This Centre is internal third-party risk readiness workflow. Numbers below are staging / simulated vendor data. Nothing here is legal advice, outsourcing-compliance certification, regulatory approval, an audit opinion, or authorization for external launch. Outsourcing notice obligations to supervisors and exit-plan adequacy require external counsel confirmation against the rule set in force per jurisdiction.
Domains map back to Launch Readiness Operational Resilience gate, Data Governance vendor controls, and the Outsourcing Concentration evidence pack.
Sample staging rows aligned to current OS posture. Critical vendors carry exit-plan-required flags pending fallback evidence; concentration-watch rows are tracked on the panel below.
Classification is internal readiness only; supervisor-notice threshold determinations require external counsel confirmation against the rule set in force.
| Service | ADGM / FSRA | UK FCA | MAS | MiFID / MiFID II | Owner · Note |
|---|---|---|---|---|---|
| Identity provider | Counsel Review | Counsel Review | Counsel Review | Counsel Review | Critical · supervisor-notice threshold to confirm pre-cutover. |
| Hosting / deployment | Counsel Review | Counsel Review | Counsel Review | Counsel Review | Critical · single-region; concentration watch. |
| Monitoring / SIEM | Counsel Review | Counsel Review | Counsel Review | Counsel Review | Critical · audit-chain integrity dependency. |
| Email / notifications | Drafted | Counsel Review | Counsel Review | Counsel Review | Medium · manual fallback available. |
| Connected tooling | Drafted | Counsel Review | Not-in-scope | Counsel Review | Medium · drafting layer; alternative tools identified. |
| Legal counsel | Drafted | Drafted | Drafted | Drafted | Professional services; not classified as outsourcing. |
| Auditor / assurance | Counsel Review | Counsel Review | Not-in-scope | Counsel Review | Independent assurance; pre-engagement. |
| Payment / billing provider | Blocking | Blocking | Blocking | Blocking | Not selected today; required before any external billing. |
| GitHub · repository | Drafted | Drafted | Drafted | Drafted | Code custodian; OAuth restrictions enforced. |
| Data storage | Not-in-scope | Not-in-scope | Not-in-scope | Not-in-scope | Internal staging only; production storage vendor TBD. |
Flow-down obligations and notification triggers are captured here; counsel review pending for supervisor-notice scope.
Staging-only readings. Breach watch ties into Production Monitoring and Regulatory Escalation for any critical-vendor degradation.
Concentration score is internal (1 = isolated, 5 = single-provider critical). Mitigation owner is named and tracked.
Closure requires reviewer pass and a Pack Registry hash for the named vendor. Sample posture aligned to current critical-vendor inventory.
Critical-outsourcing exit plans must carry tested fallback evidence; board/regulator evidence output tied to the Stakeholder Rooms and Regulatory Escalation centres.
Counsel review required for any critical-outsourcing scope; aligned with Data Governance vendor controls and Commercial Readiness contract panel.
A vendor event never lives alone — it triggers monitoring, escalation, data-governance, release-control, and stakeholder-room workflows.
NR-DETECT for vendor incidents.Closure requires owner action and a Pack Registry hash. Each row carries trigger, scope, and audit-event tag.
Sample staging entries. Production audit-event capture still requires SIEM-forwarded audit events under Microsoft Entra OIDC.
This Vendor, Outsourcing & Third-Party Risk Centre is internal third-party risk readiness workflow. All data shown is staging / simulated vendor data. It is explicitly not:
All regulated activity on the platform remains simulated, partner-routed, locked, or production-regulated as defined in the OS Architecture and Completeness Command Centre. Production cutover still requires Microsoft Entra OIDC with Conditional Access, RBAC/ABAC, server-side session issuance, and SIEM-forwarded audit events. Items shown are plausible sample states consistent with the existing Launch Readiness Command Centre, Production Monitoring & Incident Command Centre, Data Governance Centre, Approval & Sign-Off Workflow, and Release Control & Rollback Centre.