Platform · Third-party risk management
Vendor and partner oversight built on the guidance your examiner uses.
Third-party risk management follows each vendor and fintech partner through the life stages set out in the 2023 interagency guidance on third-party relationships, from planning to termination. Diligence runs from a 34-question bank, SOC 2 reports are reviewed in a seven-step memo, and every relationship shows when its next review is due.
The problem it removes
A vendor file that proves you asked, not that you looked
- Diligence questionnaires come back, get filed, and nobody records what the answers meant for the risk.
- A SOC 2 report sits in a folder unread, with its exceptions and its carve-outs never checked against how you use the vendor.
- When a relationship ends, there's no plan for your data, your customers or the handover, and no record that anyone thought about it.
What you see
Each relationship, its stage, its exposure and its next review
Every vendor and partner shows where it sits in the relationship life cycle, which enforcement categories its service exposes you to, what the diligence and SOC 2 review found, and whether its review is current or due.
| Third party | Stage | Exposure | Review |
|---|---|---|---|
| Ledgerline Card Processing | Ongoing monitoring | Data security, consumer disclosures | Current next 2027-02 |
| Brightwater Bank (sponsor) | Ongoing monitoring | BSA/AML, sanctions | Due 2026-09-30 |
| Parcel KYC Services | Due diligence | BSA/AML, fair lending | In progress 21 of 34 answered |
| Oldfield Collections | Termination | Debt collection, complaints | Exit termination pack open |
| SOC 2 review, Ledgerline | Result |
|---|---|
| Step 3: exceptions noted by the auditor | 2 exceptions, both in access review |
| Step 4: complementary controls you must run | 3 listed, 1 not yet evidenced |
Illustrative example with invented companies. Each review keeps the answers and the memo behind it.
How it works
Plan, diligence, review, oversee, exit
- Plan. Each relationship starts at the planning stage and is tagged with the enforcement categories its service exposes you to.
- Diligence. The 34-question bank is sent and answered, and each answer is kept against the question it answers.
- Review the SOC 2 report. The report is worked through seven written checks: whether the report type fits, scope, the opinion and any exceptions, the controls you're expected to run yourself, the subservice organisations it carves out, how its criteria map to your oversight controls, and any bridge letter. A practitioner reviews the memo and signs off the conclusion.
- Oversee. Each relationship carries a review cadence and shows when its next review is due.
- Exit. Moving a relationship to termination requires a recorded reason. A termination pack then lists seventeen wind-down items, from the contract's default and termination terms to records access and off-boarding, each cited to the part of the guidance that requires it and each open until evidence closes it.
Guardrails
What it will never do
- It doesn't approve a vendor on its own. The decision and the sign-off stay with your team.
Where it shows up
The work this part does for you
Plain English
What this is, and how anyone does it
Reference articles from our library, cited to the published rules and standards. No sales copy.
- Field GuideThe Vendor Risk Categories Every TPRM Program Should CoverThe eight inherent-risk categories a TPRM scoring model should cover, the tier and due-diligence depth each drives, and the separate ISACA threat-category lens a program's controls have to mitigate.
- Field GuideSponsor-Bank Oversight: A CCO's Field GuideWho owns what between a sponsor bank and its fintech partners, where partnerships fail an exam, and how to build oversight that produces evidence instead of binders.
Connected parts
What it works with
Talk to a practitioner
Book a 15-minute chat with our founder.
A real conversation with a senior compliance leader, to see if there's a fit. Not a sales call, not a demo, no pressure.