Boardroom Answers · Security & Compliance · Compliance, Regulatory & Legal
Fourth-Party Risk: Screening Your Vendors’ Vendors
The question a Chief Compliance Officer (CCO) asks: “We're a regulated institution — our vendors get screened and so do theirs. Do you have any sanctions or financial-crime exposure controls, or is that not your problem?”
The short answer
Sanctions screening is built into onboarding with audit-logged results, payments inherit Stripe's regulated financial-crime controls, and we'll sign your compliance schedules — but we're honest that we're a SaaS vendor, not a bank-grade AML shop.
The full executive answer
It is our problem, and we've built for it earlier than most vendors our size. The platform includes a sanctions-screening module as part of the compliance domain — organisation names can be screened against sanctions considerations as part of governed onboarding, and screening events are recorded in the audit trail with elevated severity, so a hit is visible to your SIEM and ours. Payments are the other classic exposure route, and there we inherit heavyweight controls: Stripe and Lemon Squeezy both operate their own sanctions and financial-crime programmes as regulated payment processors, so a sanctioned entity attempting to pay us is blocked at the payment layer independent of anything we do.
Honest scope-setting: we are a SaaS analytics vendor, not a financial institution — we don't move money, hold funds, or perform KYC in the banking sense, and I won't pretend our screening is a bank-grade AML programme. What you should require of us is what our DPA and security documentation deliver: a clean sub-processor chain of major, screened providers, auditability of who accessed what, and cooperation with your vendor-diligence process — including completing your questionnaires and standing behind the answers contractually.
If your compliance framework requires specific attestations — modern-slavery statements, anti-bribery policy, export-control representations — those are standard contract schedule items for us, and as a pre-launch company we can accommodate policy requirements from an anchor customer with unusual speed; there's no legacy bureaucracy to renegotiate.
Grounded in: ISO 27001 A.5.19 (supplier due diligence); SOC 2 TSC CC9.2; OFAC/UN/EU sanctions regimes (screening context).
The natural next questions
Related governed answers
- You keep saying your controls live in code. What does that actually mean — how would my compliance team verify a control is operating?
- Enumerate every third party that touches my data. Vendors always forget two — don't be that vendor.?
- Export controls and trade sanctions — does any of this apply to you? We have subsidiaries in jurisdictions that make my trade-compliance team nervous.?
Want this answered live, on your data?