Feature · Third parties

Continuous third-party risk governance, with evidence for your examiner.

Tier, question, monitor, and map every vendor to the controls and rules it touches.

SectionThird parties
UpdatedOctober 2026
Vendors
142
Critical
11
SOC 2 expiring
4
DDQ overdue
6
Vendor inventory · tier from criticality, data, access and spend
VendorTierRiskSOC 2Status
Core Banking CoCriticalMediumNov 2026Current
CloudAuth IncHighHighOct 2026Review
MailRelay LLCMediumLowExpiredExpired
LedgerSync LtdHighMediumJan 2027Current
Illustrative product preview. It does not show tenant data.
01 · Third-party risk management

Vendor inventory and tiering

Every vendor sits in one inventory with a risk tier, so oversight effort follows real exposure. Zovos suggests the tier from the vendor’s criticality, data sensitivity, system access, and annual spend, and you can override it.

  • 01The suggested tier comes with a rationale that names each criterion behind it.
  • 02One inventory maps each vendor to the controls and rules it touches.
02 · Third-party risk management

Questionnaires: default, custom, SIG / CAIQ import

Due-diligence questionnaires run on a default template or your own, so you can send the right depth of assessment for each vendor tier.

  • 01You can use a default DDQ template or custom templates, and import SIG and CAIQ workbooks.
  • 02Responses are tracked against the vendor record.
03 · Third-party risk management

Contracts, clauses, and SLAs

Contract clauses and service levels are tracked against each vendor, so the obligations you negotiated are the obligations you monitor.

  • 01Clauses are tracked against the executed contract.
  • 02SLAs are tracked against the vendor and its services.
04 · Third-party risk management

SOC 2 review and expiry alerts

A SOC 2 review agent summarizes the report and its exceptions for human review, and the platform alerts you before the report expires.

  • 01An agent assists with SOC 2 report review, and a human confirms the result.
  • 02Expiry alerts fire before a report goes stale.
05 · Third-party risk management

Continuous watch, ratings, and concentration

Vendor watch and ratings keep the picture current between assessments, and a concentration view surfaces where too much risk sits with one provider or its fourth parties.

  • 01Vendor watch and ratings run continuously.
  • 02The concentration view includes fourth parties.
06 · Third-party risk management

Partner and BaaS program oversight

Sponsor-bank and Banking-as-a-Service partner programs get their own oversight surface, with a structured due-diligence checklist for onboarding and review.

  • 01Partner and BaaS program oversight is a first-class surface.
  • 02A 32-item due-diligence checklist covers each program.
Proof points

Grounded in shipped behaviour.

  • The 54-connector registry includes 4 third-party-risk connectors.
  • Partner and BaaS programs get a 32-item program due-diligence checklist.
  • Zovos ships a default due-diligence questionnaire and custom templates, with SIG and CAIQ workbook import.

Counts come from the platform's regulatory corpus, connector registry, and seed template library at release. See the documentation for the current values.

FAQ

Questions, answered first.

Which questionnaire standards are supported?
Zovos ships a default due-diligence questionnaire and supports custom templates. SIG and CAIQ workbooks can be imported, so you can match assessment depth to each vendor tier.
How does Zovos handle SOC 2 reports?
A review agent summarizes the report and its exceptions for a human to confirm, and the platform alerts you before the report expires.
How are vendors tiered?
Zovos suggests a tier from four criteria: business criticality, the sensitivity of the data the vendor handles, its access to your systems, and annual spend. You can override the suggestion. The highest-exposure vendors get the deepest oversight.
Do you cover BaaS and sponsor-bank partners?
Yes. Partner programs are a first-class oversight surface with a 32-item due-diligence checklist for onboarding and ongoing review.

See third-party risk management on your library.

Bring your controls, a policy, and one regulator paragraph that gives you trouble. We target two-week onboarding.