Skip to content

Platform · Third-party risk management

Vendor and partner oversight built on the guidance your examiner uses.

Third-party risk management follows each vendor and fintech partner through the life stages set out in the 2023 interagency guidance on third-party relationships, from planning to termination. Diligence runs from a 34-question bank, SOC 2 reports are reviewed in a seven-step memo, and every relationship shows when its next review is due.

The problem it removes

A vendor file that proves you asked, not that you looked

  • Diligence questionnaires come back, get filed, and nobody records what the answers meant for the risk.
  • A SOC 2 report sits in a folder unread, with its exceptions and its carve-outs never checked against how you use the vendor.
  • When a relationship ends, there's no plan for your data, your customers or the handover, and no record that anyone thought about it.

What you see

Each relationship, its stage, its exposure and its next review

Every vendor and partner shows where it sits in the relationship life cycle, which enforcement categories its service exposes you to, what the diligence and SOC 2 review found, and whether its review is current or due.

Third-party register · Critical and high relationshipsSample data
Third partyStageExposureReview
Ledgerline Card ProcessingOngoing monitoringData security, consumer disclosuresCurrent next 2027-02
Brightwater Bank (sponsor)Ongoing monitoringBSA/AML, sanctionsDue 2026-09-30
Parcel KYC ServicesDue diligenceBSA/AML, fair lendingIn progress 21 of 34 answered
Oldfield CollectionsTerminationDebt collection, complaintsExit termination pack open
SOC 2 review, LedgerlineResult
Step 3: exceptions noted by the auditor2 exceptions, both in access review
Step 4: complementary controls you must run3 listed, 1 not yet evidenced

Illustrative example with invented companies. Each review keeps the answers and the memo behind it.

How it works

Plan, diligence, review, oversee, exit

  1. Plan. Each relationship starts at the planning stage and is tagged with the enforcement categories its service exposes you to.
  2. Diligence. The 34-question bank is sent and answered, and each answer is kept against the question it answers.
  3. Review the SOC 2 report. The report is worked through seven written checks: whether the report type fits, scope, the opinion and any exceptions, the controls you're expected to run yourself, the subservice organisations it carves out, how its criteria map to your oversight controls, and any bridge letter. A practitioner reviews the memo and signs off the conclusion.
  4. Oversee. Each relationship carries a review cadence and shows when its next review is due.
  5. Exit. Moving a relationship to termination requires a recorded reason. A termination pack then lists seventeen wind-down items, from the contract's default and termination terms to records access and off-boarding, each cited to the part of the guidance that requires it and each open until evidence closes it.

Guardrails

What it will never do

  • It doesn't approve a vendor on its own. The decision and the sign-off stay with your team.

Where it shows up

The work this part does for you

Plain English

What this is, and how anyone does it

Reference articles from our library, cited to the published rules and standards. No sales copy.

Connected parts

What it works with

See the whole platform

Talk to a practitioner

Book a 15-minute chat with our founder.

A real conversation with a senior compliance leader, to see if there's a fit. Not a sales call, not a demo, no pressure.