Continuous third-party risk governance, with evidence for your examiner.
Tier, question, monitor, and map every vendor to the controls and rules it touches.
| Vendor | Tier | Risk | SOC 2 | Status |
|---|---|---|---|---|
| Core Banking Co | Critical | Medium | Nov 2026 | Current |
| CloudAuth Inc | High | High | Oct 2026 | Review |
| MailRelay LLC | Medium | Low | Expired | Expired |
| LedgerSync Ltd | High | Medium | Jan 2027 | Current |
Vendor inventory and tiering
Every vendor sits in one inventory with a risk tier, so oversight effort follows real exposure. Zovos suggests the tier from the vendor’s criticality, data sensitivity, system access, and annual spend, and you can override it.
- 01The suggested tier comes with a rationale that names each criterion behind it.
- 02One inventory maps each vendor to the controls and rules it touches.
Questionnaires: default, custom, SIG / CAIQ import
Due-diligence questionnaires run on a default template or your own, so you can send the right depth of assessment for each vendor tier.
- 01You can use a default DDQ template or custom templates, and import SIG and CAIQ workbooks.
- 02Responses are tracked against the vendor record.
Contracts, clauses, and SLAs
Contract clauses and service levels are tracked against each vendor, so the obligations you negotiated are the obligations you monitor.
- 01Clauses are tracked against the executed contract.
- 02SLAs are tracked against the vendor and its services.
SOC 2 review and expiry alerts
A SOC 2 review agent summarizes the report and its exceptions for human review, and the platform alerts you before the report expires.
- 01An agent assists with SOC 2 report review, and a human confirms the result.
- 02Expiry alerts fire before a report goes stale.
Continuous watch, ratings, and concentration
Vendor watch and ratings keep the picture current between assessments, and a concentration view surfaces where too much risk sits with one provider or its fourth parties.
- 01Vendor watch and ratings run continuously.
- 02The concentration view includes fourth parties.
Partner and BaaS program oversight
Sponsor-bank and Banking-as-a-Service partner programs get their own oversight surface, with a structured due-diligence checklist for onboarding and review.
- 01Partner and BaaS program oversight is a first-class surface.
- 02A 32-item due-diligence checklist covers each program.
Grounded in shipped behaviour.
- The 54-connector registry includes 4 third-party-risk connectors.
- Partner and BaaS programs get a 32-item program due-diligence checklist.
- Zovos ships a default due-diligence questionnaire and custom templates, with SIG and CAIQ workbook import.
Counts come from the platform's regulatory corpus, connector registry, and seed template library at release. See the documentation for the current values.
Questions, answered first.
- Which questionnaire standards are supported?
- Zovos ships a default due-diligence questionnaire and supports custom templates. SIG and CAIQ workbooks can be imported, so you can match assessment depth to each vendor tier.
- How does Zovos handle SOC 2 reports?
- A review agent summarizes the report and its exceptions for a human to confirm, and the platform alerts you before the report expires.
- How are vendors tiered?
- Zovos suggests a tier from four criteria: business criticality, the sensitivity of the data the vendor handles, its access to your systems, and annual spend. You can override the suggestion. The highest-exposure vendors get the deepest oversight.
- Do you cover BaaS and sponsor-bank partners?
- Yes. Partner programs are a first-class oversight surface with a 32-item due-diligence checklist for onboarding and ongoing review.
See third-party risk management on your library.
Bring your controls, a policy, and one regulator paragraph that gives you trouble. We target two-week onboarding.