
Vendor due diligence is the parallel workstream of vetting the third parties a closing depends on: appraiser, environmental consultant, title company, surveyor, and insurance. Each is a link in the chain, and a weak or slow one paces the whole deal. The checklist confirms qualification, independence, and turnaround.
Two different things are called vendor diligence
The phrase covers two distinct workstreams, and conflating them causes teams to do one and think they did both.
Deal-level vendor diligence is vetting the third parties a specific closing depends on: the appraiser, the environmental consultant, the surveyor, the title company, the insurance broker. It happens per deal, on the deal's clock, and a weak link here shows up as a report you cannot rely on.
Institutional third-party risk management is the program-level discipline your regulator examines: how you select, contract with, monitor, and terminate the third parties your institution relies on, including the software holding your loan files. The federal banking agencies issued interagency guidance on third-party relationships in June 2023, and the OCC's companion bulletin frames the lifecycle expectations. This guide covers the deal level first, then where the two meet.
The deal-level vendors, and what to confirm
Each vendor in a closing is a link in a chain of reliance, and each one has one or two things that actually matter:
| Vendor | What to confirm | The failure it prevents |
|---|---|---|
| Appraiser | State certification, competency for the property type and market, and independence from the transaction | A report the credit file cannot rely on, or an independence finding at exam |
| Environmental consultant | Qualifications to the ASTM E1527-21 environmental professional definition, E&O coverage, scope in writing | A Phase I that does not support the liability protections it was ordered for |
| Surveyor | Licensure in the state, ALTA and NSPS experience, and agreement on the Table A items before work starts | A survey the title company will not insure to |
| Title company | Underwriter financial strength, state capability, closing protection letter, and endorsement availability | Discovering at the table that a required endorsement is not issuable |
| Insurance broker | Ability to produce the exact wording the loan agreement requires, on the required forms | The final-week certificate that exists but does not conform |
Independence is the one that gets you examined
Appraiser independence is where deal-level vendor selection collides with regulation. The rules exist because the incentive to influence a valuation is structural, not hypothetical: production staff want deals to clear, and the appraisal is what decides whether they do.
The operational requirements are consistent across the agencies: the appraisal function is independent of loan production, the appraiser is selected and engaged by someone outside production, communication with the appraiser cannot suggest a target value, and the appraisal receives an independent review before the credit decision. The interagency appraisal and evaluation guidelines set out the expectations, and 12 CFR Part 34 carries the OCC's real estate lending and appraisal requirements. Federally regulated transactions above the half-million-dollar commercial threshold the agencies set in 2018 need an appraisal that satisfies these rules.
The file has to prove it, not just assert it. The engagement letter showing who ordered the appraisal, the review documented and dated before the approval, and the communication record are the evidence. This is precisely where a closing record with actors and timestamps stops being a convenience.
Turnaround is a selection criterion, not a hope
Third-party reports gate the front of every close, so a vendor's realistic turnaround is a credit-process variable. Vet it like one: ask for actual recent turnaround on comparable assignments rather than a marketing number, confirm capacity in the specific market, and put the promised date in the engagement letter.
Then track it. Every ordered report is a checklist line with the order date, the promised date, and the reviewer named, so a vendor who is quietly late is visible in week two rather than week six. Vendors who are consistently late are a portfolio problem masquerading as a series of unlucky deals, and you only see the pattern if you kept the dates.
Where deal vendors meet third-party risk management
The two workstreams converge in the file. At the deal level you need the engagement letter, the qualifications, and the independence evidence. At the program level your examiner wants to see that vendor selection, monitoring, and termination follow a defined process, proportionate to the risk each relationship carries.
The highest-risk third party in a modern closing operation is often the one nobody lists as a vendor: the platform holding the loan files. Treat it like the rest, because your examiner will. Get the provider's SOC 2 report into the vendor file before anyone asks; Prodeal is SOC 2 audited annually and its Type II report is available to customers. Confirm the export path, since records you cannot extract independently are records you do not fully control. And read the interagency guidance's lifecycle framing against your own practice rather than assuming a procurement form covers it.
Questions lenders ask
- What is on a vendor due diligence checklist for a closing?
- Per vendor: appraiser (certification, competency, independence from production), environmental consultant (ASTM E1527-21 environmental professional qualifications, E&O, written scope), surveyor (licensure, ALTA/NSPS experience, agreed Table A items), title company (underwriter strength, closing protection letter, endorsement availability), and insurance broker (ability to produce the exact required wording).
- What are the appraiser independence requirements?
- The appraisal function must be independent of loan production: engagement by someone outside production, no communication suggesting a target value, and an independent review before the credit decision. The interagency appraisal and evaluation guidelines set the expectations and 12 CFR Part 34 carries the OCC's requirements. The file has to prove it with the engagement letter and a dated review.
- What is the difference between deal vendor diligence and third-party risk management?
- Deal-level diligence vets the vendors a specific closing relies on, on the deal's clock. Third-party risk management is the program-level lifecycle your regulator examines: selection, contracting, monitoring, and termination. The federal agencies' June 2023 interagency guidance frames the latter.
- How should vendor turnaround be vetted?
- As a credit-process variable, not a hope. Ask for actual recent turnaround on comparable assignments, confirm capacity in that specific market, put the promised date in the engagement letter, and track order date, promised date, and reviewer on the checklist so chronic lateness is visible as a pattern.
- Is our data room a vendor for examination purposes?
- Usually yes, and often the highest-risk one, since it holds the loan files. Keep the provider's SOC 2 report in the vendor file ahead of any request and confirm you can export your own records independently. Prodeal is SOC 2 audited annually with its Type II report available to customers.
Sources and further reading
- Interagency Guidance on Third-Party Relationships: Risk Management (June 2023)
- OCC Bulletin 2023-17, Third-Party Relationships: Interagency Guidance
- Interagency Appraisal and Evaluation Guidelines (December 2010)
- 12 CFR Part 34, real estate lending and appraisals (eCFR)
- ASTM E1527-21, the current Phase I Environmental Site Assessment standard