third party due diligence - acuia...third party due diligence by: christy c. jones sherpy &...

46
Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. [email protected]

Upload: others

Post on 08-Aug-2020

4 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Third Party Due Diligence

By:

Christy C. Jones Sherpy & Jones Law P.A.

[email protected]

Page 2: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Who Can Be a Third Party?

• VENDOR

• CUSO

• ANOTHER CREDIT UNION

Page 3: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Why Engage in Third-Party

Relationships?

Access to more Products & Services

More Cost-Effective Products &

Services

Benefit from External Expertise

Page 4: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

This Results in:

• Increased member

services

• Competiveness

• Economies of Scale

• Increased Delivery

Channels

• Reach New

Members

Page 5: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

RISKS OF VENDOR

RELATIONSHIPS

Relinquish Control

Possible Interruption of Services

Possible Legal Disputes

Page 6: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

7 DEADLY RISKS

• CREDIT

• INTEREST RATE

• LIQUIDITY

• TRANSACTION

• COMPLIANCE

• STRATEGIC

• REPUTATIONAL

RISK

Page 7: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

What to do with Risk?

• Mitigate risk

• Transfer risk

• Avoid risk

• Accept risk

• Rarely eliminate risk

Page 8: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Factors that Determine Level of

Scrutiny:

• Credit Union’s Risk Profile;

• Safety and Soundness Requirement;

• Core v. Non-core Function of Service provided;

• Long standing and tested history with Vendor;

• Degree of Control Maintained over Vendor

Functions

Page 9: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Small Credit Unions

• If new to Vendor

Relationships, Test the

Water

• Contract has well-defined

goals

• Contract has small goals

• Develop experience

Page 10: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Three Steps to Analyze

Third-Party Relationships

• Risk Assessment and Planning

• Due Diligence; and

• Risk Measurement,

• Monitoring and Control

Page 11: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

RISK ASSESSMENT & PLANNING

• What are you trying to do?

• What is your contract about?

• How does the service/product relate to your overall mission & philosophy?

• How does it relate to your strategic plan?

Page 12: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Strategic Plan

• Consider long-term goals & resources

• Action plan should be designed

• Strategic Plan’s Goals should be measurable &

achievable

• Plan should define levels of authority &

responsibility

Page 13: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Planning & Initial

Risk Assessment (Cont’d)

Compare Proposed Outsourced

Service against maintaining those

Services in-house.

Page 14: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Your Dynamic Risk Assessment

• Expectations for Outsourced Functions

• Staff Expertise

• Criticality

• Risk-Reward / Cost-Benefit

• Insurance

• Impact on Membership

• Exit Strategy

Page 15: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Financial Projections

• Project a return on investment

• Consider revenues, direct & indirect costs

• Will be evaluated for:

– reasonableness;

– considering historical performance;

– considering underlying assumptions;

– considering stated objectives.

Page 16: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

3 Steps to Analyzing

Third-Party Relationships

• Risk Assessment & Planning

• Due Diligence

• Risk Measurement & Control

Page 17: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

DUE DILIGENCE

“Systematic, on-going process of analyzing

& evaluating new strategies, programs,

products, or operations to prepare for and

mitigate unnecessary risks.”

Page 18: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Demonstrated = Documented

Page 19: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Due Diligence

• Background Check

• Vendor’s Business Model

• Cash Flows

• Financial & Operational Control Review

• Contract Issues & Legal Review

• Accounting Considerations

Page 20: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Background Check

• Experience with the particular service

• Request Referrals

• Research litigation

• Check that have proper licenses &

certifications

• BBB / FTC / CRAs / AG / State Consumer

Affairs Office

Page 21: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Business Model

“Conceptual architecture or business logic

employed to provide services to clients.”

Obtain Business & Marketing Plans, if

available

CU must understand key third party

business models

Page 22: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Business Model (cont’d)

• CU must understand vendor’s source of

income & expense.

• CU must consider possible conflicts of

interest

• CU must consider related parties (vendor’s

subsidiaries, affiliates, subcontractors)

Page 23: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Financial & Operational Control

Review

• Obtain & review Financial Statements of

Vendor

• May use NRSRO ratings

• May use SAS 70 (Type II) reports,

replaced by SSAE 16 in 2011.

Page 24: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

NRSRO Ratings

• Nationally Recognized Statistical Rating

Organizations

• Moody’s Investor Service, Standard &

Poors, Fitch Ratings, A.M. Best Co.

• SEC approves status as NRSRO

Page 25: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

SAS 70 (Type II)

• Statement on Auditing Standards No. 70:

Service Providers

• Is an auditing statement that defines

standards used by auditors to assess

internal controls of service providers

• Service Providers = Vendors

• Type II = includes auditor’s opinion re:

whether controls worked

Page 26: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

SSAE 16

• Replaces SAS 70 II as of 2011.

• Statement on Standards for Attestation

Engagements No. 16, Reporting on

Controls at a Service Organization

Page 27: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Contract Issues & Legal Review

• Qualified External Legal Counsel

• Should be Independent

Page 28: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

15 Little Contract Terms

• Scope of

arrangement

• Responsibilities

• Performance

Standards

• Penalties

• Access to records

• Servicing Rights

• Audit Rights

• Data Security

• Contingency Planning

• Insurance

• Member Service

• Regulatory

Compliance

• Dispute Resolution

• Default

• Termination

Page 29: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Big Focus:

• Performance Standards (usually lacking)

• Data Security (read a paper lately?)

• Regulatory Compliance (cannot fully

delegate duties under regs to agents)

• Default, Term and Termination

Page 30: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

CONTRACT REVIEW MUSINGS

Don’t Tell Vendor that it’s been selected until

contract has been reviewed

Contract Review should be part of Vendor

Selection Process

Page 31: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

CONTRACT REVIEW (Cont’d)

• Remember the

“entirety clause.”

• Read the contract.

• Do Not respond to

artificial time pressure

• Question Incentives

and Freebies

Page 32: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Contract Review (Cont’d)

• If IT contract, have IT Department Review

• If Indirect Lending, have Loan Department

Review

• If contract with Repossession Agent, have

Collections Department Review

Page 33: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Contract Review (Cont’d)

• Consider not obtaining comment letter;

• If obtain comment letter, do not give it to

vendor;

• NCUA examiners will see comment letters;

• Checklist just says “attorney review,” does

not require attorney letter

Page 34: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

IT Contracts

• 75% of IT Contracts do not describe

services provided;

• If services provided are included, it’s in

Exhibit that’s not attached to contract;

• Get past the Salesman & talk to vendor’s

tech guys;

• Larger IT Co’s have SSAE 16s which can

be purchased

Page 35: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Insurance

• Insurance can be denied if CU knowingly

failed to mitigate risks

• Don’t make Insurance the focus of your

analysis

Page 36: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Accounting Considerations

• GAAP used to track, ID & classify

transactions

• Does CU have accounting procedures for

new product / services?

• CPA’s advice may be necessary

Page 37: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

3 Steps to Analyzing

Third-Party Relationships

• Risk Assessment & Planning

• Due Diligence

• Risk Measurement & Control

Page 38: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Risk Measurement

• Policies & Procedures

• Monitoring

• Control Systems &

Reporting

Page 39: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Policies & Procedures

• Outline Staff Responsibilities

• Provide for Oversight of Vendor Performance

• Define content & frequency of reporting to CU management

Page 40: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Control Pace of

Program Growth

• Initially limit number

of transactions

under third party

programs

• Allows for oversight

and troubleshooting

• How applicable to

IT contracts?

Page 41: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Risk Monitoring

• CUs must measure performance of vendor

• Periodically verify accuracy of information

provided by vendor

• CU should designate employee

responsible for oversight

• Employee should have tickler system to

monitor performance

• Due Diligence is “On-Going”

Page 42: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Risk Monitoring

• CU ultimately responsible

for result of vendor service

• Cannot outsource safety &

soundness decisions

• CU must have adequate

staff, technology &

equipment to monitor

Page 43: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Control Systems & Reporting

• CU establish internal controls & audit

functions to ensure Vendor:

– Safeguards Member Assets;

– Produces Reliable Reports;

– Follows Terms of Vendor Contract

Page 44: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Control Systems & Reporting

(Cont’d)

• Vendors providing Material Programs must

send Reports

• CU staff must understand vendor reports

Page 45: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

3 Steps to Analyzing

Third-Party Relationships

• Risk Assessment & Planning

• Due Diligence

• Risk Measurement & Control

Page 46: Third Party Due Diligence - ACUIA...Third Party Due Diligence By: Christy C. Jones Sherpy & Jones Law P.A. ccj@sherpy-jones-law.com Who Can Be a Third Party? •VENDOR •CUSO •ANOTHER

Third Party Due Diligence

By:

Christy C. Jones Sherpy & Jones Law P.A.

[email protected]