vulnerabilities? | Security policy, access review sample, secure development summary and test/remediation record. |
| Privacy and location | Which customer or personal data do you process, and where? | Data flow, retention schedule, DPA, hosting locations and subprocessor register. |
| Incident response | When and how will the bank learn of an incident? | Incident plan, escalation route, exercise record and contract-aligned notification procedure. |
| Financial and corporate standing | Which entity supplies the service, and is it viable? | Entity and ownership details, insurance and financial information where proportionate and requested. |
| Fourth parties | Which critical dependencies sit behind your product? | Supplier list showing purpose, geography, data access and monitoring approach. |
| Continuity and exit | Can the bank continue or transfer the service? | Backup and recovery test, export format, transition assistance and deletion process. |
The list is illustrative. The FDIC examination material also points reviewers toward a provider's financial condition, relevant experience, controls, data security and privacy, with depth tied to the relationship's importance.
Why a short answer can cause a long review
“Yes” is rarely enough for a high-impact control. If the bank asks whether access is reviewed, distinguish employees from support contractors, production from development, and a written policy from the most recent completed review. If it asks for a penetration test, state the test date, service boundary, result summary and status of significant findings. If you cannot share the full report, propose a controlled review or redacted summary.
Reviewers commonly have to reconcile a questionnaire against policy documents, assurance reports and the contract. A vague answer or a contradiction forces a follow-up because the bank cannot tell which statement to rely on. Write the response so that a reviewer can locate the supporting evidence in one step.
Prepare before the bank sends its form
- Define the offered service. Record the legal entity, modules, environment, data categories, countries, integrations, support model and key dependencies. Do this for the actual deal, not the entire product portfolio.
- Create an evidence index. For each document, note its owner, approval date, expiration, scope, sensitivity and the claims it supports.
- Draft approved answers. Write reusable answers for recurring controls, with a source and review date. Keep space for customer-specific qualifications.
- Identify gaps openly. Separate a missing control, a control with no shareable evidence, and a document waiting for approval. Each needs a different next step.
- Agree on internal routing. Set one assessment coordinator and named reviewers for security, privacy, legal, operations and finance.
- Rehearse secure delivery. Know how you will provide restricted reports and record exactly what version the customer received.
This work reduces response time, but it does not let a supplier predict or pre-approve a bank's risk decision. The buyer may ask for extra evidence after reviewing the first packet.
When the request arrives
Read the entire questionnaire and instructions before answering. Confirm the service, entity, deadline, portal or file format, NDA terms and whether the bank expects policy copies, a report review or an evidence-room link. Group questions by owner. Answer directly, cite the exact source, and qualify any “yes” whose scope is narrower than the question.
If a question is inapplicable, explain why. If the control is partly implemented, describe the current state and the remediation plan. Do not copy an answer from a different customer if the environment, data type or contract obligation differs. Have the relevant domain owner approve the finished response and preserve the submitted version for the next review.
The bank may return findings as blockers, accepted risks or actions due later. Track each finding with a decision owner, promised action, date and evidence of closure. The supplier can propose a compensating control; only the customer can decide whether it accepts the remaining risk.
Beyond initial approval
Bank oversight can continue after onboarding. A material incident, major subprocessor change, expansion into new data or a contract renewal may trigger another assessment. The interagency guidance explicitly includes ongoing monitoring and termination in the relationship lifecycle. Keep the answer library and evidence index current so reassessment starts with a change log rather than a blank spreadsheet.
For EU financial customers buying ICT services, DORA Article 28 adds a formal risk-based assessment and due diligence context. It does not mean an ordinary SaaS supplier is automatically directly regulated by DORA; the customer's obligations often reach the supplier through questions and contract terms.
Where MatchAudit fits
MatchAudit's Vendor Assurance workspace is designed for the supplier's side of the process: keeping approved facts and documents together, organizing requests by customer relationship, identifying stale or missing evidence, and drafting responses for human review with links back to source material. A risk team still assesses the submitted material independently. See Vendor Assurance pricing if repeated assessments are becoming hard to coordinate.
Related reading
- Vendor Due Diligence for SaaS Suppliers covers the full evidence pack.
- Third-Party Risk Management Framework for Suppliers explains the frameworks behind many forms.
- Bank Vendor Onboarding explains why commercial agreement and risk approval can occur on different timelines.
FAQ
Is a bank's third-party risk assessment the same as a security questionnaire?
No. A security questionnaire is often one part of a wider assessment that can include resilience, legal terms, financial standing, subcontracting and ongoing oversight.
Will every bank ask for the same documents?
No. Questions depend on the bank, the particular service and the relationship's risk. A standard evidence pack gives you a starting point, but the final submission must match the actual request.
Can we reuse an answer from another bank?
Yes, after checking the current service scope, wording, evidence date and contract commitments. Reuse the approved fact, then adapt the response to the new question.
Related reading

Third-Party Risk Management From the Vendor Side: What Happens When Your Customer Assesses You
Almost all TPRM content is written for the buyer running the program. This is the same lifecycle — classification, due diligence, questionnaire, evidence, assessment, remediation, approval, contracting, monitoring, reassessment — from the assessed vendor's side, with practice clearly separated from regulation.

Third-Party Risk Management Framework for Suppliers: How DORA, SIG, CAIQ, ISO 27001, and Bank-Specific Requirements Fit Together.
How suppliers can map DORA, SIG, CAIQ, ISO 27001 and bank-specific requirements to one accurate, reusable evidence model.