Vendor Management

Due diligence, written agreements, access requirements, performance monitoring, and audits for court researchers, data providers, and other vendors.

Find a section

Home / For CRAs / Vendor Management

Most CRAs rely on outside parties for part of the work they deliver. Court researchers, international partners, data providers, drug testing networks, and other vendors may all contribute information that ultimately reaches the client as part of the CRA’s report.

Vendor management establishes who those parties are, what standards apply to their work, how they handle consumer information, and how their performance is reviewed.

Vendor Due Diligence and Credentialing

Before engaging a vendor, a CRA should verify that the vendor is a legitimate business capable of performing the work to the required standard.

Under FCRA § 1681e(b), a CRA must follow reasonable procedures to assure maximum possible accuracy of the information it reports. Work obtained through a vendor becomes part of the CRA’s report and should be subject to appropriate quality and oversight procedures.

  • Verify the business. Confirm the legal business name, address, registration status, and ownership through independent sources.
  • Determine the vendor’s role. Some vendors meet the definition of a consumer reporting agency under FCRA § 1681a(f) and carry their own obligations. Understand whether the vendor is acting as another CRA, a court researcher, a data provider, a reseller, or another type of service provider. Different relationships may carry different responsibilities.
  • Confirm coverage. Identify the specific jurisdictions, courts, and record types the vendor searches, along with how frequently any data it supplies is updated.
  • Ask how the work is performed. Determine whether the vendor searches records directly, subcontracts the work, or resells data obtained from another source.
  • Review the vendor’s compliance program. Ask about training, quality control procedures, insurance coverage, and any accreditation the vendor holds.
  • Check references and history. Speak with other CRAs that use the vendor, and review any regulatory actions or litigation involving the vendor.

Good Practice: Consider placing test orders before a new research or data vendor goes live. Orders that can be independently checked can help confirm the vendor’s coverage, turnaround, reporting format, and overall quality.

See the Court Researchers and Data Providers directories for wholesale vendors serving CRAs.

Written Vendor Agreements

A written agreement establishes what the vendor will provide, the standards that apply to the work, and the responsibilities of each party.

A vendor agreement should address, as applicable:

  • Services provided and jurisdictions covered
  • Turnaround expectations and how they are measured
  • Accuracy and quality standards
  • Source requirements, including whether records must be obtained directly from the court
  • Restrictions on subcontracting
  • Permitted use of consumer information supplied by the CRA
  • Data security, encryption, and transmission requirements
  • Breach notification obligations and timeframes
  • Return or destruction of data at termination
  • Audit and inspection rights
  • Insurance requirements
  • Indemnification and limitation of liability
  • Suspension and termination

Subcontracting deserves particular attention. If a vendor uses other researchers or providers to complete work, the CRA should understand when subcontracting is permitted, who may receive consumer information, and whether the same quality and security requirements apply.

Access and Data Handling Requirements

Vendors may receive sensitive consumer information in order to perform their work. CRAs should establish reasonable controls over what information is shared, how it is transmitted, and who may access it.

  • Limit what is sent. Provide only the identifying information the vendor needs to complete the search.
  • Use individual credentials. Each vendor user with access to CRA systems should have a unique login rather than a shared account.
  • Require secure transmission. Consumer information should be sent and received through encrypted channels rather than ordinary email.
  • Define retention and disposal. Specify how long the vendor may retain consumer information and how it must be destroyed. Under the FTC Disposal Rule at 16 CFR Part 682, reasonable measures include exercising due diligence in selecting a contractor engaged to dispose of consumer information.
  • Consider international data requirements. When consumer information is transferred outside the United States, determine whether additional contractual, privacy, security, or legal requirements may apply.
  • Remove access promptly. Vendor credentials should be disabled when the relationship ends or when an individual vendor user no longer requires access.

When a CRA obtains a consumer report from another CRA and resells it to an end user, FCRA § 1681e(e) applies. The CRA must disclose to the originating CRA the identity of the end user and each permissible purpose, maintain procedures ensuring reports are resold only for a permissible purpose, and verify those certifications before reselling.

Performance Monitoring

Vendor performance should be monitored against established expectations for accuracy, coverage, turnaround, and service.

  • Track turnaround by vendor and jurisdiction. An average calculated across all vendors will hide the vendor or jurisdiction that is consistently slow.
  • Track error rates. Record errors identified in internal review, in quality control sampling, and through consumer disputes, and attribute each one to its source.
  • Watch for coverage changes. Confirm that vendors continue to provide the jurisdictions and record sources represented in their coverage.
  • Monitor communication and escalation. Note how the vendor responds to questions, corrections, and time sensitive requests.
  • Review results with the vendor. Share performance findings so the vendor can address them, and record what was discussed and agreed.
  • Address repeated problems. Persistent accuracy, coverage, turnaround, or security concerns should result in additional oversight, corrective action, or reconsideration of the relationship.

See Quality Control Standards for sampling vendor work alongside internal work.

Security and Quality Audits

Periodic audits help confirm that a vendor continues to meet the standards established during onboarding and in the vendor agreement.

  • Set an audit schedule. Determine how often each vendor is reviewed, based on the volume and sensitivity of the work performed.
  • Sample vendor results against the source. Where the jurisdiction allows a direct check, comparing vendor results to the court record is the most reliable way to confirm the search was actually performed.
  • Review security practices. Examine how the vendor stores consumer information, who within the vendor has access, and what controls apply.
  • Confirm insurance remains in force. Request a current certificate rather than relying on the one provided at onboarding.
  • Review subcontractor arrangements. Confirm that the vendor’s subcontractors are the ones disclosed and that they meet the same requirements.
  • Document each audit. Record what was examined, what was found, and what corrective action was requested.

Good Practice: Include vendors with strong performance in the audit schedule, not only vendors that have already produced a problem. Routine audits help confirm that established standards continue to be followed.

Records to Keep on File

Vendor files should document both the decision to engage the vendor and the CRA’s ongoing oversight of the relationship.

Maintain, as applicable:

  • Vendor due diligence and credentialing documentation
  • Executed vendor agreement and amendments
  • Disclosed subcontractors and the jurisdictions they cover
  • Current certificates of insurance
  • Vendor users granted access, with dates granted and removed
  • Performance data, including turnaround and error rates
  • Audits performed, findings, and corrective actions requested
  • Correspondence regarding performance or compliance concerns
  • Termination documentation, including confirmation that data was returned or destroyed

Documentation should be sufficient to show why the vendor was selected, what standards apply to its work, and how those standards have been verified since.

Vendors that were evaluated and not engaged should also be documented. Maintaining those records can help demonstrate that vendor due diligence standards are being applied consistently.

See Records & Documentation for retention schedules, secure storage, and destruction.

Worth Knowing: Work performed by a vendor may ultimately become part of the CRA’s report. Vendor management helps ensure that work obtained from outside providers is subject to appropriate standards for quality, security, and oversight.

Download the Vendor Oversight Checklist

What to verify before engaging a vendor, what the agreement should cover, and what to audit.

Download PDF