Vendor due diligence
- Assessment of new vendors before contracting: legal, financial, security and concentration risk.
- Questionnaires and document requests sent and tracked on the platform.
- A risk rating and a short memo for management.
Third-party risk assessments, the register of outsourced activities and reporting to the National Bank of Serbia, run as an ongoing service for regulated financial institutions.
Banks, payment institutions and e-money institutions are responsible for the services they outsource as if they performed them themselves.
That means assessing every significant vendor before the contract is signed, monitoring it while the service runs, and notifying and reporting to the National Bank of Serbia where the regulations require it.
We run that cycle for you. Our lawyers assess vendors and review outsourcing contracts, and our platform keeps the vendor register, the assessments and the reporting calendar in one place, so the documentation is ready when the NBS asks for it. For groups in the EU, the same work covers the DORA requirements on ICT third-party risk.
Six workstreams that make up the monthly service.
What changes when third-party risk runs as a monthly service.
Assessments, contracts and the register are documented and current when the NBS asks.
Notifications and reports tracked on one calendar, with reminders before each deadline.
The same criteria and templates for every assessment, regardless of who performs it.
A specialist compliance function without adding headcount.
NBS regulations and DORA covered together for groups with EU entities.
Priced on the number of vendors and the reporting load, known in advance.
Four steps, from the first inventory to ongoing work.
We list your vendors and outsourced activities, identify critical and important functions and check what documentation exists.
We compare contracts and assessments with the regulatory requirements and set a remediation plan by priority.
New vendors are assessed before contracting and existing ones reassessed on schedule. Contracts are reviewed as they come in.
Notifications and reports to the NBS prepared on time, and a quarterly report to management on vendor risk.
The register and the reporting calendar live on the platform our team uses to run the service.
Each new vendor is screened against the NBS outsourcing criteria and added to the register of outsourced activities.
Every step of the service is carried out by our lawyers in Whisperly, software we built for this purpose.
Every review and decision is made by a lawyer; the software supports the work, it does not replace it.
Automation of routine steps makes the process up to 10 times faster than a conventional way of working.
The vendor register, deadlines and reporting are kept in one place.
Institutions supervised by the National Bank of Serbia, and their EU group entities.
Outsourcing and ICT third-party risk under NBS regulations.
Payment service providers that rely on technology and processing vendors.
Institutions whose core services run on outsourced platforms.
Other NBS-supervised entities with outsourcing obligations.
One agreement per function, or several functions combined under one.
Priced on the scope and volume agreed at onboarding, so the cost is known in advance.
The agreement lists what is included each month and how much of it.
Turnaround for each type of request is set in the agreement and tracked on the platform.
A monthly report on volumes and open items, and a quarterly review with management.
Work outside the agreed scope is quoted separately before it starts.
What clients ask before they subscribe.
No. Your compliance and risk teams stay responsible. We do the assessments, contracts and reporting work and give them the results.
Yes, for groups with EU entities. The register, assessments and contracts can be prepared to meet DORA and NBS requirements together.
Based on the number of vendors, how many are critical and the reporting load, agreed after the initial inventory.
Yes. Vendors receive a link, upload documents and answer questions, and we track what is still missing.
Advice on incident classification and reporting can be added to the scope, together with our Information Security team.
Combine vendor assessment with other functions under one agreement.
Tell us what kind of institution you are and roughly how many vendors you work with, and we will propose a scope and a monthly fee.
Contact usRecent writing on ICT risk, information security and regulation.
Legal developments in Serbia and the EU, each with the step it asks of your business.
Two emails a month. Unsubscribe any time.