Your risk perimeter extends far beyond your company.
We build and operate third-party risk programs for regulated organizations: an inventory you can trust, tiering that reflects service impact, assessments proportionate to exposure, and monitoring that keeps working after the report is filed.
- Programs designed for hundreds or thousands of vendors
- Assessment depth set by tier, not by habit
- Fourth-party and concentration visibility
- Remediation tracked to validated closure
Where engagements usually begin — and what tends to be true on day one.
- Vendors in the inventory
- Incomplete by 15–30%
- Tiering basis
- Contract value, not service impact
- Evidence location
- Email threads and shared drives
- Reassessment trigger
- A date in a calendar
- Fourth parties recorded
- Rarely
Who you depend on, and who they depend on.
Direct suppliers are the visible layer. The dependencies that cause incidents usually sit one or two levels beyond the contract you signed.
What we deliver.
Engagements combine these depending on where the program is today — a first inventory, a scaling problem, or a regulator asking how the controls are evidenced.
Inventory and tiering
Most programs fail at the inventory. If the population is incomplete or the tier is assigned by whoever raised the purchase order, everything downstream inherits the error.
- Vendor inventory build & reconciliation
- Criticality and impact assessment
- Risk tiering model & scoring
- Critical vendor identification
- Data classification & processing scope
- Intake and onboarding workflow
Due diligence and assessment
Assessment depth set by tier, not by habit. Tier 1 gets architecture, evidence and testing. Low-tier suppliers get a proportionate review and stop consuming the queue.
- Security & resilience assessments
- Questionnaire design and analysis
- Evidence collection & validation
- SOC 2 / ISO report review
- Control effectiveness testing
- Financial and legal risk inputs
Dependency and concentration
Four unrelated vendors can still be a single point of failure. Concentration only becomes visible when the inventory records platform, region and upstream provider.
- Fourth-party and subprocessor mapping
- Concentration by provider & region
- Shared-dependency analysis
- Critical service dependency mapping
- Exit and contingency planning
- Substitutability assessment
Monitoring and lifecycle
Between assessments is where exposure changes. Reassessment should be triggered by an event as often as it is triggered by a date.
- Continuous vendor monitoring
- Certification & report expiry tracking
- Findings and remediation tracking
- Periodic and event-driven reassessment
- Performance and SLA signals
- Offboarding & termination review
From an unreliable list to a defensible program.
- 01
Establish the population
Reconcile procurement, finance, identity and security sources into one inventory. Almost every engagement finds material vendors that were never assessed because they were never recorded.
- 02
Tier against service impact
Criticality is a property of the process the vendor supports, not of the contract value. We define tiering criteria the first line can apply consistently and the second line can defend.
- 03
Assess proportionately
A depth-of-assessment matrix per tier: evidence set, control coverage, testing approach, approval authority and reassessment frequency, all agreed up front.
- 04
Drive findings to closure
Findings rated against defined criteria, assigned to a named owner, tracked to an agreed date, and closed only after the remediation is validated rather than reported.
- 05
Monitor between cycles
Expiring evidence, subprocessor changes, disclosed vulnerabilities, SLA trends and concentration shifts feed the profile continuously, and trigger reassessment where they are material.
Bring your vendor population into one view.
We can start with an assessment of the current program, a build of the inventory and tiering model, or by taking on the assessment queue directly.