A CVA is reviewing an organization's vendor due diligence process. Which regulatory framework is most directly relevant to third-party risk management for U.S. banks?
-
A
OCC Bulletin 2013-29 on Third-Party Relationships
-
B
NIST SP 800-53 Revision 5
-
C
COSO ERM Framework 2017
-
D
ISO 9001:2015