Help

NCUA Glossary

The terms that come up in a credit union vendor management programme, and what each one means when an examiner uses it.

Appendix B

In credit union usage, “Appendix B” is Appendix B to 12 CFR Part 748 — the NCUA’s guidance on response programs for unauthorized access to member information. It is what sets the expectation that you can identify which vendors hold member data and notify members when that data is exposed.

The broader third-party due diligence expectations VendorLockbox is structured around come from NCUA Supervisory Letter 07-CU-13, Evaluating Third Party Relationships, with 12 CFR Part 749 covering records preservation. The exam prep checklist cites the specific source behind each procedure.

CAMEL Rating

The NCUA’s internal rating system for credit union health — Capital, Assets, Management, Earnings, and Liquidity — scored 1 (strongest) through 5 (weakest). Examiners assign it to your credit union; it is not something you self-report.

It is not a vendor field and VendorLockbox does not ask you for it. It appears here because it comes up in exam conversations and is easy to confuse with a vendor risk tier, which is a different thing you do set yourself.

Critical / High / Medium / Low vendor tiers

How VendorLockbox categorises a vendor by operational impact. Critical means that if the vendor goes down you cannot serve members today — core processor, card rails, settlement. High means they hold member PII or Social Security numbers. Medium covers business systems with limited member data. Low covers vendors with no material member data.

The tier drives everything downstream: how often the vendor is due for review, whether a SOC 2 report and a business continuity plan are expected, whether the vendor appears in your board report, and how an alert about them is prioritised. Critical vendors are reviewed annually and get board-level oversight.

Start with your best guess. The tier is editable at any time, and completing a due diligence review is usually what tells you whether you got it right.

Due Diligence

The documented evaluation of a vendor before you sign with them and periodically afterwards. It covers financial health, security posture, business continuity and disaster recovery, insurance, and the vendor’s own reliance on fourth parties.

“Documented” is the operative word. An examiner is not asking whether you thought about a vendor — they are asking to see what you looked at, when, and what you concluded. A review in VendorLockbox is that record.

Evidence Gap

A document an examiner would typically ask for that you have not uploaded — a missing SOC 2 report for a critical vendor, an expired certificate of insurance, a contract with no business continuity provision.

Gaps are computed from what is on file, not self-reported. Closing them before the exam is the single highest-leverage thing you can do with the time you have: every gap you close is a question the examiner does not have to ask.

Notice Period

The number of days of advance warning a contract requires. Contracts usually have two distinct ones and conflating them is expensive.

The cancellation notice period is how far ahead of the end date you must tell the vendor you are leaving, in order to stop the contract renewing automatically — often 60 to 90 days. Miss that window and you are committed to another full term. The termination notice period is the notice required to end the contract early, which is a separate right with its own conditions.

VendorLockbox tracks both and alerts you before the deadline, provided your alert email is set.

SOC 2 Type I vs Type II

Both are third-party audits of a service organisation’s controls over security, availability, processing integrity, confidentiality, and privacy. The difference is time.

A Type I report says the controls were suitably designed as of a single date — a snapshot. A Type II report says the controls actually operated effectively across a period, usually six to twelve months. Type II is the stronger assurance and the one to ask for.

Read the exceptions section and the complementary user entity controls, not just the opinion. Complementary user entity controls are the things the report assumes your credit union does; the vendor’s controls do not achieve their objectives without them.

TPRM (Third-Party Risk Management)

The discipline of identifying, assessing, and monitoring the risk your organisation takes on through the vendors, service providers, and partners it depends on. “Third party” is the vendor; a “fourth party” is whoever that vendor in turn depends on.

For a credit union, TPRM is the programme an examiner reviews: the inventory, the due diligence, the contracts, the evidence, and the board reporting that shows someone with authority is watching all four.

Vendor Inventory

The complete list of vendors your credit union uses, with each one’s risk tier, owner, and current status. It is the first thing an examiner asks for, because every other question they have is scoped by it.

Complete means complete: any vendor with access to member data or a role in critical operations belongs on it, including the ones procured outside IT. Most credit unions land somewhere between 30 and 80 vendors.

Still not sure how something applies to your credit union?

Email us and a person will answer. We would rather explain a term twice than have you guess at a risk tier.

[email protected]

These definitions are VendorLockbox's plain-English summaries written to help you use the product. They are not legal or regulatory advice, and VendorLockbox is not affiliated with or endorsed by the National Credit Union Administration. Where a definition cites a regulation or supervisory letter, read the source document for the authoritative text. Security overview