Skip to main content
For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
Coverbase is built for regulated third-party risk programs, and a large share of its customers are banks, credit unions, and fintechs supervised by the federal banking agencies. This page maps the platform to the guidance those examiners actually cite, stage by stage.
This is an alignment map, not a legal opinion or a certification. Coverbase is a tool your program runs on; the program remains yours, and so does the responsibility. Nothing here transfers a supervisory obligation from your institution to Coverbase.

Interagency Guidance on Third-Party Relationships (2023)

The Board of Governors of the Federal Reserve System, the OCC and the FDIC issued the Interagency Guidance on Third-Party Relationships: Risk Management in June 2023, replacing the agencies’ separate guidance (including FRB SR 13-19 / 13-21, OCC Bulletin 2013-29, and FDIC FIL-44-2008) with one framework built around the third-party relationship life cycle. Coverbase ships the guidance as a control set as well as implementing it as a workflow. The Control Set library carries Interagency Guidance on Risk Management (Full) at 156 controls across 12 sections, and a (Lite) variant at 44 controls for lower-criticality relationships. Both can be forked into a control set of your own and edited freely.

The life cycle, stage by stage

Planning

Coverbase’s intake captures the business case, the data the third party will touch, the business line, the activity, and whether it supports a critical activity, before any diligence starts. An inherent risk questionnaire scores the relationship and drives what depth of diligence follows, so the level of effort is risk-based rather than uniform. Concentration and fourth-party exposure are recorded as relationships and visible at planning time.
Assessments run against the control sets you select, with evidence collected from the third party, from its own published attestations, and from independent sources.The guidance’s named diligence areas each have a home in the platform: strategies and goals, legal and regulatory compliance, financial condition (Financial Health Score with a confidence tier that says what the number rests on), business experience, qualifications and backgrounds of principals (People Intelligence, corporate registrations, and sanctions and PEP screening of the entity, its officers and its beneficial owners), risk management, information security (Security Intelligence and evidence-backed control evaluation), management of information systems, operational resilience, incident reporting and management, physical security, human resource management, reliance on subcontractors (nth-party relationships), insurance coverage, and contractual arrangements (Contract Guardian).
Contract Guardian holds your standard as a clause playbook with tiered acceptable language, then reads the third party’s paper against it. The guidance’s contract provisions map directly onto reference clauses: nature and scope, performance measures and benchmarks, responsibilities for providing and receiving information, the right to audit and to require remediation, responsibility for compliance with applicable law, cost and compensation, ownership and licensing, confidentiality and integrity, operational resilience and business continuity, indemnification, insurance, dispute resolution, limits on liability, default and termination, customer complaints, subcontracting, foreign-based third parties, and regulatory supervision. Missing provisions are reported as missing, not silently passed.
Supplier Radar monitors third parties continuously against breach, sanctions, enforcement, financial-distress, ownership-change and adverse-media signals, and raises a signal against the vendors your organization is actually exposed to. Scheduled reassessment runs on a cadence you set by tier. Contract dates and notice periods drive their own reminders. Findings and remediation commitments are tracked to closure with evidence, and evidence that goes stale is re-requested rather than assumed to still hold.
Offboarding is a lifecycle stage with its own workflow: a termination assessment scoped to data return, access revocation and exit obligations extracted from the contract; a structured offboarding questionnaire covering destruction certification and access termination; document archival with retention metadata; and events fired to your IAM, procurement and finance systems so the internal cleanup happens too. See End-to-end workflows.

Governance, oversight and accountability

The guidance devotes as much attention to how the board and senior management oversee the program as to the life cycle itself. Coverbase supports that side directly.

Interagency Guidelines Establishing Information Security Standards

The information security standards issued under sections 501(b) and 505(b) of the Gramm-Leach-Bliley Act appear as Appendix D-2 to Regulation H for state member banks (12 CFR part 208), and in the equivalent appendices for the other agencies (12 CFR part 30 appendix B for national banks, 12 CFR part 364 appendix B for state non-member banks). Section III.D of the Guidelines places specific obligations on an institution that uses a service provider. The GLBA Safeguards Rule (16 CFR part 313) control set is in the library at 20 controls, alongside the banking-agency framing above.

Other frameworks in the library

The full library is 68 templates spanning 4,337 curated controls, including SOC 2, ISO 27001, NIST CSF and 800-53, PCI DSS, HIPAA, and the AI-governance frameworks. See the Control Set library.

Incident notification

Institutions supervised by the federal banking agencies are subject to a 36-hour notification requirement for notification incidents (12 CFR 53 for national banks and federal savings associations, 12 CFR 225 subpart N for Board-supervised institutions, and 12 CFR 304 subpart C for FDIC-supervised institutions), and the same rules require a bank service provider to notify each affected banking-organization customer as soon as possible when a computer-security incident has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, covered services for four or more hours. Coverbase supports both sides of that:
  • As your service provider, Coverbase’s incident-response process and customer-notification commitments are set out in Contract terms and exit, and the specific notification window applicable to your institution is agreed in your contract.
  • As your tooling, Coverbase records each third party’s own contractual notification window as a tracked obligation, so an incident at a fourth party lands against the clause that governs it, and a third party whose contract lacks a notification clause is flagged as missing it rather than assumed compliant.

Control Set library

Every packaged framework, its control count, and its official source.

Contract terms and exit

Incident notification, data return and destruction, renewal and notice.

Evidence packaging

Producing the complete due-diligence file for one third party.

Audit trails

The defensible record behind every decision.