third-party-risk-summaries

Generate third-party risk assessment summaries aligned with OCC 2023-17 and FFIEC guidance.

6|5|Updated Feb 4, 2026
One-click install
npx skills add https://github.com/writer/skills --skill third-party-risk-summaries-writer
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: third-party-risk-summaries
Source: https://github.com/writer/skills/tree/main/skills/third-party-risk-summaries
Command: npx skills add https://github.com/writer/skills --skill third-party-risk-summaries-writer

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill streamlines the complex process of assessing and summarizing third-party vendor risk for financial institutions, ensuring compliance with stringent regulatory requirements.

Core Features & Use Cases

  • Regulatory Compliance: Generates summaries aligned with OCC 2023-17 and FFIEC guidance.
  • Comprehensive Assessment: Evaluates vendors across criticality, due diligence, risk scoring, contract terms, and ongoing monitoring.
  • Use Case: A bank needs to prepare a quarterly report for its board on the risk exposure of its top 20 critical vendors. This Skill can ingest the raw due diligence data for each vendor and produce a concise, standardized summary highlighting key risks and recommended actions.

Quick Start

Generate a third-party risk assessment summary for 'CoreBanking Solutions LLC' using the provided vendor profile and due diligence materials.

Frequently Asked Questions about third-party-risk-summaries

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a third-party risk assessment summary for bank vendors?

To generate a third-party risk assessment summary, input structured vendor profiles, due diligence documentation, and performance metrics. The Skill processes this data to evaluate criticality, risk scoring, and ongoing monitoring compliance for financial institutions.

Does this vendor risk management process align with OCC 2023-17 and FFIEC guidance?

Yes, the vendor risk management summaries align directly with OCC 2023-17 and FFIEC guidance. It evaluates vendor due diligence, criticality assessments, and contract reviews to ensure regulatory compliance for financial institutions.

What data is required for due diligence and criticality assessment of financial vendors?

Due diligence and criticality assessment requires structured input data covering vendor profiles, performance metrics, due diligence documentation, and regulatory context. This information drives accurate risk scoring and ongoing monitoring analysis.

Can I use this for board-level reporting on critical vendor risk exposure?

Yes, you can use this for board-level reporting on critical vendor risk exposure. It transforms raw due diligence data into concise, standardized summaries highlighting key risks and recommended actions for quarterly board reviews.

What is the best way to evaluate ongoing monitoring and contract terms for vendor risk?

The best way to evaluate ongoing monitoring and contract terms is to input the raw vendor performance metrics and contract documentation. The Skill analyzes these factors to produce a standardized risk summary highlighting recommended actions.

Are there limitations when assessing third-party risk for non-financial institutions?

Assessing third-party risk for non-financial institutions is a limitation, as the summaries are tailored to regulatory frameworks like OCC 2023-17 and FFIEC guidance specifically governing financial institutions.