PILLAR 2 OF 3

Risk.

Identifying, measuring, and mitigating threats before they cause loss — operational, cyber, and inherited vendor exposure. Distinct from Compliance and Governance.

Threat radarA radar sweep over concentric threat rings — identifying threats before they cause loss.

From signal to accountable remediation

Risk you can see, own, and close

Detection is the easy part. This pillar shows the evidence, the owner, and the path to done.

NIST CSF 2.0 — the six functions

Illustrative mapping
  • Govern

    Security policy library & oversight

  • Identify

    Vulnerability management program

  • Protect

    Zero Trust gap report; awareness-training audit

  • Detect

    Continuous control-testing schedule

  • Respond

    Incident response plan review

  • Recover

    Disaster recovery gap report

Function names are exact to NIST CSF 2.0. Workflow mapping is illustrative and not a claim of full coverage.

Medium severityIllustrative

Technology Platform Concentration Risk — Galileo Client Exit

Evidence status
Confirmed (public signal)
Affected obligation
Operational / Third-Party Risk — concentration & resilience

Recommended action

Request top-10 client concentration analysis; review vendor exit/termination plans; assess revenue diversification.

Risk register (excerpt)

Illustrative

Scroll for more →

RiskTierLast reviewedEvidenceGapOwner
Vendor — Galileo (Tier 1, platform)High2026-06SOC 2 requestedConcentration — exit planVendor Mgmt
Vendor — PaymentCo (Tier 1)High2026-06SOC 2 on fileNone openVendor Mgmt
Fourth-party — CloudHostMedium2026-05PartialDR test overdueIT Risk
Internal — Access reviewsMedium2026-06CompleteNone openSecurity
Crypto — SoFiUSD operationsHigh2026-06RequestedNew (Dec 2025) — controls TBDCRO

Third-party dependency chain

Illustrative
  1. Institution

    SoFi Bank, N.A.

  2. Primary vendor

    Galileo — technology platform

  3. Subprocessor

    Cloud & data providers

Concentration and resilience risk follow the chain — fourth-party exposure is where it usually hides.

Open remediation — path to done

Illustrative
  • F-001 HighKYC / CIP program gap Overdue
    Owner
    BSA Officer
    Deadline
    Q1 2026
    Aging
    74 days
    Evidence
    FINRA AWC on record
    Closure criteria CIP gap-assessment closed against current FFIEC / FinCEN standards.
  • F-005 High$50B OCC heightened-standards uplift Monitoring
    Owner
    CRO / Governance
    Deadline
    Q3 2026
    Aging
    New
    Evidence
    Board charter under review
    Closure criteria Heightened-standards program documented and board-approved.
  • F-006 MediumGalileo platform concentration Due
    Owner
    Vendor Mgmt
    Deadline
    Q2 2026
    Aging
    32 days
    Evidence
    Top-10 client analysis requested
    Closure criteria Concentration analysis and a vendor exit plan on file.

Continuity, recovery, and resilience — how they relate

Business Continuity (BCP)

The plan — how the business keeps running through disruption.

Disaster Recovery (DR)

The technical restore — systems and data brought back within targets.

Operational Resilience Testing

The proof — stress-testing that BCP and DR actually hold under pressure.

Who this is for

Chief Risk Officers

Operational resilience, vendor risk, and cyber in one view.

Security teams

NIST CSF 2.0 alignment with evidence trails auditors accept.

Procurement & vendor management

Fourth-party visibility for the supply chain regulators actually care about.

Operational Risk

BCPDRResilienceDORA
  • Business Continuity Plan (BCP) Review
  • Disaster Recovery Gap Report
  • Operational Resilience Testing
  • Incident & Loss Data Collection

Includes all 4 workflows above.

Third-Party / Supply Chain Risk

TPRMVendor Due DiligenceFourth Party
  • Vendor Onboarding Risk Assessment
  • Third-Party Risk Register
  • Fourth-Party Supply Chain Review
  • Vendor Contract Compliance Audit

Includes all 4 workflows above.

Cybersecurity

NIST CSF 2.0Zero TrustVuln Mgmt
  • Zero Trust Architecture Gap Report
  • Vulnerability Management Program
  • Incident Response Plan Review
  • Security Awareness Training Audit

Includes all 4 workflows above.