3 controls
As of 9 Oct 2026
As of 9 Oct 2026
Filtered byDomain: Third-Party Risk ✕
| Control | Name | Domain | Applications | Q3 test | Open findings |
|---|---|---|---|---|---|
| VEN-01 | Critical third parties are risk-assessed before onboarding and annually | Third-Party Risk | PayGate Payment Gateway, Salesforce (Sales + Financial Services Cloud) | Fail | 1 |
| VEN-02 | Provider contracts include data protection and RBI audit clauses | Third-Party Risk | Salesforce (Sales + Financial Services Cloud) | Not tested | 1 |
| VEN-03 | Supplier security incidents are assessed for impact and tracked | Third-Party Risk | PayGate Payment Gateway, Meridian Customer Portal | Fail | 1 |