Guide
The vendor risk register that actually works (and why yours is rotted)
Pull up your vendor risk register right now. Look at the "last reviewed" column. How many vendors have a date older than 9 months? How many tier-1 vendors don't have a current SOC 2 report on file?
If you answered "more than zero," you're not running a vendor risk register. You're maintaining a museum.
The four properties of a working register
1. Every vendor has a tier. Tier 1 (data sensitivity high, system criticality high) through Tier 4 (low both). Tiering is consistent — same inputs, same tier, every time. Don't eyeball-tier; calculate-tier.
2. Tier drives review cadence. Tier 1 — quarterly review. Tier 2 — semi-annual. Tier 3 — annual. Tier 4 — annual self-attestation. Anything missed gets escalated.
3. SOC 2 / ISO 27001 reports stored centrally. Expiration tracking on each. Tier 1 vendors with stale reports get chased automatically.
4. Onboarding gate before contract. No new vendor gets contracted without going through risk classification BEFORE the contract is signed.
The 80/20 you keep ignoring
5 vendors actually matter at most fintechs. The other 95 are paperwork.
Spend disproportionate effort on the 5: payment processor, KYC vendor, cloud platform, customer data store, email service provider. Get THEIR SOC 2s current. Run THEIR risk reviews quarterly. Have a remediation plan for THEIR breach scenarios.
The other 95 — coffee subscription, marketing tool, scheduling app — are an annual self-attestation cycle, no more.
Stop equalising the work.
The classification calculator
Score every vendor on 4 dimensions, 0-5 each:
- Data sensitivity (do they hold customer data?)
- System criticality (does our platform fail without them?)
- Geographic risk (are they in a high-risk jurisdiction?)
- Regulatory exposure (do they touch regulated processes?)
Total: 17-20 = Tier 1. 12-16 = Tier 2. 7-11 = Tier 3. 0-6 = Tier 4.
The math removes ambiguity. The same vendor scored by different team members gets the same tier. Auditors love this. The register is defensible.
The RegTech Vendor Audit Framework
General information about compliance and programme structure, not regulatory, legal, tax or financial advice, and no promise of any examination or audit outcome. Built from public frameworks; the professional judgement is yours.