The Protocol CollectiveAll guides

Guide

The vendor risk register that actually works (and why yours is rotted)

Pull up your vendor risk register right now. Look at the "last reviewed" column. How many vendors have a date older than 9 months? How many tier-1 vendors don't have a current SOC 2 report on file?

If you answered "more than zero," you're not running a vendor risk register. You're maintaining a museum.

The four properties of a working register

1. Every vendor has a tier. Tier 1 (data sensitivity high, system criticality high) through Tier 4 (low both). Tiering is consistent — same inputs, same tier, every time. Don't eyeball-tier; calculate-tier.

2. Tier drives review cadence. Tier 1 — quarterly review. Tier 2 — semi-annual. Tier 3 — annual. Tier 4 — annual self-attestation. Anything missed gets escalated.

3. SOC 2 / ISO 27001 reports stored centrally. Expiration tracking on each. Tier 1 vendors with stale reports get chased automatically.

4. Onboarding gate before contract. No new vendor gets contracted without going through risk classification BEFORE the contract is signed.

The 80/20 you keep ignoring

5 vendors actually matter at most fintechs. The other 95 are paperwork.

Spend disproportionate effort on the 5: payment processor, KYC vendor, cloud platform, customer data store, email service provider. Get THEIR SOC 2s current. Run THEIR risk reviews quarterly. Have a remediation plan for THEIR breach scenarios.

The other 95 — coffee subscription, marketing tool, scheduling app — are an annual self-attestation cycle, no more.

Stop equalising the work.

The classification calculator

Score every vendor on 4 dimensions, 0-5 each: