Resources

Why undisclosed sub-processors show up in scans but not DPAs

2026-08-20 · 6 min read

Contractual disclosure lists and outside-in scanning answer different questions. Argus reconciles both so TPRM teams can explain the gap to auditors.

Why DPAs lag behind scans

A data processing agreement lists subprocessors the vendor intends to rely on when the contract is signed or last updated. Outside-in scanning answers a different question: what infrastructure responds when we resolve the vendor hostname today.

CDN edges, analytics scripts, and email delivery hops often appear in DNS and headers before legal updates the schedule. That gap is normal. The risk is treating the DPA as a complete inventory without reconciliation.

What Argus records

Lineage places each detected dependency in a bucket: disclosed and matched, disclosed only, detected only, or undisclosed_detected when scanning finds a provider absent from the contractual list. Analysts approve findings before they reach a customer report.

What to do with the finding

Ask the vendor for an updated sub-processor notification, tie the finding to your reassessment cadence, and track whether the same provider appears across multiple vendors in your portfolio. Concentration matters as much as any single undisclosed name.

See how 4th-party reconciliation works in Argus