Skip to content
Live prototype

NEXUS

Third-party dependency mapper: nth-party chains, concentration, and the vendors your services secretly share.

The problem

Ask a bank who its critical vendors are and you will get a list. Ask who sits underneath those vendors, four parties deep, and the list becomes a shrug. Third-party risk registers die at the boundary of the contract: the sub-processor behind the payment processor, the cloud region behind the core banking host, the single certificate authority half the estate quietly shares. Concentration hides in the layers nobody maps, and it surfaces at the worst possible moment, during an outage.

What it does

NEXUS turns the third-party register into a living dependency graph. Important business services sit at the top; beneath them, vendors, their subcontractors, and the nth-party infrastructure they share, mapped as a graph rather than rows. On top of the graph it runs the analyses the spreadsheet never could: concentration measured properly (including Herfindahl-style indices per service and per layer), hidden-common-vendor detection that surfaces the supplier three different critical paths silently share, and blast-radius views that show what a single failure actually touches.

Exit-strategy posture and substitutability sit on each edge, so the difficult conversation about a hard-to-replace vendor happens with the graph on the table, not after the incident.

Why it matters

Supervisory expectations moved here decisively: DORA expects a register of information and visibility into ICT subcontracting chains, the US interagency guidance on third-party relationships expects lifecycle risk management proportionate to criticality, and outsourcing regimes from the PRA to OSFI expect concentration to be understood, not discovered. A dependency map that ends at the second party cannot answer any of those expectations honestly. A graph can.

Honest framing

NEXUS is a working prototype and a blueprint, not a product. It runs in the browser on a synthetic demo tenant: every institution, vendor, and dependency in it is fictional, and its register export is structurally illustrative rather than a compliance artifact. Open it, follow a service down to its fourth party, and see what the spreadsheet was hiding. That is what it is for.