Managed ServicesVendor Assessment & NBS Reporting
Managed Services

Vendor Assessment & NBS Reporting

Third-party risk assessments, the register of outsourced activities and reporting to the National Bank of Serbia, run as an ongoing service for regulated financial institutions.

Banks, payment institutions and e-money institutions are responsible for the services they outsource as if they performed them themselves.

That means assessing every significant vendor before the contract is signed, monitoring it while the service runs, and notifying and reporting to the National Bank of Serbia where the regulations require it.

We run that cycle for you. Our lawyers assess vendors and review outsourcing contracts, and our platform keeps the vendor register, the assessments and the reporting calendar in one place, so the documentation is ready when the NBS asks for it. For groups in the EU, the same work covers the DORA requirements on ICT third-party risk.

Included each month

What the service covers

Six workstreams that make up the monthly service.

01

Vendor due diligence

  • Assessment of new vendors before contracting: legal, financial, security and concentration risk.
  • Questionnaires and document requests sent and tracked on the platform.
  • A risk rating and a short memo for management.
02

Outsourcing contracts

  • Review of outsourcing and ICT contracts against regulatory requirements.
  • Audit, access, subcontracting, exit and data clauses.
  • Remediation plans for existing contracts that fall short.
03

Register of outsourced activities

  • A complete register of outsourced activities and ICT services.
  • Critical and important functions identified and documented.
  • Kept current as vendors and contracts change.
04

Notifications and reporting to the NBS

  • Notifications to the NBS before outsourcing where required.
  • Periodic reports on outsourced activities.
  • A reporting calendar with every deadline in one place.
05

Ongoing vendor monitoring

  • Periodic reassessment of vendors by risk level.
  • Tracking of incidents, SLA breaches and changes at vendors.
  • Exit plans for critical vendors.
06

Supervision and audit

  • Preparation for NBS inspections and internal audit.
  • Answers to supervisory requests.
  • Reports to management and the board.
Benefits

Why outsource it as a service

What changes when third-party risk runs as a monthly service.

Ready for supervision

Assessments, contracts and the register are documented and current when the NBS asks.

No missed deadlines

Notifications and reports tracked on one calendar, with reminders before each deadline.

One method for all vendors

The same criteria and templates for every assessment, regardless of who performs it.

No extra hire

A specialist compliance function without adding headcount.

Serbian and EU rules

NBS regulations and DORA covered together for groups with EU entities.

Fixed monthly fee

Priced on the number of vendors and the reporting load, known in advance.

How it works

From vendor inventory to regular reporting

Four steps, from the first inventory to ongoing work.

01

Inventory

We list your vendors and outsourced activities, identify critical and important functions and check what documentation exists.

02

Gap analysis

We compare contracts and assessments with the regulatory requirements and set a remediation plan by priority.

03

Ongoing assessments

New vendors are assessed before contracting and existing ones reassessed on schedule. Contracts are reviewed as they come in.

04

Reporting

Notifications and reports to the NBS prepared on time, and a quarterly report to management on vendor risk.

Platform

Every vendor, assessment and deadline in one place

The register and the reporting calendar live on the platform our team uses to run the service.

Each new vendor is screened against the NBS outsourcing criteria and added to the register of outsourced activities.

Software

Our lawyers work through our own software, Whisperly

Every step of the service is carried out by our lawyers in Whisperly, software we built for this purpose.

Lawyers first

Every review and decision is made by a lawyer; the software supports the work, it does not replace it.

Up to 10 times faster

Automation of routine steps makes the process up to 10 times faster than a conventional way of working.

Everything in one place

The vendor register, deadlines and reporting are kept in one place.

Who it's for

For regulated financial institutions

Institutions supervised by the National Bank of Serbia, and their EU group entities.

Banks

Outsourcing and ICT third-party risk under NBS regulations.

Payment institutions

Payment service providers that rely on technology and processing vendors.

E-money institutions

Institutions whose core services run on outsourced platforms.

Insurers and leasing companies

Other NBS-supervised entities with outsourcing obligations.

Model

How the subscription works

One agreement per function, or several functions combined under one.

Fixed monthly fee

Priced on the scope and volume agreed at onboarding, so the cost is known in advance.

Defined scope

The agreement lists what is included each month and how much of it.

Agreed response times

Turnaround for each type of request is set in the agreement and tracked on the platform.

Regular reporting

A monthly report on volumes and open items, and a quarterly review with management.

Work outside the agreed scope is quoted separately before it starts.

FAQ

Most common questions

What clients ask before they subscribe.

Do you replace our compliance function?

No. Your compliance and risk teams stay responsible. We do the assessments, contracts and reporting work and give them the results.

Does this cover DORA?

Yes, for groups with EU entities. The register, assessments and contracts can be prepared to meet DORA and NBS requirements together.

How is the monthly fee calculated?

Based on the number of vendors, how many are critical and the reporting load, agreed after the initial inventory.

Can vendors fill in questionnaires on the platform?

Yes. Vendors receive a link, upload documents and answer questions, and we track what is still missing.

Do you also handle ICT incident reporting?

Advice on incident classification and reporting can be added to the scope, together with our Information Security team.

Related

Other managed services

Combine vendor assessment with other functions under one agreement.

Next step

Let’s scope your vendor assessment

Tell us what kind of institution you are and roughly how many vendors you work with, and we will propose a scope and a monthly fee.

Contact us
Newsletter

Learn legal updates, and what to do about them

Legal developments in Serbia and the EU, each with the step it asks of your business.

Sign up

Two emails a month. Unsubscribe any time.