Written byMichael Dean AufmuthAgency Principal, Elite FI Partners
Operational review byEmilia AufmuthAgency Principal, Elite FI Partners
Evaluate a provider as an ongoing third-party relationship, not merely a product catalog. Review strategic fit, financial capacity, product terms, compliance support, security, operations, member service, reporting, contract protections, and exit readiness.
A polished demonstration is not due diligence. The credit union needs evidence it can verify, obligations it can enforce, performance it can monitor, and a practical way to protect members if the relationship changes or ends.
Start with strategic and member fit
- Does the relationship support the credit union’s mission, plan, risk tolerance, and operational capacity?
- Which member needs and eligible loan channels does it address?
- How does the provider make money, and could incentives conflict with member outcomes?
- What people, systems, reconciliation, and oversight will the relationship require?
Request evidence—not assurances
- Ownership, leadership, affiliates, subcontractors, financial condition, insurance, and continuity plans
- Licensing or authorization, litigation, complaints, enforcement history, and client references
- Product contracts, forms, pricing, eligibility, exclusions, claims, cancellations, and refunds
- Security, privacy, access controls, testing, incident response, and data disposition
- Implementation, integrations, service levels, reporting, audit access, and reconciliation
- Transition assistance, termination, member servicing, data return, and exit planning
Use a decision scorecard
For each dimension, record the evidence reviewed, finding, risk, mitigating control, owner, and open condition. Weight member impact, legal or compliance exposure, operational criticality, and data sensitivity more heavily than feature count or presentation quality.
- Meets requirement with verified evidence
- Meets with a documented condition or compensating control
- Open issue requiring resolution before approval
- Does not meet requirement
- Not applicable, with rationale
Make the contract support oversight
- Clear scope, responsibilities, performance standards, and remedies
- Audit, reporting, record-access, and regulatory-cooperation rights
- Security, privacy, incident-notification, subcontractor, and data-return terms
- Product-change, pricing-change, complaint, cancellation, refund, and claims obligations
- Business-continuity, transition, termination, and member-servicing provisions
- Independent legal review representing the credit union’s interests
Plan monitoring before signing
- Name owners and reporting cadence.
- Set thresholds for complaints, errors, unresolved claims, refunds, incidents, and control deterioration.
- Verify provider reports against credit union records where practicable.
- Reassess after material changes and on a risk-based schedule.
- Keep a documented escalation and exit decision path.
Official sources and further reading
These primary sources inform the program principles in this guide. They do not replace advice from the credit union’s own legal and compliance professionals.