Process

A practical path from first message to a vendor risk pack your operations, risk, and procurement leads can own. Fieldwork follows how your third parties actually support regulated activity.

Audit planning notes and laptop on a desk

Map dependence

We clarify which vendors touch payments, onboarding, data, hosting, and customer support — and which ones are critical enough that an outage or control failure would disrupt licence-sensitive activity.

Sample diligence and contracts

Onboarding files, questionnaires, SOC or equivalent reports, DPAs, exit clauses, and SLAs are sampled against your stated policy. Missing evidence and stale renewals are listed early.

Test monitoring and access

We check whether ongoing reviews, incident channels, privileged access, and data-flow inventories operate as described — not only whether a policy page says they should.

Rank residual risk and hand over

Findings are ranked by operational and customer impact. You receive a remediation sequence, owner suggestions, and a walkthrough so the next board or supervisory cycle starts cleaner.