Vendor security reviews · Fintech & financial services
Vendor Security Review & Questionnaire Support for Credit Unions & Caisses Populaires
Vendor security review for a credit union starts from an uncomfortable fact: your core, payments and statement processing run on a small set of member-owned shared providers you cannot realistically replace. We assess what assurance you actually hold over Celero, Central 1 and similar CUSOs, document the concentration risk your regulator expects to see on file, and review the smaller vendors, statement printers, collections agencies, where a review can still change the outcome. Work usually starts ahead of a supervisory review or a bonding renewal.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
The vendor relationships a credit union has to account for
Some vendors can be swapped after a bad review; others are structural to how the sector operates, and the review approach differs for each.
The shared core provider
Celero's Fiserv DNA core, or an equivalent CUSO arrangement, sits underneath member accounts, deposits and transaction history, and the credit union cannot walk away from it the way it could a smaller SaaS tool.
Central payments infrastructure
Central 1 handles payments processing and settlement, including Real-Time Rail preparation, for much of the sector, making it a single point most member-owned institutions depend on simultaneously.
Digital banking channel providers
CGI Digital Banking and similar member-channel platforms carry authentication and transaction data for online and mobile banking, and their security posture is effectively the credit union's own front door.
Statement and reporting vendors
Outsourced statement printing and reporting tools handle bulk member data on a recurring schedule, and file-transfer weaknesses in this category have already caused sector-relevant breaches elsewhere.
Collections agencies and dealer partners
Third parties handling delinquent accounts or wealth and insurance referrals receive member financial detail outside the core system, and each one needs its own documented review.
Regulatory map
Why concentration risk is a documented regulatory expectation
FSRA and OSFI both frame third-party risk as something the credit union owns, even for a vendor it has no realistic alternative to.
FSRA's third-party lens
Ontario's IT risk guidance extends to third parties the credit union depends on, meaning a supervisory review can ask what oversight exists over Celero or Central 1 even though FSRA does not regulate those providers directly.
OSFI's B-10 for federally continued credit unions
A credit union that continues federally inherits B-10's third-party risk-management expectations, which formalize exactly the kind of concentration documentation provincial guidance only implies today.
PIPEDA accountability for outsourced processing
PIPEDA keeps the credit union accountable for member data even when a vendor is processing it, so a statement printer's or collections agency's security posture is legally still the credit union's problem.
Law 25 obligations that follow a caisse's data
Where a caisse shares member data with a vendor, Law 25's assessment duties travel with that data, particularly where the vendor or its infrastructure sits outside Québec.
What goes wrong
What unmanaged vendor concentration exposes
The sector's own incident history shows what happens when one shared provider has a bad day.
One vendor incident hitting many institutions at once
Because a small number of centrals and CUSOs serve much of the sector, a single provider's outage or breach can create a material IT risk incident for dozens of credit unions simultaneously, each with its own notification duty to file.
File-transfer and statement-vendor compromise
MOVEit-style breaches of transfer tooling, including one deployment that exposed roughly 100,000 Nova Scotians, map directly onto the outsourced statement-printing and reporting chains credit unions rely on every cycle.
Assurance gaps nobody has tested
Without a documented review, the credit union often does not know whether its shared providers hold the certifications or controls its own policy claims to require, a gap that only surfaces when an examiner asks for the file.
Contract terms that never got negotiated
Long-standing vendor relationships, especially with a central the credit union is a member of, sometimes predate any formal security review, leaving breach-notification and audit-access terms weaker than a newer relationship would accept.
Our vendor security reviews for credit unions & caisses populaires
What the vendor review covers, tier by tier
The review is built to match effort to what each vendor relationship actually allows, deep assessment where you have leverage, documented concentration risk where you don't.

High-level gap review
An assessment of how your current vendor oversight compares to what FSRA, BCFSA or CUDGC guidance and your own outsourcing policy expect, identifying the tiers where documentation is thin.
Concentration risk documentation
A clear written record of dependence on Celero, Central 1 or equivalent shared providers, the compensating controls the credit union holds, and what would happen operationally if that provider had an incident.
Evidence and documentation guidance
Help organizing what security evidence, SOC 2 reports, certifications, questionnaire responses, your vendors have already provided, and identifying where the file is missing something an examiner will ask for.
Control consideration support
Guidance on which controls matter most for each vendor tier, so a statement printer and a core provider are not assessed against the identical checklist.
Internal review and ongoing support
A second look at draft assessments before they go to the board or examiner, plus light-touch support keeping the vendor file current as relationships and contracts change.
How the engagement runs
How the review runs across your vendor list
The sequence starts with mapping dependence, because effort has to go where the risk is structural, not where a checklist happens to point first.
Step 1
Build the vendor inventory and tiers
Every provider touching member data or systems is listed and tiered, core and payments providers at the top, statement and referral vendors below, based on data sensitivity and how replaceable each one actually is.
Step 2
Assess the critical tier and document concentration
Core and payments relationships get a documented concentration-risk assessment rather than a conventional swap-the-vendor recommendation, since replacing a member-owned central is rarely realistic.
Step 3
Review the replaceable tier
Statement printers, collections agencies and referral partners get fuller due diligence, since these relationships can reasonably be changed if the review finds a real gap.
Step 4
Report and keep it current
Findings go to the board or risk committee as decisions, accept, request contract changes, or plan a vendor change, and the file is revisited on a set cycle.
What it costs
What determines vendor review cost for a credit union
Scope drivers include how many vendors are in play, how many sit in the critical, hard-to-replace tier versus the replaceable tier, and how much contract and evidence review is needed across statement, collections and referral relationships.
Vendor and third-party compliance oversight is also included inside a Virtual Privacy Office retainer for credit unions that want this reviewed on an ongoing basis rather than as a one-time project. Send us your vendor list and we will scope a tailored quote.
Credit Unions & Caisses Populaires: Vendor security reviews questions, answered
These vendors sit in the tier where a full due-diligence review makes sense because the relationship can reasonably be changed if it fails. We look at what member data they receive, how it's transmitted and stored, what security evidence they can provide, and what the contract says about breach notification and data return, then flag any gap as a genuine decision point rather than an accepted risk.
Generally a written statement of which critical functions depend on a single or small set of providers, what assurance the credit union holds over each, and what the institution would do operationally if that provider failed or was breached. FSRA's third-party lens and OSFI's B-10 for federally continued credit unions both expect this kind of documentation to exist before an examiner asks for it, not to be assembled the week the request lands.
Sometimes, though leverage is real: the central serves many member institutions and cannot customize terms for each one individually. What usually works is raising specific, well-documented requests, an incident-notification commitment, clarity on audit access, through your governance relationship with the central rather than treating it like a standard vendor negotiation. Our review gives you the specific asks worth raising.
Lower priority, but not zero. A vendor with no access to member data or credit union systems carries limited privacy risk, though it may still carry operational risk if the credit union depends on it. We generally tier vendors by data access and system access together, so a facilities contractor with no data access sits well below a statement printer handling member account numbers.
Vendor security review looks outward, at the providers and partners the credit union depends on, while ISO 27001 readiness looks inward, at the credit union's own management system and controls. Findings from a vendor review often feed into the supplier-relationship controls an ISO 27001 program requires, but they are separate engagements addressing different sides of the same risk picture.
More for credit unions & caisses populaires
Other services for this niche
About this service
Answers & guides
- How do we prepare for a customer security questionnaire?
- Do you need a TRA before moving sensitive data to a new cloud provider?
- How does a startup pass an enterprise vendor security review?
- Building a Third-Party Vendor Risk Assessment Program That Scales
- Before You Move Sensitive Data to a New Cloud: The Case for a TRA
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.