Skip to content

Repository files navigation

Vendor Risk Management Project

Overview

This project simulates a Third-Party Risk Management (TPRM) assessment conducted for a fintech company evaluating a new vendor. The project demonstrates the vendor risk management lifecycle including risk identification, due diligence, control analysis, and remediation planning.

The assessment evaluates CloudDocs Inc., a cloud-based document storage provider, which stores sensitive financial documentation and personally identifiable information (PII) for SentinelPay.

Company Scenario

Company: SentinelPay
Industry: Financial Technology (Fintech)
Program: Third-Party Risk Management (TPRM)

SentinelPay uses third-party vendors to support business operations. Vendors that access sensitive data must undergo a formal risk assessment before onboarding.

Vendor Overview

Vendor: CloudDocs Inc.
Service: Cloud-based document storage and management platform

CloudDocs provides a platform for storing and managing digital documents. SentinelPay plans to use the service to store:

  • Loan agreements
  • Identity verification documents
  • Financial records

Because these documents contain sensitive information, the vendor introduces potential risks related to security, privacy, and operational availability.

Risk Assessment Summary

Risk CategoryRating
Inherent RiskHigh
Control EffectivenessModerate
Residual RiskMedium

Project Files

FileDescription
README.mdProject overview
Risk Register.xlsxTracks identified risks and remediation status
Risk Remediation Plan.pdfRemediation actions for identified risks
Risk Scoring Categories.xlsxDefines vendor risk scoring factors
SOC2 Review.pdfAnalysis of the vendor’s SOC 2 report
Vendor Asessment Scenario.pdfDescription of the vendor assessment scenario
Vendor Due Diligence Checklist.pdfVendor onboarding due diligence checklist
Vendor Risk Assessment CloudDocs Inc.pdfFull vendor risk assessment report
Vendor Risk Scoring.xlsxVendor risk scoring model
Vendor Security Questionnaire.pdfVendor security questionnaire

Skills Demonstrated

  • Vendor risk assessment
  • SOC 2 control review
  • Vendor risk scoring models
  • Risk register management
  • Vendor due diligence processes
  • Risk remediation planning

Tools Used

  • Microsoft Excel
  • Google Docs
  • Risk assessment methodologies

About

Third-Party Vendor Risk Assessment project demonstrating TPRM lifecycle including vendor risk scoring, SOC 2 review, due diligence, and remediation planning.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors