← All demos·Compliance & Risk
Interactive demo Fintech & Financial

Vendor Risk Review

Third-party risk assessments in a fraction of the time — mapped to your control framework.

–65%time per vendor assessment

🏢 Vendor Risk Review

Turn scattered due-diligence inputs — SOC 2 exceptions, questionnaire answers, financial notes — into a structured vendor risk assessment mapped to your control framework, in under a minute.

VENDOR: NovaPay Systems Inc. TYPE: Payments API / Critical Third Party GENERATED IN: 38 seconds

Raw Due-Diligence Inputs

UNFORMATTED
Vendor review — NovaPay Systems Inc. SERVICE: Payment processing API for our debit card program. They tokenize and route card transactions, handle authorization requests, and store transaction-level data on behalf of the institution. We went live with them 14 months ago. Currently ~$2.1M in annual fees. DATA ACCESS: Yes — cardholder PII (name, card number, billing address), transaction amounts/merchants, account identifiers. Counts as Critical/Tier 1 under our TPRM policy. SOC 2 TYPE II (most recent report — period ending 9/30/2025): - Coverage: Security, Availability, Confidentiality - 2 exceptions noted: (1) Patch management: 3 servers in the prod environment had OS patches delayed 47+ days beyond SLA during Q3. Auditor flagged as deviation from CC6.8. (2) Subcontractor oversight: one sub (CloudRoute LLC) was onboarded mid-period without completing NovaPay's documented vendor assessment process. Flagged under CC9.2. - Management response: patch process remediated per attestation; sub assessment now complete. SECURITY QUESTIONNAIRE (completed by NovaPay, Oct 2025): - MFA: Required for all privileged access and remote access. Standard user access still password-only in legacy admin portal (acknowledged, roadmap item Q2 2026). - Encryption: TLS 1.3 in transit; AES-256 at rest for cardholder data. PCI-DSS Level 1 certified (AOC on file, valid thru Aug 2026). - BCP/DR: RTO 4 hours, RPO 1 hour. Last DR test: June 2025 — partial failover test, secondary site activated. No full failover since 2023. - Subcontractors: 4 sub-processors (CloudRoute LLC, DataVault Inc., TrustID Corp., NetMonitor AG). Only DataVault and TrustID have current SOC 2 reports on file from NovaPay. CloudRoute and NetMonitor are pending. FINANCIAL / VIABILITY: - Private company, ~$85M ARR, last funding round Series C ($40M, Jan 2024). - No public financials. Per their CFO attestation, 18+ months runway. - No insolvency proceedings, no material litigation disclosed. PRIOR INCIDENTS: - Aug 2024: 3.5-hour API outage affecting authorization routing. Root cause: misconfigured load balancer after a deploy. Postmortem provided; redundancy improvements deployed Nov 2024. - No data breaches or regulatory actions disclosed. ADDITIONAL NOTES: Contract renews Jan 2026. No SLA penalties were triggered in the past 12 months. Our team rates relationship as "satisfactory." They have not provided a right-to-audit clause — currently under negotiation.

AI-Drafted Risk Assessment

AI DRAFTED
🏢 Click "Generate Risk Assessment" to turn the raw due-diligence inputs into a structured vendor risk assessment.
Analyzing vendor inputs and mapping to control framework...
⚡ Assessment completed in 38 seconds

Vendor Overview & Service

Control Assessment

Control DomainRatingKey Note
Access ControlPARTIALMFA enforced for privileged/remote access; legacy admin portal remains password-only (remediation Q2 2026). Gap against FFIEC CAT and Interagency TPRM expectations for critical vendors.
Encryption & Data SecuritySATISFACTORYTLS 1.3 in transit, AES-256 at rest. PCI-DSS Level 1 AOC current (valid Aug 2026). Meets baseline for cardholder data environments.
Resilience / BCP & DRMONITORRTO 4 hr / RPO 1 hr documented. Last full DR test 2023; June 2025 test was partial only. Full failover testing annually is a standard TPRM expectation for Tier 1 vendors.
Patch ManagementEXCEPTIONSOC 2 exception: 3 prod servers patched 47+ days past SLA (CC6.8). Management attestation of remediation provided — verify in next report cycle.
Data PrivacySATISFACTORYCardholder PII handled under PCI-DSS scope. No data breaches disclosed. Contractual data handling obligations in place; confirm GLBA-aligned data processing addendum at renewal.
Subcontractor MgmtEXCEPTIONTwo of four sub-processors (CloudRoute LLC, NetMonitor AG) lack current SOC 2 reports in NovaPay's vendor file. CloudRoute onboarded without completing assessment (CC9.2 exception). Interagency Guidance §IV.C requires institutions to assess fourth-party risk for critical vendors.
Financial ViabilityMONITORPrivate company; no audited financials. CFO attestation of 18+ months runway. Series C funded Jan 2024. Monitor concentration risk — no obvious successor/exit plan disclosed.

Key Findings & Gaps

Recommendation & Required Remediations

Vendor reviews used to take days of analyst time. Now it's 30 minutes of review.

A custom build maps your vendor inputs to your specific control framework, risk tiers, and policy thresholds — so your team reviews instead of reformats.

Book a 30-Min Call →

Want this built for your institution?

This is a hands-on taste, wired to placeholder data. In a 30-minute call we'll scope your version — applying your vendor tiers, control framework, and policy thresholds, connected to your existing TPRM workflow.