Dependence on others.
WHO YOU DEPEND ON
Payment providers Switches and processors Banking partners Identity verification services Fraud and screening vendors Infrastructure providers
WHAT THEIR FAILURE CAUSES
Inability to take payment Inability to onboard Inability to settle Exposure of your data
WHAT TO ASSESS BEFORE ENGAGING
Their security posture Their regulatory standing Their resilience history What access they receive What data they hold
WHAT TO RESTRICT
Data shared, to what is necessary Access granted, to what is required Duration of access
WHAT TO REQUIRE CONTRACTUALLY
Notification of incidents affecting you Defined availability commitments Rights to audit or receive assurance reports Clear exit provisions
WHY EXIT PROVISIONS MATTER
Migration is difficult, and leverage disappears at termination.
WHAT TO MONITOR
Their availability, independently of their own reporting Changes to their terms News affecting their standing
WHAT TO MAINTAIN
An alternative, at least identified and assessed.
WHAT TO TEST
Your behaviour when they are unavailable.
WHAT TO RECORD
Every third party, what they do, and who owns the relationship.