See the real blast radius before it reaches you
Your vendors run on the same clouds, processors and software. VendRisk360 maps fourth parties and subservice organizations, measures where your critical services concentrate, and shows exactly who is affected when one shared provider fails.
Your risk does not stop at the contract
Operational resilience regulators now ask about the chain, not just the counterparty. The platform builds the chain from evidence you already collect.
You
Your critical or important functions, business services and the data types they depend on.
Your vendors
Each vendor record: services, tier, data types, contracts, evidence and findings.
Their providers
Subservice organizations from SOC reports and dependencies vendors disclose, each one shared across every vendor that uses it.
One entity per provider
A cloud platform named by twelve vendors is one node with twelve links, not twelve separate notes.
Direct and indirect paths
See whether a critical service depends on a provider directly, through a vendor, or through a vendor’s subservice organization.
Tied to your services and data
Each dependency connects to the vendor services, tiers and data types on the vendor record, so impact reads in terms of your operations.
Find the single points of failure you did not choose
Concentration rarely comes from one decision. It accumulates, contract by contract, until a single provider sits under a third of your critical services.
- Concentration by provider, by service type and by hosting region
- Critical services that share a fourth party, highlighted
- Systemic risk: providers whose failure would affect many of your vendors at once
- Concentration Risk Briefing deck for the risk committee, from the same data
When a shared provider fails, who is affected?
These are the scenarios risk committees now ask about. Each one starts with a single provider and ends with a list of affected vendors, services and owners.
A shared cloud region goes down
- Scenario
- A hyperscaler region fails for several hours. Your core banking provider, your fraud screening vendor and your customer messaging platform all run there, through different contracts.
- What VendRisk360 shows
- Every vendor and critical service hosted in that region, the business services they support, and which of them have tested failover evidence on file.
A core processor is breached
- Scenario
- A payment or core processing provider used by many institutions discloses a breach. Some of your vendors rely on it indirectly as a subservice organization.
- What VendRisk360 shows
- Direct and indirect exposure through the fourth-party map, the data types involved at each vendor, and the owners who need to make notification decisions.
Widely used software is compromised
- Scenario
- A vulnerability is exploited in a file-transfer or remote-access product used across the industry.
- What VendRisk360 shows
- Vendors that disclosed the product as a dependency, their tier and data types, so outreach starts with the vendors that matter most.
A subservice organization’s SOC report has exceptions
- Scenario
- A data center operator carved out of three vendors’ SOC reports receives a qualified opinion.
- What VendRisk360 shows
- Each vendor that carves out the same subservice organization, and the CUECs and compensating controls you rely on.
Scenarios are generic illustrations and do not describe any specific provider or event.
The controls the SOC report assumes you run
Every SOC 1 and SOC 2 report lists complementary user entity controls. If you do not operate them, the auditor’s conclusion may not hold for you. Most programs never check.
Captured from every SOC report
CUECs are recorded during SOC review by your analyst, or captured by VendRisk360 assessors through Comprehensive Vendor Risk Assessment Services or a SOC Report Review.
Mapped to your own controls
Each CUEC is linked to the internal control and owner that satisfies it, so gaps are visible and assigned.
Tracked across vendors
The same CUEC in several reports maps to one internal control, so a gap is resolved once, not vendor by vendor.
Why regulators now ask about the whole chain
Fourth-party and concentration risk moved from good practice to explicit expectation across major markets. VendRisk360 is aligned to these requirements; each organization remains responsible for its own compliance.
DORA
The register of information records ICT third-party arrangements and the subcontractors supporting critical or important functions. Article 29 requires assessment of ICT concentration risk before contracting.
EBA Guidelines on outsourcing
Sub-outsourcing of critical or important functions must be identified, approved and monitored, with the risks of the full chain assessed.
PRA SS2/21
Material outsourcing and sub-outsourcing oversight, with concentration and exit considered as part of operational resilience.
APRA CPS 230
Material service providers must be identified and managed, including the risks from their own reliance on downstream providers, with concentration considered.
RBI
The Master Direction on outsourcing of IT services requires regulated entities to assess concentration risk and sub-contracting arrangements of service providers.
MAS Guidelines on Outsourcing
Sub-contracting in material outsourcing must be assessed and controlled so oversight is not diluted.
OSFI Guideline B-10
Third-party risk management extends to subcontractors that support critical arrangements, with concentration risk assessed across the portfolio.
OCC and Interagency Guidance
Due diligence and ongoing monitoring should consider a third party’s reliance on subcontractors, and concentration where many banks depend on the same provider.
Works with the rest of the platform
Vendor Lifecycle Management Platform
Manage vendors, request evidence, review, record and sign off
Learn moreVendor lifecycle
Intake to offboarding in one governed record
Learn moreBoard & Executive Reporting
Board packs, executive briefings and examiner-ready exports
Learn moreComprehensive Vendor Risk Assessment
You onboard the vendor; our certified assessors do the rest
Learn moreContinuous Monitoring
Outside-in monitoring: attack surface, shadow infrastructure, compromise
Learn moreReport-Specific Reviews
SOC report, information security and business continuity reviews
Learn moreFrequently asked questions
What is nth-party risk?
Nth-party risk is the risk that comes from your vendors’ own vendors (fourth parties) and their providers in turn. A failure at a cloud platform, processor or software supplier you have never contracted with can still disrupt your critical services through the vendors that rely on it.
Where does fourth-party data come from?
VendRisk360 builds the relationship map from the subservice organizations named in SOC reports and from what vendors disclose in their questionnaires and evidence through the vendor portal. Each fourth party is one shared entity, linked to every vendor that relies on it.
How is concentration risk measured?
The platform counts how many of your vendors and critical services depend on the same provider, service or hosting region, and highlights where that dependence exceeds what you consider acceptable. The result feeds the Concentration Risk Briefing deck for the risk committee.
What is blast-radius analysis?
Blast-radius analysis starts from one failing provider and shows every vendor, critical service and business process that depends on it, directly or indirectly. It turns a news headline into a list of affected relationships and owners.
What are CUECs and why track them?
Complementary user entity controls are controls that a SOC report assumes the customer operates, such as reviewing user access or reconciling reports. If you do not operate them, the auditor’s conclusion may not hold for you. VendRisk360 lists each CUEC and maps it to your own control and owner.
Does this help with the DORA register of information?
Yes. The vendor and fourth-party records hold the ICT arrangements, supported functions and subcontracting chains the register draws on, and the data exports to Excel. Your compliance team remains responsible for the final submission and its format.
See VendRisk360 on your own vendors
A tailored walkthrough with a third-party risk specialist, built around your program, your regulators and your vendors.