Written byMichael Dean AufmuthAgency Principal, Elite FI Partners

Operational review byEmilia AufmuthAgency Principal, Elite FI Partners

Direct answer

Evaluate a provider as an ongoing third-party relationship, not merely a product catalog. Review strategic fit, financial capacity, product terms, compliance support, security, operations, member service, reporting, contract protections, and exit readiness.

Executive takeaway

A polished demonstration is not due diligence. The credit union needs evidence it can verify, obligations it can enforce, performance it can monitor, and a practical way to protect members if the relationship changes or ends.

Start with strategic and member fit

  • Does the relationship support the credit union’s mission, plan, risk tolerance, and operational capacity?
  • Which member needs and eligible loan channels does it address?
  • How does the provider make money, and could incentives conflict with member outcomes?
  • What people, systems, reconciliation, and oversight will the relationship require?

Request evidence—not assurances

  • Ownership, leadership, affiliates, subcontractors, financial condition, insurance, and continuity plans
  • Licensing or authorization, litigation, complaints, enforcement history, and client references
  • Product contracts, forms, pricing, eligibility, exclusions, claims, cancellations, and refunds
  • Security, privacy, access controls, testing, incident response, and data disposition
  • Implementation, integrations, service levels, reporting, audit access, and reconciliation
  • Transition assistance, termination, member servicing, data return, and exit planning

Use a decision scorecard

For each dimension, record the evidence reviewed, finding, risk, mitigating control, owner, and open condition. Weight member impact, legal or compliance exposure, operational criticality, and data sensitivity more heavily than feature count or presentation quality.

  • Meets requirement with verified evidence
  • Meets with a documented condition or compensating control
  • Open issue requiring resolution before approval
  • Does not meet requirement
  • Not applicable, with rationale

Make the contract support oversight

  • Clear scope, responsibilities, performance standards, and remedies
  • Audit, reporting, record-access, and regulatory-cooperation rights
  • Security, privacy, incident-notification, subcontractor, and data-return terms
  • Product-change, pricing-change, complaint, cancellation, refund, and claims obligations
  • Business-continuity, transition, termination, and member-servicing provisions
  • Independent legal review representing the credit union’s interests

Plan monitoring before signing

  • Name owners and reporting cadence.
  • Set thresholds for complaints, errors, unresolved claims, refunds, incidents, and control deterioration.
  • Verify provider reports against credit union records where practicable.
  • Reassess after material changes and on a risk-based schedule.
  • Keep a documented escalation and exit decision path.

Official sources and further reading

These primary sources inform the program principles in this guide. They do not replace advice from the credit union’s own legal and compliance professionals.