The third-party risk industry has a favorite success story: vendor reviews that used to take three weeks now take three days. That is a genuine operational win, and it is close to irrelevant in your next examination. Examiners do not grade how fast you review vendors — they grade whether oversight operated on schedule, across the whole portfolio, with evidence behind every number.
Key Takeaways:
- Review turnaround time, documents processed, and hours saved are operations metrics; examiners grade coverage, timeliness, aging, and evidence currency
- Seven metrics carry examination weight: risk-rating coverage, on-schedule review completion, findings aging and closure, evidence currency, exceptions with approvals, fourth-party identification, and board reporting
- Every examination metric needs an artifact behind it; a percentage without supporting records is an assertion, not a metric
- A program can double its review speed and still fail an exam if reviews did not happen on the cadence its own policy requires
Why Faster Vendor Reviews Don't Impress Examiners
AI review copilots and document repositories have genuinely compressed the time it takes to analyze a SOC 2 or complete a questionnaire. That creates capacity, and capacity is valuable. But ongoing monitoring under OCC Bulletin 2023-17 is an expectation about continuity and proportionality: banks should monitor third parties throughout the relationship, with intensity commensurate with the risk and criticality of the activity.
The examination approach reflected in the FFIEC IT Examination Handbook tests whether the program operated as designed. Examiners sample vendors, check that reviews occurred when policy required, and inspect the evidence behind each one. The speed of any individual review appears nowhere in that test. Speed only matters if the freed capacity gets spent on coverage and timeliness — the numbers examiners actually read.
Operational Metrics vs. Examination Metrics
| Operational metrics (what dashboards celebrate) | Examination metrics (what examiners grade) |
|---|---|
| Review turnaround time | Reviews completed on schedule vs. policy cadence |
| Documents processed and analyzed | Percentage of third parties risk-rated and current |
| Hours saved per review | Findings aging and closure rate |
| Questionnaires completed | Expired or missing evidence items |
| Reviews per analyst | Exceptions outstanding, with documented approvals |
| Time to onboard a new vendor | Fourth parties identified for critical vendors |
| Platform adoption and logins | Board reporting frequency and content |
The left column measures the machinery. The right column measures the program. Both are worth tracking, but only one column decides how your third-party exam goes.
The Seven Metrics Examiners Actually Grade
Percentage of third parties risk-rated and current
The risk rating drives everything downstream: review cadence, due diligence depth, monitoring intensity. A vendor with no rating, or a stale one, is a vendor whose oversight was never calibrated. Good looks like near-complete coverage with ratings refreshed on the schedule policy sets. The supporting evidence is the rating record itself — methodology, date, and approver.
Reviews completed on schedule vs. policy cadence
Your policy sets a cadence — annual for critical vendors, less frequent for lower tiers — and examiners test operation against your own document. Good looks like a high on-time percentage with documented handling of any misses. The evidence is the review work item trail: due date, completion date, reviewer, and the assessment produced.
Findings aging and closure rate
Reviews that surface gaps nobody fixes are documentation, not risk management. Examiners read the aging report to see whether findings move: a shrinking 90-plus-day bucket, closures keeping pace with new findings, no past-due critical items without an approved exception. The evidence is the finding record with owner, deadline, and closure artifact. What happens after the vendor review finds gaps is its own discipline.
Expired or missing evidence items
SOC 2 reports, insurance certificates, and financial statements all age out. An expired artifact means monitoring lapsed for however long nobody noticed. Good looks like tracked expiration dates with renewal work triggered before expiry and documented exceptions for anything outstanding. The evidence is an evidence register with dates — not a folder of PDFs of unknown vintage.
Exceptions outstanding, with approvals
Exceptions are legitimate; unapproved or perpetual ones are not. Examiners check that every open exception names an approver with appropriate authority and carries an expiry date forcing re-approval. Good looks like a short, current register the board has seen. The evidence is the exception record: what was accepted, why, by whom, until when.
Fourth parties identified for critical vendors
The interagency guidance expects banks to understand significant subcontractor reliance behind critical activities. If a critical vendor's own providers are unknown, the bank cannot assess concentration or continuity risk. Good looks like documented fourth parties for every critical relationship, considered during the review. The evidence is due diligence records that name them.
Board reporting frequency and content
The guidance places ultimate accountability with the board, and examiners read the minutes. Good looks like periodic reporting that covers the portfolio's shape, critical relationships, findings and their aging, and open exceptions — not a single reassuring slide. The evidence is the reports themselves plus minutes showing they were received and discussed.
A Program Can Double Review Speed and Still Fail the Exam
Picture a bank that cut review turnaround by 60 percent, while one in five vendors lacks a current risk rating and critical findings average 200 days open. The examiner never asks how long a review takes. They ask for the vendor inventory with ratings, sample reviews against the policy cadence, and pull the aging report — and each answer needs records behind it.
That is the trap in celebrating operational metrics: they can all improve while the program's actual obligations go unmet. The full set of expectations is covered in our guide to what examiners expect from third-party risk management, and our third-party risk exam preparation guide walks through the request list itself.
How Modern Teams Produce Examination Metrics
The seven metrics above share one property: they cannot be assembled at exam time. They are byproducts of work executed on schedule with evidence captured as it completes. If reviews, renewals, and re-approvals run through email and spreadsheets, the metrics are reconstructions — and reconstructions have gaps.
In Canarie, each vendor obligation generates recurring review work with owners and due dates; evidence attaches at completion; findings, exceptions, and expirations are dated records rather than tribal knowledge. Coverage, timeliness, and aging become live views instead of quarterly assembly projects.
See what examiners will ask of your TPRM program →
Frequently Asked Questions
What TPRM metrics should be reported to the board?
Board reporting should cover the portfolio and its exposures, not operational throughput: the number and criticality distribution of third parties, risk-rating coverage, review completion against policy cadence, findings aging with past-due items highlighted, open risk acceptances, and any concentration concerns including fourth-party reliance. Examiners read board minutes to verify this reporting happened on a regular schedule and prompted actual discussion.
How often should third parties be reviewed?
The interagency guidance does not prescribe a frequency; it requires monitoring commensurate with the risk and criticality of the activity, which banks translate into a tiered cadence in policy — commonly annual for critical and high-risk vendors and every two to three years for lower tiers, with continuous monitoring of key indicators for the most critical relationships. Whatever cadence your policy sets becomes the standard examiners test against.
What do examiners actually test in a third-party risk exam?
They test whether the program operated as designed: a complete vendor inventory with current risk ratings, reviews completed on the schedule policy requires, findings tracked to closure with artifacts, exceptions formally approved and time-bound, and board reporting that demonstrates oversight. They sample individual relationships and trace each one through the lifecycle, so a single vendor with missing records can undermine an otherwise strong narrative.
Do faster vendor reviews help with examinations at all?
Indirectly, yes — speed creates capacity, and capacity spent on coverage and timeliness improves the metrics examiners grade. A team that reviews vendors in days instead of weeks can keep the full portfolio on schedule with the same headcount. The mistake is treating turnaround time as the outcome rather than the input; an exam rewards the program that operated on schedule, not the one that operated quickly.