
Concentration risk calculator. Breach response protocol (24-hour comms). Tier 1/2/3 classification. The toolkit for vendor risk management at fintech operator scale.
The vendor that gets the annual questionnaire, the SOC 2 review and the quarterly call is usually the one that's easy to review. The vendor that would take the business down on a Tuesday morning — the single processor, the one KYC provider, the ledger nobody else can read — often gets renewed on an email.
That inversion is not a paperwork problem. It shows up as a real outage, or as a finding in an examination where you cannot evidence that the relationship was ever assessed. The fix is unglamorous: classify by what breaks if they fail, then spend the effort in that order.
A scoring framework with live scoring built into the page. You answer a fixed set of questions per vendor — data held, criticality, substitutability, regulatory exposure — and the tier falls out of the answers rather than out of an opinion.
Revenue and operational exposure to a single-vendor failure, calculated in the file. It shows you the vendors where there is no second option and no quick migration path, which is usually a shorter list than people expect and a more alarming one.
The 24-hour comms tree: who is told, in what order, with what information, and who is authorised to say it. Written before it's needed, because the day it's needed nobody is drafting a comms plan.
SOC 2, BAA and DPA request templates, scaled to tier — the Tier 1 pack, the Tier 2 short form, and the Tier 3 register entry. The point of the tiering is that Tier 3 does not get the Tier 1 pack.
Audit-defensible: what was reviewed, by whom, on what date, with what conclusion, and what changed as a result. A review you can't evidence is a review that reopens.
Every contract with its notice period, auto-renewal date and owner. The expensive vendor mistakes are usually not the sourcing — they're the auto-renewal nobody diarised.
The first pass is a list-building exercise: every third party you pay or send data to, scored through the classification module. Most operators find the list is longer than the one in their heads and that two or three vendors move up a tier once the questions are answered honestly.
After that it runs on a cadence. Tier 1 gets the full annual review and a quarterly check. Tier 2 gets the short form. Tier 3 sits in the register and gets looked at on renewal. The renewal tracker is the part you'll open most often, because notice periods are the thing that catches people.
That toolkit is the wider programme — policy, governance, board reporting. This is the working vendor module: classify, calculate concentration, review, renew. Operators who want the module standalone buy this one.
It's that module, standalone, at a lower price. If you already own CCO QOS ($277) you have it.
No. The scoring runs in your browser. Nothing is transmitted and there is no server to transmit it to.
A download link to your order email, immediately after checkout. The file is yours from that point.
See the refunds page. It's a digital file, so read the two exclusion sections above before buying rather than after.