HOMEPLATFORMPARTNERSPRICINGRESEARCH
Who we serve
Community BanksSponsor BanksFintechs
Blog · Third-Party Risk

Your Vendor Review Found Gaps. Now What?

Vendor risk remediation explained: how to convert review findings into risk-ranked plans, closure evidence, and the aging report examiners will ask for.

By Canarie Team · June 16, 2026

The vendor review is finished. The assessment flagged an expired SOC 2, an untested business continuity plan, and a subcontractor nobody had vetted. If your process ends with filing that report, you have documented risk without managing it — and an examiner will read it exactly that way.

Key Takeaways:

  • An assessment report sitting in a folder is evidence you knew about a problem, not evidence you managed it
  • Every finding needs an internal owner, a risk rank, a cure deadline, and a closure standard defined before anyone starts fixing anything
  • Closure requires an artifact — a reissued report, a configuration export, a test result — never the vendor's assurance that it is handled
  • Examiners will ask for a findings aging report; past-due items with no compensating control and no documented exception become exam findings of your own

Why the Assessment Report Is Not the Deliverable

Review tools and AI review copilots have made vendor assessment dramatically faster, which reinforces a dangerous assumption: that the assessment is the work product. The interagency framework says otherwise. OCC Bulletin 2023-17, which the FDIC adopted through FIL-29-2023, describes third-party risk management as a lifecycle — planning, due diligence, contracting, ongoing monitoring, and termination. The ongoing monitoring section expects banks to escalate and respond to issues they identify, not merely record them.

The examiner's logic is mechanical. Your dated report proves you knew about the gap as of a specific day. Everything the examiner asks from that point forward is a version of the same question: what happened next?


How to Convert Findings Into a Remediation Plan

Every finding coming out of a review should become a work item with four attributes fixed at creation:

  • Internal owner — a named person at the bank, not "the vendor." The vendor performs the fix; the owner drives it, tracks it, and answers for it
  • Risk rank — scored against the service's criticality and data access, not the control gap in the abstract. Missing multi-factor authentication at a vendor holding customer NPI is not the same finding as missing MFA at the landscaping company
  • Cure deadline — set by rank according to policy: for example, 30 days for critical findings, 60–90 for high, next review cycle for moderate. Once your policy sets these periods, examiners will hold you to them
  • Closure standard — the specific artifact that will prove the fix, defined before remediation starts, so nobody argues about it at the end

For findings that cannot close quickly, add an interim compensating control: enhanced transaction monitoring, restricted data flows, an added approval step. Document it in the finding record. When an examiner sees a 90-day cure window on a critical item, the next question is what covered the exposure in the meantime.


Re-Verification: Never Accept "We Fixed It"

A vendor's email saying the issue is resolved closes nothing. Closure means collecting the artifact defined in the closure standard: a reissued SOC 2 or bridge letter, a configuration export or dated screenshot, an updated policy with version history, a test result showing the control operating.

Two disciplines matter here. First, the artifact gets attached to the finding record itself, because that record is what an examiner samples when testing your remediation process. Second, the person verifying closure should not be the relationship manager whose scorecard rewards closing items quickly. The full workflow is covered in our guide to tracking vendor remediation to closure.


Exceptions and Risk Acceptances Need Expiry Dates

Some findings will not be remediated, and that can be a legitimate outcome — if it is documented as a risk acceptance rather than left as an aging item. A defensible exception record states what is being accepted and why, names an approver with the right level of authority under your policy, and carries an expiry date that forces re-approval.

The expiry date is the part most programs skip, and it is the part examiners check. A risk acceptance with no end date is not a decision; it is a finding that stopped being tracked. Exceptions should live in a register that management and the board can see, separate from open remediation items.


The Aging Report Examiners Will Ask For

At some point in a third-party exam, you will be asked to produce open and closed findings across the vendor portfolio, and the examiner will sort them by age. Build that report before they ask: findings by age bucket (0–30, 31–60, 61–90, 90+ days), by risk rank, with past-due items flagged against their cure deadlines and approved exceptions listed separately.

What good looks like is legible in the shape of the data: a shrinking 90+ bucket, closures keeping pace with new findings, and no past-due critical items lacking a documented exception. This single artifact tells an examiner whether remediation is a process or an aspiration — which is why it appears on every list of TPRM metrics examiners care about.


Feed Findings Into the Next Review Cycle and the Contract

Remediation history should open the next review, not disappear after closure. The first questions of any review cycle: were prior findings closed with evidence, and did any recur? A vendor that generates the same finding two cycles running is telling you something no fresh questionnaire will.

Finding history also belongs in commercial decisions. Contract renewals are the moment to convert lessons into terms — remediation obligations, audit rights, notification requirements. And the termination section of OCC Bulletin 2023-17 expects banks to have a considered basis for ending relationships; a documented record of repeated, unremediated findings is exactly that basis.


How Modern Teams Track Remediation to Closure

Tracking all of this in a spreadsheet works until the second review cycle, when open findings, exceptions, expiring evidence, and re-verification tasks start colliding. In a compliance execution platform, each finding is a work item with an owner, a deadline, and closure evidence attached; the aging report is a live view rather than a quarterly assembly job; and exceptions carry approvers and expiry dates that generate re-approval work automatically.

Canarie treats vendor findings the way it treats every other obligation: as owned, scheduled, evidenced work. When the examiner asks what happened after the review, the answer is already a record.

Turn vendor findings into owned, evidenced work →


Frequently Asked Questions

Who should own a vendor remediation item, the bank or the vendor?

The bank, always. The vendor performs the technical fix, but regulatory guidance places responsibility for managing third-party risk on the banking organization, so each finding needs a named internal owner who drives the item to closure and answers for it in an exam. "Waiting on the vendor" is a status the owner reports, not a substitute for ownership.

How long should a vendor get to fix a finding?

Cure periods should be set by risk rank in your third-party risk policy — commonly around 30 days for critical findings, 60 to 90 days for high, and the next review cycle for moderate items. The specific numbers matter less than two things: the rank reflects the service's criticality and data access, and the bank actually enforces the deadlines it wrote down. Examiners test performance against your own policy before anything else.

What counts as closure evidence for a vendor finding?

An artifact that demonstrates the fixed state: a reissued SOC 2 report or bridge letter, a dated configuration export or screenshot, an updated and version-controlled policy, or a test result showing the control operating. The vendor's written assurance that the issue is resolved is a status update, not closure evidence. Define the required artifact when the finding is opened so closure is a factual question rather than a negotiation.

Can a bank accept a vendor risk instead of remediating it?

Yes, if it is documented as a formal risk acceptance: a statement of what is accepted and why, approval by someone with the authority your policy requires, and an expiry date that forces periodic re-approval. Examiners generally accept well-documented exceptions; what draws criticism is the perpetual exception with no approver, no rationale, and no end date, which reads as unmanaged risk.

What is a vendor findings aging report?

It is a portfolio-level view of review findings organized by how long each has been open — typically buckets of 0–30, 31–60, 61–90, and 90+ days — broken out by risk rank, with past-due items flagged and approved exceptions listed separately. Examiners request it because it reveals in one page whether remediation operates on schedule. Programs that cannot produce it quickly usually cannot demonstrate that it does.

Topics:Third-Party RiskVendor ManagementRemediation

Ready to automate your compliance workflows?

See how Canarie transforms regulatory requirements into executed tasks with built-in evidence capture.

Explore the platform