Back to Blog

Contract Checklist

By Finosec

February 10, 2022

Get notified on new insights from Finosec now!

Be the first to know about new Finosec blogs to grow your knowledge of the cybersecurity governance industry today!

Contracts are typically dense, highly detailed documents that can be hard to navigate. After wading through strikingly specific legal verbiage, it can be difficult to ascertain whether or not the contracts are accomplishing everything they claim to be. As a result, financial institutions may wonder how they can feel confident in signing such a document. Systematically and thoroughly reading and reviewing the contract before agreeing to its terms are vital, but knowing how to do that well can be tough. Prior to conducting a review, you’ll need to understand the expectations of the relationship: which products/services were selected, any prerequisites or additional costs to implement, term(s) of the agreement, and the stakeholders. Conducting a contract review is vital to reduce overall risk, ensure that the provisions are correct, and provide both sides with the opportunity to fully understand what they are agreeing to before the final signing decision is made. Regulatory requirements mandate that each institution is responsible for reviewing and understanding vendor contracts and/or agreements – but that is easier said than done.

Finosec has created a checklist that will assist you and your institution as you examine each contract so you can feel confident in signing such an agreement. For example, every contract must contain these main elements: an offer, acceptance, and consideration. Furthermore, please be sure that whoever signs a contract has the authority to do so on behalf of the institution. Whether you have contract experience or not, this checklist will help guide you through the review process. While this does not replace a legal review, it can be a great jumping off point to further conversation and a deeper understanding of the contract in question. 

If you would like to download and utilize this contract checklist, as well as connect with an ever growing community of like-minded industry leaders, we hope you’ll join Finosec Academy. Sign up – Log In- Learn.

More from Finosec

The Critical Link Between Third-Party Risk Management (TPRM) and Access Management

The Critical Link Between Third-Party Risk Management (TPRM) and Access Management

As highlighted in a recent article from the Federal Reserve, managing third-party relationships and the access associated with those relationships is a critical component of Third-Party Risk Management (TPRM). The associated access third party vendors have to banking systems is known as Access Management and is foundational for mitigating risks associated with third-party relationships. Access Management may be easy to overlook because it does not always reside with the same person or team as TPRM; making it difficult to provide critical oversight.

With increased regulatory focus, how should institutions be thinking of Access Management? Here are five steps your institution can take today to strengthen your third-party governance.

The Critical Foundation of Managing Access to Banking Systems

The Critical Foundation of Managing Access to Banking Systems

Managing access to banking systems has become increasingly complex as financial institutions navigate legacy reporting systems, API access, and cloud solutions. These challenges, along with the risks posed by unmanaged systems, emphasize the need for maintaining a...

Talk To An Expert Now
Talk To An Expert Now 770.268.2765