Skip to content
BOL Conferences

Thread Options
#499039 - 02/14/06 10:47 PM Vendor Due Diligence
Wiqit Offline
Member
Joined: Dec 2004
Posts: 56
Are we required to obtain a confidentiality agreement from the credit reporting agency? We have a contract, do we also need a confidentiality agreement?

Does anyone have guidance on what type of information is required to be obtained for specific types of vendors?

I appreciate any assistance! Thank you!

Return to Top
Operations Compliance
#499040 - 02/15/06 04:38 PM Re: Vendor Due Diligence
P*Q Offline

Power Poster
P*Q
Joined: May 2001
Posts: 8,458
Somewhere
In response to your first question, if your contract contains the required language relating to information security, there should no need for an additional agreement. We found that when GLB first came out, a lot of contracts didn't have language and we had to develop an agreement. However, has time as gone on, most are aware of what banks will be looking for and generally contain the language or something similar.

Return to Top
#499041 - 02/17/06 08:27 PM Re: Vendor Due Diligence
BrendaC Offline
Power Poster
BrendaC
Joined: Sep 2001
Posts: 6,029
Sweet Home AL
We risk rate our vendors based on risk associated with information security and business continuity. If a customer is rated as high risk in either category, we require annual review of financials and SAS70 or other audit to identify internal control weaknesses. Any vendor that has access to customer information must execute a contract with GLBA info security verbiage, security breach notice and document disposal language. I have a sample security agreement that serves as an addendum to any existing contract for those contracts that do not contain satisfactory language.
_________________________
Life without Jesus is like an unsharpened pencil - it has no point.

Return to Top
#499042 - 05/11/06 10:54 PM Re: Vendor Due Diligence
researchlady Offline
New Poster
Joined: May 2006
Posts: 2
Hello, I seen your response regarding having an addendum if the vendor does not have the GLBA verbiage in the agreement. Do you mind sending me a a copy, I currently audit 3rd party vendors and this info would be useful.. I appreciate your help.

Return to Top

Moderator:  Andy_Z, John Burnett