Every vendor's tiering, risk assessment, SOC 2 report, and DORA ICT register status tracked from onboarding to contract renewal. A risk-committee escalation alert fires automatically the moment a residual risk score crosses into the high threshold or a Tier-1 vendor's SOC 2 report lapses — not discovered during the next exam cycle.
Every user journey, the dashboard, and the AI Management Console — walked end to end.
A single platform for bank third-party risk teams — connecting the vendor inventory, risk assessments, SOC 2 reports, DORA ICT assessments, contracts, SLA metrics, incidents, and risk exceptions.
Chief Risk Officers, Heads of Vendor Risk Management, and CISOs at regulated banks and financial institutions.
Vendor risk analysts log vendors, assessments, and compliance artifacts directly — unlimited users, no per-seat cost, no core banking integration required.
The CRO queries which Tier-1 software vendors have not submitted an updated SOC 2 report this year in plain English.
Purpose-built data models, workflows, and views — generated by the VeloIQ™ framework and refined for the vertical.
Vendor tier, category, criticality rating, DORA ICT scope, and annual spend tracked per third-party relationship.
Inherent and residual risk scoring against reference frameworks (FFIEC, DORA, SOC 2, internal), with mitigating controls and reassessment cadence.
Report type, audit period, auditor's opinion, exceptions noted, and review-cadence status — every field a due-diligence review actually checks.
Criticality classification, concentration risk, exit-strategy documentation, and resilience testing — the DORA register fields regulators expect.
Renewal terms, termination notice periods, and measured SLA performance against contracted targets, with an automatic performance-gap calculation.
Vendor-attributed incidents with financial impact, and a formal risk-acceptance/exception workflow for vendors that exceed the standard risk appetite.
VeloIQ™ Third-Party Risk & FFIEC Matrix ships as a complete, working application — not a template you still have to build.
Arrives with realistic sample data (10 vendors, 4 risk frameworks, 14 risk assessments, 9 SOC 2 reports, 7 DORA ICT assessments, 10 vendor contracts, 14 SLA metrics, 8 incidents, 5 risk exceptions) plus a clean production-ready database. Explore instantly, then switch when you go live.
5 pre-configured NL chats with 28 sample sentences — vendors & risk assessments, SOC 2 & DORA compliance, and contracts & incidents (native), plus risk committee escalations and SLA/contract renewal planning AI assistants (agentic).
One veloiq run and the full application is live: REST API, React frontend, admin back-office, and AI console — all on your own infrastructure.
Automated smoke, regression, and licensing suites ship with the app, including checks that residual risk scores and SOC 2 expirations trigger risk-committee escalation correctly against real seeded data.
Measurable outcomes for every role — from the vendor risk analyst to the CRO.
Every risk assessment's residual score is checked automatically — a vendor crossing into the "high" threshold is flagged for escalation, not discovered during the next regulatory exam.
A Tier-1 vendor's expired SOC 2 report is visible immediately and drives automatic escalation — not buried in a shared drive.
IQVigilant's Exception Management watches for high residual risk and lapsed Tier-1 SOC 2 reports, with a 1-user free-tier Natural Language license included.
The single most common acute pain point for bank vendor risk teams — a spreadsheet of SOC 2 expiration dates — replaced with a real, queryable system of record.
Prospects can upload a year of past vendor risk assessment history via the Data Import Engine to see immediately where coverage gaps existed.
A vendor's ICT criticality classification and resilience testing sit alongside their risk score and SOC 2 standing — one record, not three separate systems.
From the risk dashboard to risk assessments, SOC 2 reports, and DORA ICT assessments — every screen generated by VeloIQ™, refined for bank third-party risk management.
Ask questions in plain English. Get bar charts, pie charts, donuts, bubble charts, area charts, and boxplots — no SQL required. 5 pre-built NL chats for vendors & risk assessments, SOC 2 & DORA compliance, and contracts & incidents (native), plus risk committee escalations and SLA/contract renewal planning AI assistants (agentic).
Data models and metadata that speak your industry’s language — because interoperability with examiners and auditors starts with the schema. See the full mapping in the app's STANDARDS.md.
| Area | Standard | Models mapped |
|---|---|---|
| Third-party risk lifecycle | FFIEC Third-Party Risk Guidance | RiskAssessment (inherent_risk_score, residual_risk_score, risk_tier), RiskFramework |
| Vendor security due diligence | AICPA SOC 2 Trust Services Criteria | Soc2Report (report_type, opinion, exceptions_noted_count, status) |
| ICT third-party risk register | EU DORA | DoraIctAssessment (criticality_classification, concentration_risk_flag, resilience_score) |
Every VeloIQ™ vertical application is versioned source code — not a locked SaaS. Fork, extend, integrate, or white-label.
Each module is a self-contained VeloIQ™ unit with its own models.py, generated GUI views, and REST API. Add or remove modules as your needs evolve.
Bring in IQVigilant for NL analytics and exception alerts, and Advanced Development for page-config templates, business rules, and data import — configured declaratively in veloiq.toml.
Add custom business logic in custom_api.py, override page-config templates per model:action, or add SQLAdmin views for advanced administration.
Switch from the shipped SQLite to PostgreSQL, MySQL, or Snowflake with a single connection string change. Schema migrations are tracked via Alembic.
AI-ready with 1-User Natural Language · 10 Exception Alerts · UI Configuration, Dynamic Business Rules & Data Import — learn about IQVigilant capabilities
Get in touch with the VeloIQ™ team to discuss deployment, customization, and licensing.