third-party-risk-summaries
Installation
SKILL.md
Third-Party Risk Assessment Summaries
Overview
Generate comprehensive third-party risk assessment summaries aligned with OCC Bulletin 2023-17 (Third-Party Relationships: Risk Management Guidance), Federal Reserve SR 13-19, and FFIEC IT Examination Handbook. This skill supports the full third-party risk management lifecycle: planning, due diligence, contract negotiation support, ongoing monitoring, and termination assessment.
When to Use
- Conducting initial due diligence on prospective third-party vendors
- Preparing periodic risk assessments for existing third-party relationships
- Evaluating whether a third-party relationship is critical per OCC 2023-17 criteria
- Analyzing concentration risk across the third-party portfolio
- Preparing board or committee reporting on third-party risk exposure
- Responding to regulatory findings on third-party risk management practices
- Assessing fourth-party (subcontractor) risk exposure through critical vendors