The bank third-party-risk questionnaire, question by question
A bank's third-party-risk questionnaire is neither an audit nor an arbitrary list. Its sections track the due-diligence topics named in the 2023 Interagency Guidance on Third-Party Relationships: legal and regulatory compliance, financial condition, business experience, key personnel, risk management, information security, management of information systems, operational resilience, incident reporting, physical security, reliance on subcontractors, insurance, and the third party's own contracts with other parties. A second set of questions tracks what the bank has to be able to evidence in its contract with you: audit rights, business continuity, complaint handling, and notification of lapses. The guidance does not bind your firm; it binds the bank, and it reaches you through the engagement agreement — which is why the questionnaire reads like a contract negotiation conducted in a spreadsheet. A good answer names the control, names the system or document that evidences it, and states the review cadence. A bad answer restates the question as a policy commitment.
Key facts
- The topic list is not the bank's invention — it is the due-diligence section of the June 2023 interagency guidance, which is why questionnaires from unrelated banks rhyme.
- The guidance imposes no requirement on a law firm directly; it reaches you through the bank's contract, so the engagement agreement is where your answers become obligations.
- Information-security questions are the least negotiable of the set: a standing rule requires banks to bind service providers by contract to appropriate safeguards.
- Subcontractor questions reach your vendors and their locations, not just your staff — hosting, e-filing, skip tracing, print and mail, and outside counsel all count.
- Complaint questions ask for volume, nature and trend plus your response, not a count.
- Answers are re-asked. Monitoring may be periodic or continuous and scales with the risk of the activity, so a questionnaire answered once becomes a recurring reporting obligation.
Where the questions come from
In June 2023 the Federal Reserve, the FDIC and the OCC issued joint guidance on third-party relationships that replaced each agency's earlier version. Its due-diligence section is organised into fourteen lettered topics, and if you lay a bank's questionnaire next to it the correspondence is usually one-for-one: strategy and goals, legal and regulatory compliance, financial condition, business experience, qualifications and backgrounds of key personnel, risk management, information security, management of information systems, operational resilience, incident reporting and management processes, physical security, reliance on subcontractors, insurance coverage, and contractual arrangements with other parties.
Knowing that changes how you read a question you find strange. When a TPRM analyst asks a nine-lawyer firm for audited financial statements and debt-rating agency reports, they are not confused about your size; they are working a topic list that also covers core processors. The right answer is the honest scoped one — what you have, what you do not, and what you can offer instead — not silence and not an improvised approximation.
It also changes what you can push back on. The guidance is explicit that oversight is risk-proportionate and that the bank decides its own scope. It says in terms that supervisory guidance "does not have the force and effect of law and does not impose any new requirements on banking organizations." A bank cannot cite it to you as a rule you have broken, and you cannot cite it to a bank as a reason its questions are excessive. It is a shared vocabulary, not a ceiling.
Legal and regulatory compliance, business experience, and consumer harm
These questions ask whether you are licensed and authorised to do the work, whether you or your principals are sanctioned or under regulatory action, whether you can keep the bank in compliance, how you have responded when compliance issues arose, and — the one firms most often under-answer — whether you have "identified, and articulated a process to mitigate, areas of potential consumer harm."
That last item is not a request for reassurance. A good answer names the specific harms your practice can cause — suing the wrong person, suing on a time-barred debt, calling outside permitted windows, continuing collection through a dispute, filing on incomplete documentation — and, for each, names the control that prevents it and the record the control leaves. "We comply with the FDCPA and Regulation F" tells a reviewer nothing they can test.
The business-experience questions have a specific edge for law firms. The guidance directs the bank to evaluate a third party's "history of addressing customer complaints or litigation and subsequent outcomes." For a collections firm, adverse FDCPA judgments, bar complaints and sanctions are the relevant history, and they are public. Disclose them with the outcome and what changed afterwards. A discoverable omission costs more than the incident.
Information security
This is the section where the bank has the least room to negotiate, and knowing why helps you answer it in the right register. Under the Interagency Guidelines Establishing Information Security Standards — a rule, not guidance — each institution must "[r]equire its service providers by contract to implement appropriate measures designed to meet the objectives of these Guidelines," and, where its risk assessment indicates, monitor them to confirm they have. The analyst asking you for an encryption standard is discharging a standing obligation of their employer.
The questions themselves come from the guidance's information-security topic: the consistency of your programme with the bank's, your approach to confidentiality, integrity and availability of the bank's data, and "the extent to which the third party applies controls to limit access to the banking organization's data and transactions, such as multifactor authentication, end-to-end encryption, and secure source code management." Expect follow-ups on threat and vulnerability management, penetration and vulnerability test results, and remediation of what testing found.
A good answer is concrete and dated: MFA enforced on every remote path with the enforcement mechanism named; encryption in transit and at rest with where the keys live; the date of the last penetration test, who ran it, whether findings were closed and how that is evidenced. If you have a SOC 2 report, offer the report and the bridge letter rather than the logo — the guidance tells the bank to consider whether the scope of a SOC report is actually relevant to the activity, so a report scoped to a hosting provider will not answer questions about your practice. If you do not have one, say so and offer what you do have: the policy set, the last independent assessment, the remediation log.
Subcontractors, and what counts as one
The guidance uses "subcontractors" for any supplier, service provider or other organisation your firm enlists, and it directs the bank to evaluate "the volume and types of subcontracted activities and the degree to which the third party relies on subcontractors," including how you select and oversee them, whether their geography adds risk, and whether you depend on a single provider for several activities.
Firms routinely under-report here because they read "subcontractor" as "contract lawyer." For a collections practice the real list is longer: case management hosting, document storage, the electronic filing service provider, print and mail, skip tracing and data append, dialer and telephony, payment processing, records destruction, IT managed services, and any local or forwarding counsel who touches the file. Anywhere consumer data leaves your building, the bank's question reaches.
Answer with an inventory rather than a narrative: vendor, what they do, what data they receive, where they process it, what contractual security terms bind them, and what you review annually. Concentration is a separate question and worth answering unprompted — if one vendor supplies hosting, filing and telephony, say so, because the bank will otherwise discover it during an incident. The guidance also asks the bank to look at your legally binding arrangements with other parties to see whether they transfer risk back to the bank, so an assignment or subcontracting clause you agreed to years ago may come up.
Complaint handling
Where the third party interacts with customers, the guidance tells the bank to specify in the contract who answers complaints, and, if it is you, to require you to respond in a timely manner and to give the bank "sufficient, timely, and usable information to analyze customer complaint and inquiry activity and associated trends." Ongoing monitoring then covers "[t]he volume, nature, and trends of customer inquiries and complaints, the adequacy of the third party's responses (if responsible for handling customer inquiries or complaints), and any resulting remediation."
Read those two clauses together and the reporting shape becomes clear. A quarterly count is not an answer. What the bank needs is categorised volume over time, time-to-resolution, outcome, and what changed as a result — and it needs it in a form its own analysts can aggregate with complaints from other channels.
The hardest part in practice is definitional. Firms tend to count only what arrives labelled as a complaint, while a bank counts anything a consumer said that expressed dissatisfaction, including inside a dispute letter or a call the collector coded as a refusal to pay. Agree the definition in writing before the first report, and state your definition in the questionnaire answer. A trend line that changes shape because you changed your definition is worse than no trend line.
Business continuity and incident reporting
Resilience questions ask whether you can keep working through a disruption and how fast you recover. The guidance points at disaster recovery and business continuity plans "that specify the time frame to resume activities and recover data," the results of continuity testing and performance during real disruptions, telecommunications redundancy, and preparedness for wide-scale events. On the contract side it notes that contracts often require the third party to supply operating procedures to be used when continuity plans are invoked, "including specific recovery time and recovery point objectives," and may set out whether and how often the two sides test jointly.
So the answer the bank wants is numeric and evidenced: an RTO and an RPO for each service you provide them, the date of the last test, what failed in it, and what you changed. "We maintain a business continuity plan" is the answer that generates a follow-up. For a litigation practice, add the thing generic templates miss — what happens to court deadlines during an outage, and who is authorised to seek relief for a missed filing.
Incident questions run on a parallel track. The guidance directs the bank to look for "clearly documented processes, timelines, and accountability for identifying, reporting, investigating, and escalating incidents." The security standards go further: the bank's contract with its service provider "should require the service provider to take appropriate actions to address incidents of unauthorized access to the financial institution's customer information, including notification to the institution as soon as possible of any such incident, to enable the institution to expeditiously implement its response program." Practically, that means you need a current named contact at each bank client, an internal trigger definition that does not require certainty before it fires, and a runbook that treats notification as an early step rather than a conclusion.
Audit rights — answer without promising what you cannot deliver
The final block asks what the bank may inspect. The guidance is direct: a contract "generally" includes provisions for "periodic, independent audits of the third party and its relevant subcontractors, consistent with the risk and complexity of the third-party relationship," should describe the types and frequency of audit reports the bank is entitled to receive, and may reserve the bank's right to audit you itself or to send an independent party.
This is the section where firms create future problems by being agreeable. An unqualified right to audit "and its subcontractors" commits you to something your vendor contracts may not permit; committing to an annual SOC 2 Type II commits you to a recurring six-figure exercise; committing to "any records" collides with privilege and with your obligations to other clients. Answer with what you can actually do and say plainly what you cannot: which reports you will provide and when, what notice you need for an on-site review, which subcontractors you can pass audit rights through to today and which you will seek at renewal, and how privileged and other-client material is segregated.
One more thing to expect. The same guidance tells the bank that monitoring may be periodic or continuous, and that more frequent monitoring is appropriate for higher-risk activities. If the relationship is classified as supporting a critical activity — a determination the guidance leaves entirely to the bank — the questionnaire is not an event. It is the first instance of a recurring reporting relationship, and the answers you give now become the baseline you will be measured against.
Primary sources
-
The information-security due-diligence topic, and the specific controls named
considering the extent to which the third party applies controls to limit access to the banking organization's data and transactions, such as multifactor authentication, end-to-end encryption, and secure source code management
-
What the subcontractor questions are actually asking
An evaluation of the volume and types of subcontracted activities and the degree to which the third party relies on subcontractors helps inform whether such subcontracting arrangements pose additional or heightened risk to a banking organization.
-
Complaint and litigation history as a due-diligence topic
history of addressing customer complaints or litigation and subsequent outcomes
-
The consumer-harm question, verbatim
considering whether the third party has identified, and articulated a process to mitigate, areas of potential consumer harm
-
Recovery objectives and continuity testing
including specific recovery time and recovery point objectives
-
What the incident questions look for
clearly documented processes, timelines, and accountability for identifying, reporting, investigating, and escalating incidents
-
The complaint-reporting contract provision
to provide the banking organization with sufficient, timely, and usable information to analyze customer complaint and inquiry activity and associated trends
-
What an audit-rights clause typically contains
Generally, a contract includes provisions for periodic, independent audits of the third party and its relevant subcontractors
-
Why the questionnaire recurs
Ongoing monitoring may be conducted on a periodic or continuous basis, and more comprehensive or frequent monitoring is appropriate when a third-party relationship supports higher-risk activities, including critical activities.
-
Complaint volume, nature and trend as a monitoring input
The volume, nature, and trends of customer inquiries and complaints, the adequacy of the third party's responses (if responsible for handling customer inquiries or complaints), and any resulting remediation.
-
Legal effect — the guidance is not a rule
Supervisory guidance does not have the force and effect of law and does not impose any new requirements on banking organizations.
-
Interagency Guidelines Establishing Information Security Standards, 12 CFR pt. 30, app. B, § III.D.2
The standing rule behind the security section of every questionnaire
Require its service providers by contract to implement appropriate measures designed to meet the objectives of these Guidelines
-
Why the bank needs notification from you as soon as possible
including notification to the institution as soon as possible of any such incident, to enable the institution to expeditiously implement its response program
This is an informational reference, not legal advice, and using it creates no attorney-client relationship. Limitations periods turn on facts this page cannot know — which state's law governs, the contract type, when the claim accrued, and whether anything tolled or revived it. Confirm against the primary source and your own counsel before acting.