Process
A practical path from first message to a vendor risk pack your operations, risk, and procurement leads can own. Fieldwork follows how your third parties actually support regulated activity.
Map dependence
We clarify which vendors touch payments, onboarding, data, hosting, and customer support — and which ones are critical enough that an outage or control failure would disrupt licence-sensitive activity.
Sample diligence and contracts
Onboarding files, questionnaires, SOC or equivalent reports, DPAs, exit clauses, and SLAs are sampled against your stated policy. Missing evidence and stale renewals are listed early.
Test monitoring and access
We check whether ongoing reviews, incident channels, privileged access, and data-flow inventories operate as described — not only whether a policy page says they should.
Rank residual risk and hand over
Findings are ranked by operational and customer impact. You receive a remediation sequence, owner suggestions, and a walkthrough so the next board or supervisory cycle starts cleaner.