Operational · Technology · Third-Party Risk
Risk management built for how companies actually operate.
Two Lines Risk helps organizations identify, assess, monitor and mitigate operational, technology, cyber and third-party risk — combining risk expertise with deep technical understanding and hands-on execution.
Built for regulated environments
- Banking
- Payments
- Insurance
- Asset management
- Fintech
- Regulated technology
Where ownership meets oversight.
Risk is owned by the teams doing the work and overseen by the functions that set the standard. Most risk programs fail in the space between those two responsibilities — not inside either one of them.
The teams that take risk as part of doing the work — and that have to absorb the consequences when a control fails.
- Business
- Operations
- Technology
- Product
- Procurement
- Fragmented information
Vendor facts live in procurement, security and finance systems.
- Manual assessments
Questionnaires re-sent, re-answered and re-read every cycle.
- Unclear ownership
Findings raised against a function rather than a named owner.
- Remediation delays
Actions agreed in a forum, then tracked in nobody's backlog.
- Duplicated controls
The same control tested three times for three frameworks.
- Vendor exposure
Concentration and fourth parties visible only after an incident.
The functions that set the framework, challenge decisions, test controls and hold the aggregate view of exposure.
- Operational Risk
- Information Security
- Compliance
- Third-Party Risk
- Technology Risk
Both lines are doing their job. They are simply working from different systems, different definitions and different versions of the truth — and the distance between them is where exposure accumulates.
Three capabilities, one operating picture.
Each engagement is scoped to a real decision: whether to onboard a vendor, whether a control can be relied on, whether a service can absorb the failure of the thing beneath it.
Capabilities are usually combined. A third-party program without control testing produces paperwork; control testing without an inventory produces coverage you cannot defend.
Your risk perimeter extends far beyond your company.
Cloud providers, SaaS platforms, payment processors, data vendors, infrastructure operators, consultants — a modern regulated business runs on hundreds or thousands of external relationships, and the ones that matter most are rarely the largest contracts.
Six questions a third-party program has to answer at any moment.
Not once a year, and not only for the vendors that happened to be in scope. We build programs around the answers, then keep the answers current.
Explore Third-Party Risk- 01Who do you actually depend on to deliver a critical service?
- 02What risk does each relationship introduce, and to which process?
- 03Are the controls you rely on operating, or merely contracted?
- 04What needs remediation, by whom, and by when?
- 05Where is concentration building — by provider, region or platform?
- 06What changed since the assessment was signed off?
Risk changes every day. Your assessment process should too.
An annual questionnaire tells you what a vendor believed about itself on the day it was completed. Everything material — a certificate lapsing, a new subprocessor, an SLA trend, a disclosed vulnerability — happens in between.
Traditional risk management
Accurate on the day it was signed. Increasingly theoretical after that.
- Annual questionnaire
- Spreadsheet of record
- Static risk score
- PDF evidence attached to email
- Periodic review, once a year
- Exposure known at a point in time
Continuous risk management
The picture updates when your exposure updates, not when the calendar does.
- Risk signals as they occur
- Control status monitoring
- Vendor and subprocessor changes
- Evidence with an expiry date
- Live remediation tracking
- Exposure known today
Thirty days in the life of one Tier 1 vendor
Move from periodic assessments to continuous risk awareness.
- D+0ISO 27001 certificate expires+6
Payments processor · Tier 1 · evidence now stale
- D+3Critical vulnerability disclosed+11
Affects the data platform used by two Tier 1 vendors
- D+9Vendor adds a subprocessor+7
New fourth party in a region outside the approved scope
- D+14SLA breach recorded+5
Third consecutive month below the contractual threshold
- D+21Control evidence goes out of date+3
Access recertification not produced for the current quarter
- D+27Remediation validated-14
Vendor closes two high findings · re-tested and accepted
Aggregate exposure index · Tier 1 population
- Signals received
- 0
- Requiring action
- 0
Illustrative. The profile moves as evidence, findings and vendor changes arrive.
Risk teams shouldn’t need a translator to understand technology.
Technology risk requires understanding how systems are actually designed, deployed, accessed, monitored and operated. Select a control category to see where it has to hold across the estate.
- 01UsersCustomers, employees, machine identities
- 02ApplicationWeb, mobile and internal front ends
- 03APIsPublic, partner and internal service interfaces
- 04CloudAccounts, networks, workloads, orchestration
- 05DatabaseTransactional stores, warehouses, backups
- 06Third partiesProcessors, SaaS, infrastructure providers
IAM: Who can reach production, through which identity, and what removes that access when the role changes?
We read the artefact, not the summary
Cloud configuration, IAM policy, network design, pipeline definitions, architecture decision records — the places where a control either exists or does not.
Findings written for the team that fixes them
An engineering audience gets the specific condition and the change required. The risk committee gets the exposure and the decision. Same finding, two registers.
Assessment that survives an engineer's challenge
If a recommendation cannot withstand a technical objection, it will not be implemented. We test our own conclusions before they reach a report.
From strategy to execution.
Three ways to work with us. Most clients move between them — a framework designed in advisory becomes an assessment programme, and the steady-state runs as risk operations.
Advisory
Design the operating model.
Risk taxonomies, frameworks, policies, methodologies, tiering models, governance forums and target operating models — specified in enough detail that they can be run the day after we hand them over.
- Risk & control framework
- TPRM methodology and tiering model
- Governance and escalation design
- Target operating model & roadmap
Assessment
Establish the facts.
Focused, time-boxed assessments of a vendor, a platform, a process or a control set. Findings are written to be actionable by the team that owns the remediation, not only by the risk committee.
- Vendor & critical supplier assessments
- Technology and cloud risk reviews
- Control design & effectiveness testing
- Gap analysis against target frameworks
Risk Operations
Run it with us.
A named team operating defined parts of your risk program under your governance: assessment queues, evidence review, reassessment cycles, remediation follow-up and reporting.
- Managed assessment queue
- Evidence and questionnaire review
- Remediation tracking & escalation
- Recurring risk & board reporting
A vendor lifecycle, with ownership on every step.
Programs stall where a step has no owner. This is the third-party lifecycle we implement most often — each stage annotated with the line accountable for it.
- 1st Line
- 2nd Line
- Both lines
- 01
Vendor onboarded
Business need, data scope and process dependency captured at intake.
- 02
Criticality assessment
Impact on critical services, data classification and substitutability.
- 03
Risk tier
Tier drives assessment depth, evidence set and reassessment frequency.
- 04
Due diligence
Security, resilience, privacy, financial and concentration review.
- 05
Evidence review
Certifications, reports and configuration read against the control set.
- 06
Findings
Rated against defined criteria, with a named owner on the first line.
- 07
Remediation
Actions, dates and compensating controls tracked to closure.
- 08
Approval
Residual risk accepted at the right level, with the rationale recorded.
- 09
Continuous monitoring
Signals, expiries and vendor changes update the profile between cycles.
- 10
Reassessment
Triggered by tier, by material change, or by the risk picture itself.
Step 10 returns to step 02 — reassessment is a trigger, not a date in a calendar.
What better risk operations look like.
Not maturity levels. The specific, observable differences between a risk program that is documented and one that is operating.
- Onboarding
Faster vendor onboarding
Tiering at intake means low-risk suppliers stop queueing behind Tier 1 reviews.
- Ownership
Clear risk ownership
Every risk, control and finding resolves to a named accountable owner.
- Method
Consistent assessments
The same criteria applied by every analyst, so results can be compared over time.
- Governance
Defensible decisions
Acceptances recorded with rationale, evidence, expiry and approving authority.
- Effort
Reduced manual work
Evidence reused across frameworks instead of recollected per audit.
- Evidence
Centralised evidence
One location, with freshness and coverage visible before an auditor asks.
- Delivery
Visible remediation
Open findings tracked to a date, an owner and a validated closure.
- Assurance
Audit-ready controls
Policy-to-control traceability maintained continuously, not reconstructed.
- Coverage
Continuous vendor visibility
Material vendor changes surface between assessment cycles, not after them.
- Reporting
Better executive reporting
Exposure, trend and concentration expressed in terms an executive committee can act on.
One view an executive committee can act on.
Risk reporting fails when it presents activity instead of exposure. The numbers a board needs are few, comparable across quarters, and traceable back to the assessment that produced them.
Aggregate exposure index
−18% · 12 monthsWeighted by criticality, control effectiveness and open findings
Exposure by risk category
Share of open exposure · movement vs. prior quarter
- Cybersecurity31 open▼
- Operational24 open—
- Resilience19 open▲
- Privacy13 open▼
- Compliance11 open—
- Concentration7 open▲
Recent signals
Streaming| Vendor | Tier | Signal | Severity | Age |
|---|---|---|---|---|
| Core payment processor | Tier 1 | SOC 2 report expires in 21 days | Medium | 2h |
| Cloud data platform | Tier 1 | New subprocessor added outside approved region | High | 6h |
| KYC data provider | Tier 2 | Availability below contractual SLA, third month | Medium | 1d |
| Managed SOC | Tier 1 | Access recertification evidence not provided | Low | 3d |
Risk management built by people who understand both risk and technology.
Two Lines Risk brings together professionals from operational risk, information security, technology and software engineering. We translate frameworks into operating processes, controls into evidence, findings into remediation, and risk information into decisions someone is willing to sign.
Risk expertise
Operational, technology, third-party, cyber and compliance risk — practised inside regulated institutions, not only described in a methodology.
Technical depth
APIs, cloud accounts, network and identity architecture, CI/CD, data flows and application design read directly, without an intermediary.
Operational execution
We run assessments, analyse evidence, work with vendors and follow remediation to closure. The framework is the beginning of the engagement, not the end.
Continuous visibility
Programs designed to be measured: coverage, freshness, throughput and exposure, reported on a cadence your governance forums can rely on.
Frameworks we work against
- ISO 27001
- ISO 31000
- NIST CSF
- NIST 800-53
- SOC 2
- COBIT
- COSO
- DORA
- PCI DSS
- GDPR
Referenced for control mapping and readiness work. No affiliation with, or endorsement by, the issuing bodies is implied.
Make risk part of how your organization operates.
Whether you’re building a risk program, scaling third-party risk management, preparing for audit, or improving technology-risk visibility — Two Lines Risk can help.
- Building a risk program from a standing start
- Scaling third-party risk beyond a spreadsheet
- Preparing for an audit or a regulatory review
- Improving technology-risk visibility