Skip to content
Two LinesRisk

Operational · Technology · Third-Party Risk

Risk management built for how companies actually operate.

Two Lines Risk helps organizations identify, assess, monitor and mitigate operational, technology, cyber and third-party risk — combining risk expertise with deep technical understanding and hands-on execution.

Built for regulated environments

  • Banking
  • Payments
  • Insurance
  • Asset management
  • Fintech
  • Regulated technology
BusinessTechnologyVendorsOperationsControlsDataRisk Visibility1st Line — Own & Manage2nd Line — Challenge & Oversee
The name01

Where ownership meets oversight.

Risk is owned by the teams doing the work and overseen by the functions that set the standard. Most risk programs fail in the space between those two responsibilities — not inside either one of them.

1st LineOwn & Manage

The teams that take risk as part of doing the work — and that have to absorb the consequences when a control fails.

  • Business
  • Operations
  • Technology
  • Product
  • Procurement
  • Fragmented information

    Vendor facts live in procurement, security and finance systems.

  • Manual assessments

    Questionnaires re-sent, re-answered and re-read every cycle.

  • Unclear ownership

    Findings raised against a function rather than a named owner.

  • Remediation delays

    Actions agreed in a forum, then tracked in nobody's backlog.

  • Duplicated controls

    The same control tested three times for three frameworks.

  • Vendor exposure

    Concentration and fourth parties visible only after an incident.

Two Lines Risk
2nd LineChallenge & Oversee

The functions that set the framework, challenge decisions, test controls and hold the aggregate view of exposure.

  • Operational Risk
  • Information Security
  • Compliance
  • Third-Party Risk
  • Technology Risk

Both lines are doing their job. They are simply working from different systems, different definitions and different versions of the truth — and the distance between them is where exposure accumulates.

Third-party risk03

Your risk perimeter extends far beyond your company.

Cloud providers, SaaS platforms, payment processors, data vendors, infrastructure operators, consultants — a modern regulated business runs on hundreds or thousands of external relationships, and the ones that matter most are rarely the largest contracts.

Yourorganization

Six questions a third-party program has to answer at any moment.

Not once a year, and not only for the vendors that happened to be in scope. We build programs around the answers, then keep the answers current.

Explore Third-Party Risk
  1. 01Who do you actually depend on to deliver a critical service?
  2. 02What risk does each relationship introduce, and to which process?
  3. 03Are the controls you rely on operating, or merely contracted?
  4. 04What needs remediation, by whom, and by when?
  5. 05Where is concentration building — by provider, region or platform?
  6. 06What changed since the assessment was signed off?
Continuous risk04

Risk changes every day. Your assessment process should too.

An annual questionnaire tells you what a vendor believed about itself on the day it was completed. Everything material — a certificate lapsing, a new subprocessor, an SLA trend, a disclosed vulnerability — happens in between.

Point in time

Traditional risk management

Accurate on the day it was signed. Increasingly theoretical after that.

  • Annual questionnaire
  • Spreadsheet of record
  • Static risk score
  • PDF evidence attached to email
  • Periodic review, once a year
  • Exposure known at a point in time
Continuous

Continuous risk management

The picture updates when your exposure updates, not when the calendar does.

  • Risk signals as they occur
  • Control status monitoring
  • Vendor and subprocessor changes
  • Evidence with an expiry date
  • Live remediation tracking
  • Exposure known today

Thirty days in the life of one Tier 1 vendor

Move from periodic assessments to continuous risk awareness.

  1. D+0ISO 27001 certificate expires+6

    Payments processor · Tier 1 · evidence now stale

  2. D+3Critical vulnerability disclosed+11

    Affects the data platform used by two Tier 1 vendors

  3. D+9Vendor adds a subprocessor+7

    New fourth party in a region outside the approved scope

  4. D+14SLA breach recorded+5

    Third consecutive month below the contractual threshold

  5. D+21Control evidence goes out of date+3

    Access recertification not produced for the current quarter

  6. D+27Remediation validated-14

    Vendor closes two high findings · re-tested and accepted

Vendor risk profileLive
580 vs. baseline

Aggregate exposure index · Tier 1 population

Signals received
0
Requiring action
0

Illustrative. The profile moves as evidence, findings and vendor changes arrive.

Technology & risk05

Risk teams shouldn’t need a translator to understand technology.

Technology risk requires understanding how systems are actually designed, deployed, accessed, monitored and operated. Select a control category to see where it has to hold across the estate.

Control overlay
  1. 01UsersCustomers, employees, machine identities
  2. 02ApplicationWeb, mobile and internal front ends
  3. 03APIsPublic, partner and internal service interfaces
  4. 04CloudAccounts, networks, workloads, orchestration
  5. 05DatabaseTransactional stores, warehouses, backups
  6. 06Third partiesProcessors, SaaS, infrastructure providers

IAM: Who can reach production, through which identity, and what removes that access when the role changes?

01

We read the artefact, not the summary

Cloud configuration, IAM policy, network design, pipeline definitions, architecture decision records — the places where a control either exists or does not.

02

Findings written for the team that fixes them

An engineering audience gets the specific condition and the change required. The risk committee gets the exposure and the decision. Same finding, two registers.

03

Assessment that survives an engineer's challenge

If a recommendation cannot withstand a technical objection, it will not be implemented. We test our own conclusions before they reach a report.

Engagement model06

From strategy to execution.

Three ways to work with us. Most clients move between them — a framework designed in advisory becomes an assessment programme, and the steady-state runs as risk operations.

01

Advisory

Design the operating model.

Risk taxonomies, frameworks, policies, methodologies, tiering models, governance forums and target operating models — specified in enough detail that they can be run the day after we hand them over.

  • Risk & control framework
  • TPRM methodology and tiering model
  • Governance and escalation design
  • Target operating model & roadmap
02

Assessment

Establish the facts.

Focused, time-boxed assessments of a vendor, a platform, a process or a control set. Findings are written to be actionable by the team that owns the remediation, not only by the risk committee.

  • Vendor & critical supplier assessments
  • Technology and cloud risk reviews
  • Control design & effectiveness testing
  • Gap analysis against target frameworks
03

Risk Operations

Run it with us.

A named team operating defined parts of your risk program under your governance: assessment queues, evidence review, reassessment cycles, remediation follow-up and reporting.

  • Managed assessment queue
  • Evidence and questionnaire review
  • Remediation tracking & escalation
  • Recurring risk & board reporting
How it runs07

A vendor lifecycle, with ownership on every step.

Programs stall where a step has no owner. This is the third-party lifecycle we implement most often — each stage annotated with the line accountable for it.

  • 1st Line
  • 2nd Line
  • Both lines
  1. 01

    Vendor onboarded

    Business need, data scope and process dependency captured at intake.

  2. 02

    Criticality assessment

    Impact on critical services, data classification and substitutability.

  3. 03

    Risk tier

    Tier drives assessment depth, evidence set and reassessment frequency.

  4. 04

    Due diligence

    Security, resilience, privacy, financial and concentration review.

  5. 05

    Evidence review

    Certifications, reports and configuration read against the control set.

  6. 06

    Findings

    Rated against defined criteria, with a named owner on the first line.

  7. 07

    Remediation

    Actions, dates and compensating controls tracked to closure.

  8. 08

    Approval

    Residual risk accepted at the right level, with the rationale recorded.

  9. 09

    Continuous monitoring

    Signals, expiries and vendor changes update the profile between cycles.

  10. 10

    Reassessment

    Triggered by tier, by material change, or by the risk picture itself.

Step 10 returns to step 02 — reassessment is a trigger, not a date in a calendar.

Outcomes08

What better risk operations look like.

Not maturity levels. The specific, observable differences between a risk program that is documented and one that is operating.

  • Onboarding

    Faster vendor onboarding

    Tiering at intake means low-risk suppliers stop queueing behind Tier 1 reviews.

  • Ownership

    Clear risk ownership

    Every risk, control and finding resolves to a named accountable owner.

  • Method

    Consistent assessments

    The same criteria applied by every analyst, so results can be compared over time.

  • Governance

    Defensible decisions

    Acceptances recorded with rationale, evidence, expiry and approving authority.

  • Effort

    Reduced manual work

    Evidence reused across frameworks instead of recollected per audit.

  • Evidence

    Centralised evidence

    One location, with freshness and coverage visible before an auditor asks.

  • Delivery

    Visible remediation

    Open findings tracked to a date, an owner and a validated closure.

  • Assurance

    Audit-ready controls

    Policy-to-control traceability maintained continuously, not reconstructed.

  • Coverage

    Continuous vendor visibility

    Material vendor changes surface between assessment cycles, not after them.

  • Reporting

    Better executive reporting

    Exposure, trend and concentration expressed in terms an executive committee can act on.

Reporting09

One view an executive committee can act on.

Risk reporting fails when it presents activity instead of exposure. The numbers a board needs are few, comparable across quarters, and traceable back to the assessment that produced them.

Third-party & operational risk overviewQ3 · consolidatedIllustrative
Third parties
428+14 QTD
Active in the inventory
Critical vendors
37+2 QTD
Tier 1 · service-critical
Open high risks
12−5 vs. Q2
Across 9 vendors
Remediation overdue
8−3 vs. Q2
Past agreed closure date
Controls monitored
164+22 QTD
Continuously evidenced
Upcoming reassessments
21Scheduled
Next 90 days

Aggregate exposure index

−18% · 12 months

Weighted by criticality, control effectiveness and open findings

SepNovJanMarMayJul

Exposure by risk category

Share of open exposure · movement vs. prior quarter

  • Cybersecurity31 open
  • Operational24 open
  • Resilience19 open
  • Privacy13 open
  • Compliance11 open
  • Concentration7 open

Recent signals

Streaming
VendorTierSignalSeverityAge
Core payment processorTier 1SOC 2 report expires in 21 daysMedium2h
Cloud data platformTier 1New subprocessor added outside approved regionHigh6h
KYC data providerTier 2Availability below contractual SLA, third monthMedium1d
Managed SOCTier 1Access recertification evidence not providedLow3d
Illustrative reporting view with representative figures. Two Lines Risk is a services firm: we design reporting like this inside the tooling you already own — GRC platform, data warehouse or spreadsheet — or operate it for you.
About10

Risk management built by people who understand both risk and technology.

Two Lines Risk brings together professionals from operational risk, information security, technology and software engineering. We translate frameworks into operating processes, controls into evidence, findings into remediation, and risk information into decisions someone is willing to sign.

2 linesOwnership and oversight, working from one risk picture
10+Frameworks mapped to a single control set
0Certifications we issue — we prepare you, we do not audit you
  • Risk expertise

    Operational, technology, third-party, cyber and compliance risk — practised inside regulated institutions, not only described in a methodology.

  • Technical depth

    APIs, cloud accounts, network and identity architecture, CI/CD, data flows and application design read directly, without an intermediary.

  • Operational execution

    We run assessments, analyse evidence, work with vendors and follow remediation to closure. The framework is the beginning of the engagement, not the end.

  • Continuous visibility

    Programs designed to be measured: coverage, freshness, throughput and exposure, reported on a cadence your governance forums can rely on.

Frameworks we work against

  • ISO 27001
  • ISO 31000
  • NIST CSF
  • NIST 800-53
  • SOC 2
  • COBIT
  • COSO
  • DORA
  • PCI DSS
  • GDPR

Referenced for control mapping and readiness work. No affiliation with, or endorsement by, the issuing bodies is implied.

Make risk part of how your organization operates.

Whether you’re building a risk program, scaling third-party risk management, preparing for audit, or improving technology-risk visibility — Two Lines Risk can help.

  • Building a risk program from a standing start
  • Scaling third-party risk beyond a spreadsheet
  • Preparing for an audit or a regulatory review
  • Improving technology-risk visibility