When most credit union leaders hear the phrase “third-party risk management,” their minds usually jump straight to tedious compliance checklists, examiner scrutiny, or worst-case cybersecurity nightmares.
But what if vendor risk management wasn’t just a defensive shield—what if it was actually a engine for strategic growth and member value?
In this episode of The Credit Union Connection podcast, host Sarah Snell Cooke sits down with Ncontracts CEO Michael Berman (a self-proclaimed “recovering lawyer turned entrepreneur”) and Ncontracts risk expert Michael Carpenter (former credit union Chief Risk Officer and BSA/AML veteran). Together, they share insights from their book, The Upside of Third-Party Risk Management: The Practitioner’s Guide to Turning Vendor Risk into Strategic Value.
Whether you’re looking to get past examiner-minimum compliance or want to align your third-party relationships directly with your credit union’s mission, this conversation delivers actionable, real-world advice.
Catch the full episode to learn how to turn vendor risk into strategic value!
NOTE: This transcript may contain minor imperfections courtesy of our AI overlords-in-training. We’re not complaining. We’re definitely not complaining.
Sarah Snell Cooke: Hello, and welcome everyone. I am Sarah Snell Cooke, your host here at The Credit Union Connection. I am joined today by Michael and Michael. Now, I’ve been told I can call them Michael Berman and Michael Carpenter. Welcome.
Michael Carpenter: Thanks for having us.
Sarah Snell Cooke: Yeah, thank you… a company called Ncontracts. Michael Berman is the CEO there. Why don’t you tell us a little bit more about yourself and the company?
Michael Berman: Fantastic. First, Sarah, thank you so much for having us on. My name’s Michael Berman. I’m the founder and CEO here at Ncontracts. I’m a recovering lawyer turned entrepreneur, so I’ve been involved in third-party risk management and operational risk management both as a lawyer and now for 17 years helping financial institutions, wealth management firms, and mortgage companies deal with the complexities of operational risk management, including third-party risk management.
Sarah Snell Cooke: Yep, always a big topic of discussion. And Carp, tell us a little bit more about yourself.
Michael Carpenter: Yeah. Thanks, Sarah, and I echo Mr. Berman—glad to be here. Out of the military, my early time in the financial institution space was really financial intelligence with a BSA/AML focus. But then when I went to community banks and then ultimately the credit union, I served as a risk officer, chief risk officer, and owner of the vendor management programs. I used Ncontracts as a client, and so now I’m here and get a chance to talk about my experiences.
Sarah Snell Cooke: Yeah. That’s perfect as a credit union person, being able to talk from that side of the fence as well. So the reason I asked you all here today is ’cause I understand you’re launching a book, The Upside of Third-Party Risk Management. You make it sound so positive: Third-Party Risk Management: The Practitioner’s Guide to Turning Vendor Risk into Strategic Value. Now, what is the impetus behind this book?
Michael Carpenter: I’ll go ahead and start. So colleagues of ours internally at Ncontracts look at vendor management. The floor of third-party risk management is established through some pretty standard and well-known doctrine, and it talks about the five stages of vendor management and has a focus on risk—as it should.
However, as you mature, then you start to actually gain a lot of benefit from the effective risk management that you do. Examples include an awareness of not just that the vendor’s important, but the actual impact to the organization should it go down, giving you much more insight to make informed business decisions. Does the contract have liability amounts that actually address the impact of an outage? Is our insurance appropriate? Do we have appropriate backups? Does the vendor actually help me get where I’m going?
So there’s a lot to say, but there is a broad spectrum. From 2015, when we really started as a financial industry getting serious about vendor management and having programs, there’s been a shift, and now the ship is turning to being strategic and doing things for a business purpose.
Michael Berman: And to add to that, I think there’s a lot of fear-mongering out there where people think third-party risk management is somehow equivalent to cybersecurity and that you need to do this just for defensive purposes.
I like the analogy that third parties are a lot like the people your credit union works with. You have employees and you have vendors. Can you imagine running a credit union and never meeting with any employee to do a review, or never really managing your employees in any way whatsoever? And yet we have vendors that, once they’re onboarded, nobody really manages, and yet some of them have access to every piece of member information.
When a credit union does an effective job at managing those third parties, they can get much better outcomes for their members, and it becomes a benefit to all those members. Is the vendor providing all the things I want? How’s the vendor evolving as I evolve as a credit union? That matters so much more, and there’s a lot more to it than just, “Did the vendor do something bad?” We want the vendor to do great things for our members as they move forward, just like we want our employees to do great things for our members as we continue the mission.
Sarah Snell Cooke: Yeah, that’s really interesting insight there. I’ll stick with Berman for a while. The premise of the book is that programs aren’t failing because controls are missing; they’re failing because it’s not connected to the executive strategy, which you guys have both touched on. Can you explain a little bit more about that, please?
Michael Berman: Absolutely. When it comes to thinking through what our long-term mission is, what we are trying to accomplish, and what our goals are as a credit union, there are multiple ways to get there, and part of that is vendor relationships. Most credit unions are never going to develop their own technology for online bill pay, digital wallets, or cryptocurrency. The list goes on and on, so you’ve got to partner with the right vendors.
That’s more than just “the vendor’s not going to lose my member data” (certainly hope that doesn’t happen) and “I want to make sure the vendor’s financially solvent”. You can tell I’m checking boxes, right? Okay, they do those things, but what is really being delivered? Where is my vendor going?
One of the things that’s fascinating is vendors are evolving. When we buy a subscription to software that’s all online—and most software is now online—it’s not static. We’re not buying a rug that’s going to be in the center of the lobby of the credit union, and then we’re done decorating. Instead, this thing’s going to constantly evolve. Is it going to evolve in a way that helps my members over time, or is it going to create burdens for us that we didn’t realize?
Every time we change our own internal employee work structure, we’ve got to spend resources changing a workflow in some software that no longer fits our organization, creating unintentional costs that no one’s really accounting for that ultimately harm the membership. Those are some extreme examples, but ultimately, we’re trying to get those things aligned so everything’s working in lockstep towards the goals that the executive team for the credit union lays out for their organization.
Sarah Snell Cooke: Anything to follow up, Carp?
Michael Carpenter: Yeah, I would say if you don’t define or know where you’re going, then how do you know when you get there? Or how do you know when you’re going the wrong direction? I agree with everything Mr. Berman said.
Sarah Snell Cooke: Financial institutions, as we’ve seen—especially as tech has evolved—aren’t running themselves anymore. They are using all these vendors to come in and run the credit union from an operational perspective, at least. So when one of these vendors fails—and it happens, we know some stories—what are some examples that you can provide that might cause the biggest issues for credit unions or are somewhat common mistakes?
Michael Berman: I’ll start with the one that I think people don’t pay nearly enough attention to: business continuity management.
People will have outages, and if you aren’t paying attention—as you mentioned, I still think credit union leadership runs the credit union, but you’re dependent highly on these systems to provide access to members’ money. That relationship more and more is digitally oriented, where you’re using an app or a web interface to interact with the credit union. If it’s down, the whole credit union’s basically down.
So if you don’t fully understand business continuity—meaning if my vendor’s down, how long can they be down for? What are their backup systems? Are they tested? This is no longer a check-the-box exercise. This is now, “I’m down, and how long can I be down before my members have real problems because they can’t access their money?” They can’t live their lives the way they’re used to living them because of this outage. They’re not going to blame the vendor; they’re going to blame the credit union.
We’ve seen this happen time and time again now where a credit union feels blindsided because all of a sudden they have a disruption in service caused by a vendor who didn’t have an adequate business continuity plan, and no one had done the adequate planning to think about, “What do we do if this happens?” That’s a classic case of how this manifests itself in the real world and creates real problems.
Sarah Snell Cooke: And I’ve heard of experiences where a credit union can’t get the testing results of that business continuity plan. They don’t get access to the results of the testing of the plan, which I think is kind of interesting—something that they should really insist upon.
Michael Berman: There are ways around that, yeah. It pains me to hear that because that’s a big vendor bullying a credit union.
It’s time to make sure you’ve got that. I hear Michael Carpenter talk about this all the time: failure to plan means you set yourself up for this. That should be in the contract; that should be required boilerplate. And no, this is not an advertisement to pay lawyers more money. You should have a set of things you’re requiring that are basic for anything that’s a critical service for you.
If the vendor won’t agree to those things, which includes giving you their business continuity plans and test results, you need a new vendor. As painful as that might be, you need somebody who’s going to provide that for you, because what you’re basically saying is, “This vendor relationship is more important than my members’ experience.” I can’t imagine any executive at a credit union who says, “Yep, that’s the value I have.” It’s a short-term lack of pain switching a vendor versus long-term pain when that vendor does something bad and you now have zero recourse, nothing you can do, and your members are the ones who suffer.
That planning is absolutely critical to having successful vendor relationships.
Sarah Snell Cooke: Absolutely. Carp, I want you to follow up on that, but also, having been inside a credit union working as the CRO (chief risk officer), credit unions have historically prided themselves on the human touch, knowing their members, the local community, that sort of thing. How should credit unions look at this from a competitive position and how it affects member relationships as more and more vendors are coming in?
Michael Carpenter: I love that question. Third-party risk management actually is every single individual, and I’m glad you touched on the fact that credit unions differ in that they have these relationships with their communities. They are member-owned and member-driven. Every single employee at a credit union is almost like the liaison of the vendor; they are the face of the products and services offered by that third party.
When the third party isn’t performing well, the face is the one taking the blame. Member attrition could be a real problem because economies of scale benefit membership. As members leave to go somewhere else because it looks like the business isn’t working and the vendors aren’t working, there’s citable data that shows just how much attrition costs a credit union. That ultimately affects the membership and the ability for the credit union to offer more competitive rates, like in auto lending and home lending. There’s this trickle-down effect.
So to answer your question, market competitiveness does matter. You don’t want your members leaving; more members benefit the collective. Efficiency ratios may look decent on paper, but not doing our best to get the most out of what we invest in our third parties ultimately affects the membership. Again, members leaving costs the remaining members in one way or another.
Sarah Snell Cooke: Absolutely. We’ve seen that play out in headlines over the years, I’m sure. Particularly Michael Berman, what should credit unions be thinking about with vendor concentration risk these days? I feel like I hear there is a trend back toward one vendor that can serve multiple purposes versus a bunch of different small vendors, like the fintechs coming in.
Michael Berman: There can be advantages to having one vendor, and of course, those vendors are typically a Jack Henry, a Fiserv, or an FIS, and they do have a tremendous number of solutions.
Now, whether you’re getting best-of-breed solutions for everything you just signed up for is another question. What it does is simplify some things and complicate others.
It simplifies that you probably have better interfaces between the solutions. You’ve got one vendor, which means you’ve got one set of financials to review. That’s really the only thing that gets unified, because you’re still going to want to do tests and review SOC reports for all the products. But you feel like you’ve simplified things.
On the other hand, you’ve complicated another matter that many people bury: if I ever have to switch, I’ve got to switch it all. What does my business continuity plan look like at my credit union if I have to get off 30 products at my core? That’s going to be pretty complicated to put together. Probably our friends at the big cores aren’t going to help you with that because they never want you to leave. They believe in the Hotel California method—once you’re on, they really want to make sure you’re never ever going to leave.
That’s okay, but technology changes, companies change, and leadership changes. Probably the most egregious contract I’ve seen, without naming the core vendor, is a 25-year agreement for a core system. Let’s think about that: did the phone change at all in the last 25 years? Did computers change at all in the last 25 years? Tech is moving super fast, and 25 years is a lifetime in the technology world. While it might sound good and you get great pricing, you are creating other real costs that will impact the credit union.
Going back to the strategic plan: what are we trying to accomplish, and how do we get there? Typically, it’s not with a long-term, 25-year agreement with one vendor because you’re creating a tremendous amount of risk. Going back to my analogy, it’s the same as saying, “I’m going to hire one person to work at the credit union and they’re going to do everything, and let’s just hope they don’t get hit by a bus.”
Sarah Snell Cooke: Yeah.
Michael Carpenter: Can I add to that, Sarah?
Sarah Snell Cooke: Of course.
Michael Carpenter: Thinking about being at a credit union, we wanted our members to use every product that we had available for that member, right? And the credit union has a narrative of why that benefits the individual. There are pros and cons to everything, but for the credit union, when it talks to its member about “you don’t need to go to Financial Institution A for that product, Financial Institution B for that other product, and then us for this product”—they want them all here. Most of that from a credit union perspective is a relationship angle: “You can trust us,” and “You know us.” The consumer isn’t worried about the credit union going down and all their eggs being in one basket.
So again, a pro is the relationship. But like all the things Michael mentioned, cons could be the lack of information. Ultimately, as Michael said, it comes back to strategy. If we’re focusing on where we’re going, one vendor helping us in lots of different ways to get there and actually doing it is great. One vendor tied to many areas not helping us—
Sarah Snell Cooke: —isn’t so great. Absolutely.
So we’re running close on time. I gotta mention AI. You can’t do a talk on vendor management risk without talking about AI, and I know this is also in your book. What are some of the key topics under AI vendor risk management that are new, perhaps? Michael Berman?
Michael Berman: Either of us can start. I think people need to understand first what AI is, because there’s a lot of noise in the marketplace and what one vendor calls AI is not necessarily a textbook definition of what AI really is.
Then there’s due diligence. You need to be asking your current vendors—even if you’re a credit union that’s not looking to get into AI—your current vendors may already be leveraging it. Speaking about how vendors change over time, what risk does that create for your credit union that you now have to make sure you’ve got appropriate controls in place for? Whether you’re talking about Fannie or Freddie, who have rules around AI if you’re selling mortgages to them that you’ve got to comply with. I’ll run out of time talking about it, but you’ve got to have a framework to evaluate vendors, both current and prospective, from an AI point of view. Michael?
Michael Carpenter: I’ll say two major points: one, consistency; number two, risk-based.
“Risk-based” is thrown around a lot, but applying Michael’s statement of true AI, define it for yourself so you know what you’re looking for. It isn’t scary just by its presence. It can be more risky depending on its impact should it go away or should it get it wrong.
Back to consistency: set what is risky to you, set what is more risky than another, and then be consistent in your response. That’s the fastest way I can talk AI vendor management.
Sarah Snell Cooke: Excellent insights. Thank you. Now, I always allow my guests to have the final thoughts. We’ll start with you, Michael Berman.
Michael Berman: I certainly appreciate the time here at The Credit Union Connection. I would encourage people to read our book, The Upside of Third-Party Risk Management, and if you have any questions, please let us know. We’d be delighted to help in any way that we can.
Sarah Snell Cooke: Awesome. Thank you. And Carpenter?
Michael Carpenter: Yeah. I would say that you can get by meeting the expectations of an examiner, but I believe in the industry and the professionals that I’ve met to not just do the minimum. The book attempts to make things reality and operational. So yeah, read the book.
Sarah Snell Cooke: Excellent. Awesome. Thank you, guys, for your time. Appreciate it.
Michael Berman: Thank you.
Sarah Snell Cooke: Of course. Have a great rest of your day.
Michael Berman: You the same. Thank you. Bye.