Skip to content
Resources / Global regulatory coverage

One platform for every regulator you answer to

Third-party risk, outsourcing risk, ICT third-party risk, material service providers, business associates, sub-processors: the same discipline under different names. Here is what each regime expects of your program, and how VendRisk360 supports it.

How the mapping works

One program structure, many regimes

Third-party regulations worldwide share a common core. VendRisk360 builds your program on that core and records each regime’s specific terms on the vendor record.

Lifecycle

Intake, due diligence, contracting, monitoring and offboarding with exit evidence: the arc every regime describes.

Criticality tiering

Critical, Material and Low risk tiers set assessment depth and cadence under your own policy, mapped to each regime’s definition of critical.

Controls and evidence

30+ control domains assessed on evidence, with outside-in monitoring between reviews, reused across frameworks.

Reporting

Board decks, dashboards and the examiner package export, from the same records, for any regulator.

Region

North America

Third-party risk management for US and Canadian banks, credit unions, payment providers and healthcare organizations.

Interagency TPRM Guidance

Interagency Guidance on Third-Party Relationships: Risk Management (Federal Reserve, FDIC, OCC, 2023)

What it requires of your program
Risk management across planning, due diligence and third-party selection, contract negotiation, ongoing monitoring and termination. More comprehensive oversight for relationships that support critical activities, and board oversight of the program.
How VendRisk360 supports it
Lifecycle stages from intake to offboarding, criticality tiering that sets depth and cadence, and board decks from live data.
OCC Bulletin 2023-17

OCC Bulletin 2023-17, Third-Party Relationships: Interagency Guidance on Risk Management

What it requires of your program
Adopts the interagency guidance for national banks and federal savings associations and replaces earlier OCC third-party guidance. Examiners assess whether oversight is commensurate with risk and complexity.
How VendRisk360 supports it
Examiner package export, the Audit committee and examiner readiness deck and a full audit trail of decisions.
FFIEC

FFIEC IT Examination Handbook

What it requires of your program
Examiners evaluate how institutions select, contract with and monitor technology service providers, including review of assurance reports and business continuity arrangements.
How VendRisk360 supports it
Artifact-based assessments across 30+ control domains, SOC report analysis and BCP and DR evidence review.
NCUA

NCUA supervisory guidance on third-party relationships and 12 CFR Part 748

What it requires of your program
Credit unions assess risk, perform due diligence and monitor third parties and CUSOs, and ensure service providers safeguard member information (12 CFR Part 748, Appendix A).
How VendRisk360 supports it
Vendor and CUSO records, tiered due diligence, SOC 1 and CUEC review, and board and supervisory committee reporting.
NYDFS 23 NYCRR 500

New York DFS Cybersecurity Regulation, Section 500.11

What it requires of your program
Covered entities maintain written third-party service provider security policies: identification and risk assessment, minimum cybersecurity practices, due diligence and periodic assessment.
How VendRisk360 supports it
Policy-driven intake and tiering, cybersecurity control domains, periodic reassessment and attack-surface monitoring.
SEC Regulation S-P

SEC Regulation S-P (as amended)

What it requires of your program
Covered institutions oversee service providers through due diligence and monitoring, including arrangements for service providers to notify them of breaches affecting customer information.
How VendRisk360 supports it
Service provider due diligence, contract evidence and confirmed breach signals linked to each vendor.
GLBA Safeguards Rule

FTC Safeguards Rule (GLBA)

What it requires of your program
Select service providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess providers based on risk.
How VendRisk360 supports it
Data-type scoping at intake, safeguard evidence, contract records and risk-based reassessment.
HIPAA

HIPAA Security Rule and HITECH Act

What it requires of your program
Business associate agreements giving satisfactory assurances that PHI is safeguarded, flow-down to subcontractors, and breach notification from business associates to covered entities.
How VendRisk360 supports it
PHI scoping at intake, BAA evidence on the record, Security Rule control domains, subcontractor mapping and breach monitoring.
OSFI B-10

OSFI Guideline B-10, Third-Party Risk Management (Canada)

What it requires of your program
A third-party risk management framework for federally regulated financial institutions: risk assessment, due diligence, contracting, subcontracting oversight, monitoring, and plans for exit and disruption.
How VendRisk360 supports it
Risk-scoped intake, nth-party mapping of subcontractors, continuous monitoring and exit evidence at offboarding.
Region

Europe & UK

ICT third-party and outsourcing risk for EU and UK financial entities, insurers and data controllers.

DORA

Digital Operational Resilience Act, Regulation (EU) 2022/2554

What it requires of your program
An ICT third-party risk strategy, a register of information on ICT contractual arrangements, pre-contract assessment, mandatory contractual provisions, concentration risk assessment and exit strategies for services supporting critical or important functions.
How VendRisk360 supports it
One inventory of ICT third parties and the functions they support, criticality tagging, contract evidence, concentration analysis and exit records that feed your register of information.
EBA Outsourcing Guidelines

EBA Guidelines on outsourcing arrangements

What it requires of your program
An outsourcing register, pre-outsourcing analysis (criticality assessment and due diligence), contractual requirements, ongoing monitoring and documented exit strategies for critical or important functions.
How VendRisk360 supports it
Critical or important function tagging, pre-outsourcing due diligence, contract evidence and exit strategies per arrangement.
EIOPA Cloud Guidelines

EIOPA Guidelines on outsourcing to cloud service providers

What it requires of your program
Materiality assessment of cloud outsourcing, due diligence, contractual terms on access, audit and sub-outsourcing, monitoring and exit planning for insurers and reinsurers.
How VendRisk360 supports it
Cloud providers tiered by materiality, assessed on evidence including CSA CCM and SOC reports, with exit evidence.
NIS2

NIS2 Directive, (EU) 2022/2555

What it requires of your program
Supply chain security as a cybersecurity risk-management measure, taking account of each direct supplier’s vulnerabilities, product quality and secure development practices.
How VendRisk360 supports it
Supplier inventory, security assessments of direct suppliers and monitoring of vulnerabilities, breaches and attack surface.
GDPR

General Data Protection Regulation, Article 28

What it requires of your program
Use only processors that provide sufficient guarantees, bind them by a data processing agreement, and control sub-processors through prior authorization and flow-down of obligations.
How VendRisk360 supports it
Processor and sub-processor records with data categories and location, DPA evidence and assessment before engagement.
EU AI Act

EU Artificial Intelligence Act, Regulation (EU) 2024/1689

What it requires of your program
Risk-based obligations for providers and deployers of AI systems, phasing in from 2025. Organizations need visibility of the AI systems they use and the role they play.
How VendRisk360 supports it
AI use captured at intake, an AI-use control domain in assessments and AI vendors visible across the portfolio.
PRA SS2/21

PRA Supervisory Statement SS2/21, Outsourcing and third party risk management (UK)

What it requires of your program
Materiality assessment, proportionate due diligence, contractual safeguards, data security, sub-outsourcing oversight, business continuity and stressed exit planning for material outsourcing.
How VendRisk360 supports it
Materiality captured at intake, tiered due diligence, sub-outsourcing visibility and exit plans held on each material arrangement.
FCA SYSC 8

FCA Handbook SYSC 8, Outsourcing (UK)

What it requires of your program
Firms remain fully responsible for outsourced critical or important operational functions, must avoid undue additional operational risk and must keep the ability to monitor and terminate.
How VendRisk360 supports it
Critical or important function tagging, ongoing monitoring and offboarding evidence that shows the firm can exit.
Region

India, Asia & Middle East

Outsourcing and IT third-party oversight for banks, NBFCs, market intermediaries and healthcare across India, Singapore, the Gulf and the Philippines.

RBI IT Outsourcing Directions

RBI Master Direction on Outsourcing of Information Technology Services (India)

What it requires of your program
A board-approved IT outsourcing policy, materiality assessment, due diligence, concentration risk monitoring, periodic review, and business continuity and exit strategies for regulated entities.
How VendRisk360 supports it
Materiality tiering, evidence-based due diligence, concentration and nth-party analysis, board decks and exit evidence.
SEBI CSCRF

SEBI Cybersecurity and Cyber Resilience Framework (India)

What it requires of your program
Third-party and supply-chain cyber risk management by SEBI-regulated entities, graded by the entity’s category, including assessment of technology service providers.
How VendRisk360 supports it
Technology vendor assessments across cybersecurity domains, monitoring and an audit trail for cyber audits.
DPDP Act

Digital Personal Data Protection Act, 2023 (India)

What it requires of your program
Data fiduciaries engage data processors only under a valid contract and remain responsible for processing carried out on their behalf, including reasonable security safeguards.
How VendRisk360 supports it
Data-type scoping identifies processors of personal data; contract and safeguard evidence is held on each record.
MAS Outsourcing Guidelines

MAS Guidelines on Outsourcing and Technology Risk Management Guidelines (Singapore)

What it requires of your program
Materiality assessment, service provider due diligence, contractual protections, ongoing monitoring, and business continuity and exit planning, with technology risk expectations under the TRM Guidelines.
How VendRisk360 supports it
Material outsourcing tagging, tiered assessments, confirmed-only monitoring and exit evidence per arrangement.
SAMA

SAMA Cyber Security Framework and third-party requirements (Saudi Arabia)

What it requires of your program
Member organizations manage cybersecurity in third-party relationships through contract requirements, due diligence and ongoing monitoring, alongside SAMA’s outsourcing rules.
How VendRisk360 supports it
Cybersecurity control domains, contract evidence, tiered due diligence and a documented approval trail.
NCA ECC

NCA Essential Cybersecurity Controls (Saudi Arabia)

What it requires of your program
Cybersecurity requirements for third parties and cloud computing, including contractual clauses on data protection, confidentiality and incident notification.
How VendRisk360 supports it
Evidence-based third-party and cloud security assessments, with outside-in monitoring between reviews.
CBUAE Outsourcing Regulation

Central Bank of the UAE Outsourcing Regulation and Standards

What it requires of your program
Assessment and approval of outsourcing, stronger oversight of material outsourcing, contractual safeguards, monitoring and contingency planning for licensed financial institutions.
How VendRisk360 supports it
Material outsourcing tiering, multi-stage approval with segregation of duties and ongoing monitoring.
BSP Outsourcing & IT Risk

Bangko Sentral ng Pilipinas outsourcing and IT risk management regulations (Philippines)

What it requires of your program
Due diligence and ongoing oversight of service providers, retained accountability for outsourced activities, and IT risk management in outsourcing arrangements.
How VendRisk360 supports it
Structured due diligence, findings and remediation tracking and monitoring between assessments.
Philippine Data Privacy Act

Data Privacy Act of 2012, Republic Act 10173 (Philippines)

What it requires of your program
Personal information controllers remain responsible for data processed by personal information processors and must use contractual or other means to ensure comparable protection.
How VendRisk360 supports it
Processors of personal information identified at intake, with agreement and safeguard evidence on the record.
Region

Australia & New Zealand

Material service provider management for APRA-regulated entities and privacy obligations across the region.

APRA CPS 230

APRA Prudential Standard CPS 230 Operational Risk Management

What it requires of your program
Identify material service providers and critical operations, maintain a service provider management policy, manage the risks of material arrangements including fourth parties, and notify APRA of material arrangements.
How VendRisk360 supports it
Material service provider tagging, links to critical operations, fourth-party mapping and board-level reporting.
APRA CPS 234

APRA Prudential Standard CPS 234 Information Security

What it requires of your program
Where information assets are managed by third parties, evaluate the third party’s information security capability commensurate with the potential consequences of an incident.
How VendRisk360 supports it
Information security control domains and evidence review scaled to the vendor’s criticality.
Privacy Act 1988

Privacy Act 1988 and the Australian Privacy Principles

What it requires of your program
Take reasonable steps before disclosing personal information overseas (APP 8) and protect personal information held, including by contractors (APP 11).
How VendRisk360 supports it
Data type and location scoping at intake, contract evidence and breach monitoring for vendors holding personal information.
NZ Privacy Act 2020

Privacy Act 2020 (New Zealand)

What it requires of your program
Information held by a service provider on an agency’s behalf is treated as held by the agency, which remains responsible for it; cross-border disclosure rules apply.
How VendRisk360 supports it
Service providers holding personal information identified, assessed and monitored like any other vendor.
Region

Global standards

The control frameworks and assurance reports that vendors, auditors and examiners use everywhere.

NIST CSF 2.0

NIST Cybersecurity Framework 2.0

What it requires of your program
A cybersecurity supply chain risk management program (GV.SC): suppliers known and prioritized by criticality, requirements in contracts, due diligence, monitoring and post-relationship activities.
How VendRisk360 supports it
Suppliers prioritized by criticality, requirements and evidence per supplier, continuous monitoring and offboarding records.
NIST SP 800-161

NIST SP 800-161 Rev. 1, Cybersecurity Supply Chain Risk Management

What it requires of your program
Cybersecurity supply chain risk management practices at enterprise, mission and system levels, including assessment of suppliers and their suppliers.
How VendRisk360 supports it
Nth-party mapping of suppliers’ suppliers, concentration analysis and supply chain assessments.
NIST AI RMF

NIST AI Risk Management Framework 1.0

What it requires of your program
Govern, map, measure and manage AI risk; GOVERN 6 addresses risks from third-party software, data and AI models.
How VendRisk360 supports it
AI vendors identified and assessed, with a named reviewer approving every AI output in VendRisk360 itself.
ISO/IEC 27001

ISO/IEC 27001:2022

What it requires of your program
Supplier relationship controls (Annex A 5.19 to 5.23): policy, agreements, ICT supply chain, monitoring and change of supplier services, and cloud service security.
How VendRisk360 supports it
Control domains that map to supplier controls, supplier agreements as evidence and scheduled reassessment.
ISO/IEC 27701

ISO/IEC 27701

What it requires of your program
Privacy information management, including processor controls on subcontractors that process personal information.
How VendRisk360 supports it
Sub-processor inventory and diligence records that support your privacy information management evidence.
ISO/IEC 27036

ISO/IEC 27036, Information security for supplier relationships

What it requires of your program
Information security across the supplier relationship lifecycle, for acquirers and suppliers of products and services.
How VendRisk360 supports it
A governed lifecycle for each supplier from intake to offboarding.
ISO/IEC 42001

ISO/IEC 42001, AI management systems

What it requires of your program
An AI management system, including controls that allocate responsibilities with, and manage, AI suppliers and third parties.
How VendRisk360 supports it
AI suppliers tiered and assessed with an AI-use control domain and evidence such as 42001 certificates.
ISO 22301

ISO 22301, Business continuity management

What it requires of your program
Business continuity management, including continuity of activities that depend on suppliers.
How VendRisk360 supports it
BCP and DR test evidence reviewed for Critical vendors and linked to exit plans.
SOC 1 & SOC 2

AICPA SOC 1 and SOC 2 reports

What it requires of your program
User entities review service organization reports for scope, opinion, exceptions, subservice organizations and the complementary user entity controls (CUECs) they must operate.
How VendRisk360 supports it
SOC report review covering exceptions, carve-outs, subservice organizations and CUECs mapped to your controls, on the platform or as an expert SOC Report Review with optional AI assistance.
PCI DSS v4.0

PCI DSS v4.0, Requirement 12.8

What it requires of your program
Requirement 12.8: a list of third-party service providers, written agreements, pre-engagement due diligence, annual monitoring of compliance status and a record of shared responsibilities.
How VendRisk360 supports it
Providers touching account data identified at intake, agreements and AOCs as evidence, and a reassessment cadence set to your policy.
HITRUST CSF

HITRUST CSF

What it requires of your program
A certifiable control framework widely used as assurance for vendors that handle sensitive healthcare data.
How VendRisk360 supports it
HITRUST reports reviewed against your control domains as vendor evidence.
CSA CCM

Cloud Security Alliance Cloud Controls Matrix

What it requires of your program
Cloud control objectives, including the supply chain management, transparency and accountability domain, used to assess cloud providers.
How VendRisk360 supports it
Cloud provider questionnaires and CCM-aligned evidence reviewed against your control domains.
Terminology crosswalk

What each regime calls a critical vendor

The same relationship can be a critical activity to your US examiner, a critical or important function under DORA and a material service provider under CPS 230. VendRisk360 records the designation and applies one consistent tier.

Terminology crosswalk: how each regime describes critical third parties and how VendRisk360 tiers them
US Interagency Guidance, OCC 2023-17Third parties that support critical activitiesCritical tier; critical activity recorded at intake
NCUAThird-party relationships, including CUSOsCritical or Material tier; CUSO recorded on the vendor
OSFI B-10 (Canada)High-risk and critical third-party arrangementsCritical tier, with subcontractors mapped
DORA (EU)ICT services supporting critical or important functionsCritical tier; function recorded for the register of information
EBA Outsourcing Guidelines (EU)Outsourcing of critical or important functionsCritical tier; outsourcing arrangement flagged
PRA SS2/21 (UK)Material outsourcing arrangementsCritical or Material tier by your materiality assessment
FCA SYSC 8 (UK)Outsourcing of critical or important operational functionsCritical tier
RBI (India)Material outsourcing of IT servicesCritical or Material tier by materiality
MAS (Singapore)Material outsourcing arrangementsCritical or Material tier by materiality
CBUAE (UAE)Material outsourcingCritical or Material tier by materiality
APRA CPS 230 (Australia)Material service providers supporting critical operationsCritical tier; critical operation linked
HIPAA (US)Business associates and their subcontractorsPHI in scope; tier by data and service criticality
GDPR (EU and UK)Processors and sub-processorsPersonal data in scope; tier by data and service
PCI DSS v4.0Third-party service providers (TPSPs)Account data in scope; tier by service
SOC 1 and SOC 2 reportsSubservice organizationsMapped as fourth parties, with CUECs tracked
NIST CSF 2.0Suppliers prioritized by criticality (GV.SC)Critical, Material or Low risk tier

Important: VendRisk360 is aligned to and maps to the regulations and standards on this page. It does not certify compliance with them, and nothing here is legal or regulatory advice. Summaries are simplified for comparison and may not reflect every provision, amendment or regulator interpretation. Your organization remains responsible for its own compliance and should confirm how each requirement applies to it with its advisers and regulators.

FAQ

Frequently asked questions

Does using VendRisk360 make us compliant with these regulations?

No platform can make an organization compliant. VendRisk360 is aligned to and maps to these regulations and standards: it structures your program, evidence and reporting the way they expect. Your organization remains responsible for its own compliance and for how each rule applies to it.

Can one program satisfy several regulators at once?

Yes, for most of the work. Tiering, control domains and evidence are shared, and the vocabulary each regime uses (critical activities, critical or important functions, material outsourcing, material service providers) is recorded on the vendor, so one assessment can support obligations in several jurisdictions. Registers and notifications to each regulator are still prepared by you in the required format.

Do you offer data residency in my country?

VendRisk360 is hosted on enterprise cloud infrastructure. If you have data residency or localization requirements, for example under RBI, SAMA or NCA rules, raise them with our team during your evaluation so we can discuss what is available for your deployment.

How do you keep regulatory mappings current?

Regulations change. We review how the platform maps to a regime when it is amended, and your team records the regime-specific designation and tiering rationale on each vendor record, so your program reflects your own policies and interpretation.

Is my regulator missing?

The frameworks here are the ones customers ask about most. The platform’s structure (lifecycle, tiering, evidence, monitoring, reporting) is common to third-party rules worldwide, so other regimes can usually be supported through configuration. Talk to us about your jurisdiction.

Get started

See how VendRisk360 maps to your regulators

A tailored walkthrough with a third-party risk specialist, built around your program, your regulators and your vendors.