PILLAR 2 OF 3
Risk.
Identifying, measuring, and mitigating threats before they cause loss — operational, cyber, and inherited vendor exposure. Distinct from Compliance and Governance.
From signal to accountable remediation
Risk you can see, own, and close
Detection is the easy part. This pillar shows the evidence, the owner, and the path to done.
NIST CSF 2.0 — the six functions
Illustrative mappingGovern
Security policy library & oversight
Identify
Vulnerability management program
Protect
Zero Trust gap report; awareness-training audit
Detect
Continuous control-testing schedule
Respond
Incident response plan review
Recover
Disaster recovery gap report
Function names are exact to NIST CSF 2.0. Workflow mapping is illustrative and not a claim of full coverage.
Technology Platform Concentration Risk — Galileo Client Exit
- Evidence status
- Confirmed (public signal)
- Affected obligation
- Operational / Third-Party Risk — concentration & resilience
Recommended action
Request top-10 client concentration analysis; review vendor exit/termination plans; assess revenue diversification.
Risk register (excerpt)
IllustrativeScroll for more →
| Risk | Tier | Last reviewed | Evidence | Gap | Owner |
|---|---|---|---|---|---|
| Vendor — Galileo (Tier 1, platform) | High | 2026-06 | SOC 2 requested | Concentration — exit plan | Vendor Mgmt |
| Vendor — PaymentCo (Tier 1) | High | 2026-06 | SOC 2 on file | None open | Vendor Mgmt |
| Fourth-party — CloudHost | Medium | 2026-05 | Partial | DR test overdue | IT Risk |
| Internal — Access reviews | Medium | 2026-06 | Complete | None open | Security |
| Crypto — SoFiUSD operations | High | 2026-06 | Requested | New (Dec 2025) — controls TBD | CRO |
Third-party dependency chain
IllustrativeInstitution
SoFi Bank, N.A.
Primary vendor
Galileo — technology platform
Subprocessor
Cloud & data providers
Concentration and resilience risk follow the chain — fourth-party exposure is where it usually hides.
Open remediation — path to done
Illustrative- F-001 HighKYC / CIP program gap Overdue
- Owner
- BSA Officer
- Deadline
- Q1 2026
- Aging
- 74 days
- Evidence
- FINRA AWC on record
Closure criteria CIP gap-assessment closed against current FFIEC / FinCEN standards. - F-005 High$50B OCC heightened-standards uplift Monitoring
- Owner
- CRO / Governance
- Deadline
- Q3 2026
- Aging
- New
- Evidence
- Board charter under review
Closure criteria Heightened-standards program documented and board-approved. - F-006 MediumGalileo platform concentration Due
- Owner
- Vendor Mgmt
- Deadline
- Q2 2026
- Aging
- 32 days
- Evidence
- Top-10 client analysis requested
Closure criteria Concentration analysis and a vendor exit plan on file.
Continuity, recovery, and resilience — how they relate
Business Continuity (BCP)
The plan — how the business keeps running through disruption.
Disaster Recovery (DR)
The technical restore — systems and data brought back within targets.
Operational Resilience Testing
The proof — stress-testing that BCP and DR actually hold under pressure.
Who this is for
Chief Risk Officers
Operational resilience, vendor risk, and cyber in one view.
Security teams
NIST CSF 2.0 alignment with evidence trails auditors accept.
Procurement & vendor management
Fourth-party visibility for the supply chain regulators actually care about.
Operational Risk
- Business Continuity Plan (BCP) Review
- Disaster Recovery Gap Report
- Operational Resilience Testing
- Incident & Loss Data Collection
Includes all 4 workflows above.
Third-Party / Supply Chain Risk
- Vendor Onboarding Risk Assessment
- Third-Party Risk Register
- Fourth-Party Supply Chain Review
- Vendor Contract Compliance Audit
Includes all 4 workflows above.
Cybersecurity
- Zero Trust Architecture Gap Report
- Vulnerability Management Program
- Incident Response Plan Review
- Security Awareness Training Audit
Includes all 4 workflows above.