third-party-risk-summaries

Generate third-party risk assessment summaries aligned with OCC 2023-17 and FFIEC guidance.

1|1|Updated Feb 19, 2026
One-click install
npx skills add https://github.com/GoldenZero/skills --skill third-party-risk-summaries-goldenzero
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: third-party-risk-summaries
Source: https://github.com/GoldenZero/skills/tree/main/skills/third-party-risk-summaries
Command: npx skills add https://github.com/GoldenZero/skills --skill third-party-risk-summaries-goldenzero

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes assets (resource) and references (resource) components.

What problem does it solve?

This Skill streamlines the complex process of assessing and summarizing vendor and third-party risk for financial institutions, ensuring compliance with regulatory guidance and enabling informed decision-making.

Core Features & Use Cases

  • Comprehensive Risk Assessment: Evaluates vendors across financial, operational, security, compliance, and reputational domains.
  • Regulatory Alignment: Specifically designed to meet OCC 2023-17 and FFIEC guidance.
  • Use Case: A bank needs to conduct its annual risk assessment for a critical software vendor. This Skill can process the vendor's SOC report, contract terms, and performance data to generate a concise summary report highlighting key risks and recommended actions for the risk committee.

Quick Start

Use the third-party-risk-summaries skill to generate a risk assessment summary for 'CoreBanking Solutions LLC'.

Frequently Asked Questions about third-party-risk-summaries

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a third-party risk assessment summary aligned with OCC 2023-17?

Generate a third-party risk assessment summary by inputting structured vendor profiles, due diligence materials, and performance metrics. The Skill evaluates vendor criticality, financial condition, and operational resilience to produce reports aligned with OCC 2023-17 and FFIEC guidance.

What vendor data do I need to conduct due diligence and ongoing monitoring for financial services compliance?

Conducting due diligence and ongoing monitoring requires structured input data on vendor profiles, due diligence materials, and performance metrics. This data enables evaluation across financial, operational, security, compliance, and reputational domains for financial services compliance.

Can I use vendor SOC reports and contract terms to evaluate operational resilience and compliance?

Yes, you can use vendor SOC reports and contract terms to evaluate operational resilience and compliance. The Skill processes these due diligence materials alongside performance data to generate a concise summary highlighting key risks and actionable recommendations.

What's the best way to assess vendor criticality and information security for a bank's risk committee?

Assess vendor criticality and information security by processing vendor profiles and performance metrics through the Skill. It generates detailed risk reports with actionable recommendations tailored for a bank's risk committee, covering financial condition and contractual terms.

Does this third-party risk management approach support portfolio risk analysis across multiple vendors?

Yes, this third-party risk management approach supports portfolio risk analysis across multiple vendors. It evaluates vendor criticality, financial condition, information security, operational resilience, and compliance to produce detailed risk reports for comprehensive portfolio oversight.

When do I need OCC 2023-17 compliant vendor assessment reports for critical software providers?

You need OCC 2023-17 compliant vendor assessment reports for critical software providers during annual risk assessments and ongoing monitoring. The Skill aligns with FFIEC guidance to evaluate operational resilience, information security, and compliance for financial institutions.