Use cases
Vendor risk programs that have to defend answers to auditors
Argus supports Canadian financial and retail buyers running OSFI-aligned TPRM, privacy office reviews under PIPEDA and Law 25, and global SOC 2 or GDPR vendor diligence. One assessment run produces sourced output your team approves.
Frameworks
Canadian compliance and global crosswalks
Assessments anchor on NIST CSF 2.0. Tenant settings record which frameworks your program tracks so reports and questionnaires use the language your stakeholders expect.
OSFI B-13
Technology and cyber risk management for federally regulated financial institutions. Argus maps vendor controls to your third-party risk program with sourced evidence and outside-in checks.
PIPEDA
Accountability for personal information handled by vendors. Assessments capture data types, cross-border transfer claims, and sub-processor disclosure quality from the DPA.
Quebec Law 25
Privacy impact and vendor diligence for Quebec personal information. Questionnaire sections target retention, subprocessors, and breach notification where your evidence supports it.
SOC 2
Crosswalk SOC trust criteria to NIST CSF controls. Librarian extracts Type II claims; Scorer flags where scan results contradict the report.
GDPR
Processor diligence for EU personal data. Lineage reconciles Article 28 sub-processor lists against detected infrastructure dependencies.
NIST CSF 2.0
Primary control library for every assessment. Residual scores roll up to categories your board and regulators already recognize.
Concentration
4th-party concentration risk
When twelve vendors all depend on the same cloud region or CDN, a single outage becomes a portfolio event. Lineage rolls sub-processor dependencies up so you see shared anchors before an incident forces the conversation.
Example output: 5 of 12 vendors share Amazon Web Services in their detected dependency chain. That number lands in the weekly brief and the board PDF with citations.
Portfolio alert
5 of 12 vendors
Share a detected sub-processor chain through one provider.
Concentration elevatedCadence
Continuous reassessment, tiered by vendor criticality
Tenant settings store reassessment intervals per tier. The weekly brief surfaces vendors due for refresh, score drops, and new undisclosed dependencies so the program does not rely on calendar reminders in a spreadsheet.
| Tier | Interval (days) | What runs |
|---|---|---|
| Critical vendors | 90 | Full reassessment including outside-in scan refresh |
| Medium vendors | 180 | Evidence refresh plus delta scan on material changes |
| Low vendors | 365 | Lightweight hygiene check and DPA drift review |
Map Argus to your program
Walk through framework crosswalks and concentration reporting on a demo call.