BLACKSWANCapital Markets OS Vendor, Outsourcing & Third-Party Risk Centre · v1.0 draft ← Return to OS Architecture
Vendor & Third-Party Risk · Founder-only staging

Vendor, Outsourcing & Third-Party Risk Centre Vendor inventory, criticality, due diligence, contracts, subcontractor chain, SLA/SLOs, resilience, concentration, exit plans, and ongoing attestation evidence.

This Centre is internal third-party risk readiness workflow. Numbers below are staging / simulated vendor data. Nothing here is legal advice, outsourcing-compliance certification, regulatory approval, an audit opinion, or authorization for external launch. Outsourcing notice obligations to supervisors and exit-plan adequacy require external counsel confirmation against the rule set in force per jurisdiction.

Vendors in inventory
10
Mapped
Identity provider · GitHub · hosting · email · storage · monitoring · tooling · counsel · auditor · billing provider.
Critical outsourcing
3
Critical
Identity provider · hosting · monitoring (SIEM target).
Exit plan required
3
Required
Critical-outsourcing rows pending fallback provider evidence.
Concentration watch
2
Watch
Hosting + monitoring single-region; counsel review on dispersion.
Vendor states used on this Centre
Not Assessed
Identified dependency; assessment not started.
Intake
Vendor intake template captured; owner named.
Due Diligence
Security, resilience, financial-viability assessments in flight.
Contracting
MSA / DPA / SCC / audit rights in review.
Approved
Owner approval recorded; baseline controls in place.
Conditional Approval
Conditional with limitation text and expiry; review date set.
Critical Outsourcing
Service whose loss materially impacts a regulated activity if launched.
Concentration Watch
Dependency exceeds internal concentration threshold; mitigation tracked.
SLA Breach Watch
SLA/SLO degraded; escalation to Production Monitoring.
Exit Plan Required
Fallback / substitution plan evidence outstanding.
Suspended
Vendor relationship paused pending evidence uplift or counsel review.
Offboarded
Vendor exited; data return / deletion evidenced.
Archived
Closure recorded; immutable evidence retained per retention class.
Twelve vendor risk domains

Each domain has named owner, evidence pack, audit-event tag

Domains map back to Launch Readiness Operational Resilience gate, Data Governance vendor controls, and the Outsourcing Concentration evidence pack.

Domain 1
Vendor Inventory Master register of vendors, subcontractors, services, owners, jurisdictions.
Green
Domain 2
Criticality Assessment Material-to-regulated-activity test; criticality tier per vendor; tied to Operational Resilience.
Green
Domain 3
Outsourcing Classification Internal classification per jurisdiction; counsel confirmation on supervisor-notice threshold.
Amber
Domain 4
Due Diligence SOC 2 / ISO evidence, security questionnaire, financial viability, audit rights.
Amber
Domain 5
Contract / DPA Controls MSA · DPA · SCC · audit rights · breach notice · subcontractor notice · termination assistance.
Amber
Domain 6
Subcontractor Chain Fourth-party register; flow-down of obligations; notification on changes.
Amber
Domain 7
Data Access & Processing Data categories, processing purpose, jurisdiction; ties to Data Governance.
Amber
Domain 8
SLA / SLO Monitoring Uptime · response · RTO/RPO · audit log availability · breach watch.
Amber
Domain 9
Resilience & BCP/DR Vendor BCP/DR test evidence, RTO/RPO commitments, scenario evidence.
Amber
Domain 10
Concentration Risk Single-provider / single-region dependencies; mitigation; substitute readiness.
Amber
Domain 11
Exit & Substitution Plan Trigger · replacement · data return · transition timeline · board/regulator evidence.
Red
Domain 12
Ongoing Review & Attestation 60d / 90d review cadence; vendor attestation; audit-event capture mandatory at cutover.
Green
Vendor inventory · ten vendors

Each vendor owner-named with criticality, service, jurisdiction, contract posture

Sample staging rows aligned to current OS posture. Critical vendors carry exit-plan-required flags pending fallback evidence; concentration-watch rows are tracked on the panel below.

Vendor · owner
Service · criticality · jurisdiction · contract · review · blocker · next
Classification
State
Identity Provider (target Entra)
CISO · IAM
Service
Auth issuance · Conditional Access · RBAC/ABAC.
Criticality
Critical · loss blocks auth.
Jurisdiction
EU / multi-region.
Contract
DPA + SCC drafted · cutover pending.
Review
90d.
Blocker
Tenant application registration outstanding.
Next
Cutover application · SIEM forwarding wired.
Critical
Contracting
GitHub · repository
CISO · Founder Admin
Service
Source code · pack hashes · CI metadata.
Criticality
High · code custodianship.
Jurisdiction
US.
Contract
DPA on file · OAuth restrictions enforced.
Review
90d.
Blocker
None.
Next
Quarterly attestation; SOC 2 refresh.
Approved
Approved
Hosting / deployment
CISO · COO
Service
Static + Node backend · single-tenant staging.
Criticality
Critical · loss blocks API.
Jurisdiction
Single-region · concentration watch.
Contract
DPA drafted; SCC pending.
Review
60d.
Blocker
Multi-region failover plan outstanding.
Next
Document fallback provider candidates.
Critical
Exit Plan Required
Email / notifications
Founder Admin · CCO
Service
Stakeholder comms · supervisor pre-engagement comms.
Criticality
Medium · manual fallback available.
Jurisdiction
Multi-region.
Contract
DPA + SCC drafted; counsel review pending.
Review
60d (stale on next cycle).
Blocker
Counsel review on transfer safeguards.
Next
Counsel opinion; manual fallback rehearsed.
Approved
Conditional
Data storage
CISO
Service
In-memory session registry · file-system Pack Registry.
Criticality
Medium · staging-only; no real client data.
Jurisdiction
Internal staging.
Contract
Internal · DPA n/a (no third-party storage today).
Review
60d.
Blocker
None.
Next
Map production storage vendor decision at cutover.
Approved
Approved
Monitoring / logging (SIEM target)
CISO
Service
Audit-event forwarding · session telemetry · detection rules.
Criticality
Critical · loss breaks audit chain.
Jurisdiction
Single-region · concentration watch.
Contract
DPA + SCC drafted; counsel review pending.
Review
60d.
Blocker
Production SIEM target identified but not wired.
Next
Pre-cutover failover rehearsal; fallback provider documented.
Critical
Exit Plan Required
Connected tooling
Founder Admin
Service
Document drafting · Pack Registry tooling.
Criticality
Medium · drafting layer only.
Jurisdiction
Multi-region.
Contract
DPA on file; SCC pending.
Review
90d.
Blocker
Counsel review on transfer safeguards.
Next
Counsel opinion; alternative tooling identified.
Approved
Conditional
External legal counsel
Legal Counsel · Founder Admin
Service
Counsel opinions · perimeter · DPA · transfer safeguards.
Criticality
High · perimeter and counsel review depend on this.
Jurisdiction
Multi-region (admitted jurisdictions confirmed).
Contract
Engagement letter + NDA + privilege wording on file.
Review
90d.
Blocker
None.
Next
UK · MAS · MiFID perimeter opinions.
Approved
Approved
Prospective auditor / assurance
Founder Admin · CFO sponsor
Service
SOC 2 / ISAE 3402 / financial-statement audit (pre-engagement).
Criticality
High · external assurance gate.
Jurisdiction
Multi-region.
Contract
Scope letter pending; conflict-check open.
Review
90d.
Blocker
Scope letter outstanding.
Next
Pre-engagement walk-through.
Due Diligence
Due Diligence
Payment / billing provider
CFO · CCO
Service
Outbound invoicing · payments · reconciliation (pre-launch).
Criticality
High when launched · Tier 1+ revenue path.
Jurisdiction
Multi-region · pending selection.
Contract
Not signed · pre-launch.
Review
Pre-launch.
Blocker
Vendor not selected; no live billing.
Next
Down-select shortlist · DD start.
Intake
Not Assessed
Outsourcing classification matrix

Per-jurisdiction internal classification & supervisor-notice posture

Classification is internal readiness only; supervisor-notice threshold determinations require external counsel confirmation against the rule set in force.

Drafted Counsel Review Blocking Not-in-scope
Service ADGM / FSRA UK FCA MAS MiFID / MiFID II Owner · Note
Identity provider Counsel Review Counsel Review Counsel Review Counsel Review Critical · supervisor-notice threshold to confirm pre-cutover.
Hosting / deployment Counsel Review Counsel Review Counsel Review Counsel Review Critical · single-region; concentration watch.
Monitoring / SIEM Counsel Review Counsel Review Counsel Review Counsel Review Critical · audit-chain integrity dependency.
Email / notifications Drafted Counsel Review Counsel Review Counsel Review Medium · manual fallback available.
Connected tooling Drafted Counsel Review Not-in-scope Counsel Review Medium · drafting layer; alternative tools identified.
Legal counsel Drafted Drafted Drafted Drafted Professional services; not classified as outsourcing.
Auditor / assurance Counsel Review Counsel Review Not-in-scope Counsel Review Independent assurance; pre-engagement.
Payment / billing provider Blocking Blocking Blocking Blocking Not selected today; required before any external billing.
GitHub · repository Drafted Drafted Drafted Drafted Code custodian; OAuth restrictions enforced.
Data storage Not-in-scope Not-in-scope Not-in-scope Not-in-scope Internal staging only; production storage vendor TBD.
Subcontractor & fourth-party chain

Vendor → subcontractor → service → data access → approval

Flow-down obligations and notification triggers are captured here; counsel review pending for supervisor-notice scope.

Vendor · subcontractor
Service · data access · location · notification obligation · evidence
Owner
State
Identity Provider → Cloud infra
Underlying cloud infra · auth token storage · multi-region.
Auth issuance · personal identifiers · vendor-managed regions · supervisor-notice threshold counsel-pending.
CISO · IAM
Counsel Review
Hosting → CDN edge
Static asset edge cache · no client personal data.
Asset delivery · no MNPI · multi-region edges · notification not required at current scope.
CISO · COO
Approved
Email → Deliverability network
SMTP / DKIM / DMARC partners · recipient identifiers.
Comms delivery · personal data · multi-region · supervisor-notice n/a at current scope.
Founder Admin · CCO
Counsel Review
Monitoring → Long-term log storage
Cold storage for audit-event chain.
Audit-event retention · staging-only today · production target identified · counsel review on cross-border.
CISO
Counsel Review
Tooling → Search / AI sub-processors
Drafting and search sub-processors.
Document drafting · staging metadata only · counsel review on transfer safeguards.
Founder Admin
Counsel Review
Payment provider → Acquirer / bank
Settlement bank rail; not selected today.
Settlement · no live billing · supervisor-notice required pre-launch · evidence outstanding.
CFO · CCO
Not Assessed
SLA / SLO monitoring panel

Eight metrics · target · current · breach watch

Staging-only readings. Breach watch ties into Production Monitoring and Regulatory Escalation for any critical-vendor degradation.

Metric · note
Target
Current
State
Uptime · combined Auth + API
30d window; staging.
≥ 99.9%
99.94%
Green
Incident response · vendor-side acknowledgement
Sev-1 / Sev-2 ack.
≤ 30 min
22 min
Green
RTO / RPO commitments
Critical services.
RTO 4h · RPO 15m
Tested staging
Amber
Audit log availability
Immutable retention.
≥ 99.95%
100% (staging)
Green
Data export availability
DSR / regulator response.
≥ 99.5%
99.7% (staging)
Green
Notification response · vendor breach
From vendor to BLACKSWAN.
≤ 24h
Tabletop only
Amber
Support response
P1 / P2.
P1 1h · P2 4h
Within target
Green
SLA breach watch
Open breach incidents (24h).
0
0
Green
Concentration risk panel

Dependencies · affected services · substitute · concentration score

Concentration score is internal (1 = isolated, 5 = single-provider critical). Mitigation owner is named and tracked.

Dependency
Affected BLACKSWAN services · substitute · exit complexity · mitigation
Score · owner
State
Identity provider (Entra target)
Affected: Auth · sign-in · Conditional Access. Substitute: other OIDC IdP (engineering effort). Exit complexity: high — session model refactor. Mitigation: documented break-glass; counsel pre-engagement.
5 · CISO · IAM
Concentration Watch
Hosting / deployment
Affected: API / app delivery. Substitute: alternate region / provider. Exit complexity: medium — config + DNS. Mitigation: multi-region runbook drafted; fallback provider candidates identified.
4 · CISO · COO
Concentration Watch
Monitoring / SIEM
Affected: audit-event chain · detection rules. Substitute: alternative SIEM. Exit complexity: high — hash continuity reconciliation. Mitigation: staging-only today; failover rehearsal scheduled.
4 · CISO
Exit Plan Required
Email / notifications
Affected: stakeholder comms · supervisor pre-engagement. Substitute: alternate provider. Exit complexity: low — DNS + template re-pin. Mitigation: manual fallback rehearsed.
2 · Founder Admin · CCO
Mitigated
External legal counsel
Affected: counsel opinions · perimeter. Substitute: panel of admitted firms. Exit complexity: low — engagement letter. Mitigation: backup firm identified.
2 · Legal Counsel · Founder Admin
Mitigated
Auditor / assurance
Affected: external assurance (SOC 2 / ISAE 3402). Substitute: alternate Big-4. Exit complexity: medium. Mitigation: scope letter shortlists two firms.
3 · CFO sponsor · Founder Admin
Due Diligence
Payment / billing provider
Affected: outbound invoicing path. Substitute: not selected today. Exit complexity: n/a until selected. Mitigation: vendor shortlist exercise pending.
1 · CFO · CCO
Not Assessed
Due diligence checklist

Ten DD items — owner named, evidence on Pack Registry

Closure requires reviewer pass and a Pack Registry hash for the named vendor. Sample posture aligned to current critical-vendor inventory.

✓Closed ~Partial ✗Blocking
Due diligence item
Owner
~
SOC 2 / ISO evidence
SOC 2 collected for hosting + GitHub; SIEM target SOC 2 outstanding pre-cutover.
CISO
~
Security questionnaire
Critical vendors questionnaire complete in staging; production targets pending.
CISO
~
DPA / SCC / contract terms
Drafted for hosting, monitoring, email, tooling; counsel review outstanding.
Legal Counsel · CCO
~
Data location
Mapped per Data Governance inventory; multi-region documented; sub-processor map outstanding for tooling.
CISO · CCO
~
Resilience test evidence
Tabletop test evidence captured for hosting + identity provider; full DR rehearsal pre-cutover required.
CISO · COO
~
Incident notification
Vendor incident notification clauses drafted; counsel review on 24h trigger.
CCO · CISO
~
Audit rights
Right-to-audit drafted; supervisor right-of-access clauses outstanding for critical outsourcing.
Legal Counsel · CCO
~
Subcontractor disclosure
Disclosure obligation in contract for critical vendors; fourth-party map maintained internally.
CCO · CISO
~
Financial viability
Public-filing review captured for critical vendors; supplier covenant clause drafted.
CFO · CCO
✗
Exit assistance / transition
Exit assistance clauses outstanding for hosting + monitoring; blocks critical-outsourcing supervisor-notice readiness.
Legal Counsel · CISO · COO
Exit & substitution plan

Trigger · replacement · data return · transition · board/regulator evidence

Critical-outsourcing exit plans must carry tested fallback evidence; board/regulator evidence output tied to the Stakeholder Rooms and Regulatory Escalation centres.

Vendor · service
Trigger · replacement · data return · transition · evidence output
Owner
State
Identity provider
Trigger: vendor failure · regulatory direction · concentration threshold. Replacement: alternate OIDC IdP. Data return: session keys + token store. Transition: 30d window. Evidence: pack/policy-attestation · audit chain.
CISO · IAM
Exit Plan Required
Hosting / deployment
Trigger: regional outage · vendor solvency · supervisor direction. Replacement: alternate region + provider candidates. Data return: hash continuity check. Transition: 14d window. Evidence: pack/incident · runbook hash.
CISO · COO
Exit Plan Required
Monitoring / SIEM
Trigger: SIEM regression · vendor failure. Replacement: alternative SIEM. Data return: full log export with hash chain. Transition: 30d. Evidence: pack/audit-log · SIEM forwarding evidence.
CISO
Exit Plan Required
Email / notifications
Trigger: deliverability degradation · vendor failure. Replacement: alternate provider. Data return: contact lists + headers. Transition: 7d. Evidence: pack/policy-attestation · manual fallback rehearsal.
Founder Admin · CCO
Conditional
Connected tooling
Trigger: vendor scope change · counsel decision. Replacement: alternative tooling. Data return: drafting metadata. Transition: 14d. Evidence: pack/policy-attestation.
Founder Admin
Conditional
Contract controls panel

Ten contract artefacts with current state

Counsel review required for any critical-outsourcing scope; aligned with Data Governance vendor controls and Commercial Readiness contract panel.

Artefact
Detail
State
MSA / Master Services Agreement
Critical-vendor template drafted; per-vendor execution outstanding for hosting + monitoring.
Drafting
DPA · Data Processing Agreement
Drafted for hosting · monitoring · email · tooling · KYC partner; counsel review outstanding.
Counsel Review
SCC / transfer mechanism
SCC + IDTA + supplementary measures drafted; counsel review pending per Data Governance transfer matrix.
Counsel Review
Audit rights
Right-to-audit and supervisor right-of-access clauses drafted; counsel review on critical outsourcing pending.
Counsel Review
Breach notice
24h vendor-to-BLACKSWAN notice drafted; counsel review on threshold for sub-processors pending.
Counsel Review
Subcontractor notice
Subcontractor / fourth-party change notice drafted with 30d window.
Drafting
Termination assistance
Exit assistance clauses required for critical outsourcing; outstanding for hosting + monitoring.
Blocking
Confidentiality / MNPI
Confidentiality + MNPI flow-down drafted; tied to Stakeholder Rooms recipient ack.
Approved Internal
Liability · indemnity
Per-vendor caps and carve-outs drafted; insurance evidence on file for counsel + auditor.
Drafting
Service credits
Service credit / SLA breach remedies drafted; tied to SLA / SLO panel above.
Drafting
Third-party incident linkage

Where vendor / outsourcing events surface in the rest of the OS

A vendor event never lives alone — it triggers monitoring, escalation, data-governance, release-control, and stakeholder-room workflows.

Vendor exception register

Open items blocking third-party risk progression

Closure requires owner action and a Pack Registry hash. Each row carries trigger, scope, and audit-event tag.

Item
Detail · audit event
Owner
State
Missing DPA
Email / notifications + monitoring + tooling DPAs drafted but counsel-review pending. VR-EXC-DPA
Legal Counsel · CCO
Counsel Review
Stale review
Email / notifications vendor 60d review approaches; refresh required ahead of next cycle. VR-EXC-REVIEW
Founder Admin · CCO
Amber
Critical vendor — no exit plan
Hosting + monitoring exit assistance and tested fallback outstanding; blocks supervisor-notice readiness. VR-EXC-EXIT
CISO · COO · Legal Counsel
Red
Concentration threshold breach
Hosting + monitoring single-region; concentration score 4–5; mitigation tracked. VR-EXC-CONC
CISO · COO
Watch
SLA breach
No live breach today; tabletop SLA breach captured for evidence. VR-EXC-SLA
CISO · COO
Tested
Subcontractor pending approval
Tooling sub-processor disclosure outstanding; transfer review pending in Data Governance. VR-EXC-SUB
Founder Admin · CCO
Amber
Unsupported jurisdiction
Tooling sub-processor MAS support outstanding; route flagged not-in-scope until counsel review. VR-EXC-JURIS
Founder Admin · Legal Counsel
Not-in-scope
Missing audit rights
Supervisor right-of-access clauses outstanding for critical outsourcing (hosting + monitoring). VR-EXC-AUDIT
Legal Counsel · CCO
Red
Audit trail · evidence preservation

Every vendor state change is timestamped, actor-named, evidence-hashed

Sample staging entries. Production audit-event capture still requires SIEM-forwarded audit events under Microsoft Entra OIDC.

Timestamp · event
Actor
Vendor · action · evidence · limitation · next step
Hash
2026-05-15 06:00Z
VR-INVENTORY
CISO · CCO
Vendor inventory v1.0 published · 10 vendors mapped · criticality, jurisdiction, contract status captured.
hash:9a2c…
2026-05-15 07:30Z
VR-CRITICALITY
CISO
3 critical-outsourcing vendors identified (identity provider · hosting · monitoring) · exit plan required flag set.
hash:7e11…
2026-05-15 09:00Z
VR-CONCENTRATION
CISO · COO
Concentration watch opened on hosting + monitoring (single-region) · mitigation owner named.
hash:bc40…
2026-05-15 10:30Z
VR-COUNSEL
Legal Counsel · CCO
Critical-outsourcing supervisor-notice threshold review opened · ADGM/FSRA · UK · MAS · MiFID/MiFID II.
hash:5d8f…
2026-05-15 12:15Z
VR-SLA-TABLETOP
CISO · COO
SLA breach tabletop exercised for hosting + monitoring · escalation to Production Monitoring rehearsed.
hash:e5d0…
2026-05-15 14:00Z
VR-DPA
Legal Counsel · CCO
DPA drafts published for hosting · monitoring · email · tooling · KYC partner · counsel review pending.
hash:c2e9…
2026-05-15 14:50Z
VR-EXIT-REQUIRED
CISO · COO · Legal Counsel
Exit assistance + tested fallback outstanding for hosting + monitoring · blocks critical-outsourcing supervisor-notice readiness.
hash:1f73…
2026-05-15 15:30Z
VR-SUBMAP
CISO · CCO
Subcontractor / fourth-party map published for identity provider · hosting · email · monitoring · tooling · payment.
hash:38ab…
2026-05-15 16:00Z
VR-DUE-DILIGENCE
CISO · CFO sponsor · Legal Counsel
Due diligence checklist published · 10 items · exit assistance flagged blocking for critical outsourcing.
hash:7c92…
2026-05-15 17:14Z
VR-ATTEST
CISO · Founder Admin
Ongoing attestation cadence published · 60d critical · 90d high · review owner named.
hash:0b6d…

Assumptions and limitations

This Vendor, Outsourcing & Third-Party Risk Centre is internal third-party risk readiness workflow. All data shown is staging / simulated vendor data. It is explicitly not:

All regulated activity on the platform remains simulated, partner-routed, locked, or production-regulated as defined in the OS Architecture and Completeness Command Centre. Production cutover still requires Microsoft Entra OIDC with Conditional Access, RBAC/ABAC, server-side session issuance, and SIEM-forwarded audit events. Items shown are plausible sample states consistent with the existing Launch Readiness Command Centre, Production Monitoring & Incident Command Centre, Data Governance Centre, Approval & Sign-Off Workflow, and Release Control & Rollback Centre.