Release roundup · October 5, 2026

Vendor oversight, examination tracking, and evidence management.

ThirdNexa brings vendor records, due diligence, contracts, findings, incidents, and examination evidence into one workspace. This roundup covers the major capabilities built into the platform to help financial-services teams organize oversight work and preserve the records behind their decisions.

The platform serves SEC- and FINRA-regulated firms, including investment advisers, broker-dealers, hybrid firms, hedge funds, private equity firms, and asset managers, as well as consultancies supporting those organizations.

This is a cumulative feature guide, not a list of changes made on a single day. Availability depends on your plan, role, and workspace configuration.

The firm makes every decision.

ThirdNexa organizes records, highlights follow-up work, and assists with extraction and summaries. It does not provide legal advice, determine whether a regulation applies, approve vendors automatically, or judge whether an examination response is adequate.

At a glance

What is in this release.

Twelve capability areas, each with the place to start in the application.

  • A centralized vendor inventory with business and compliance ownership.
  • Reviewed imports from spreadsheets, PDFs, Word documents, pasted lists, and images.
  • Customizable due diligence questionnaires with conditional questions and exception flags.
  • AI-assisted contract extraction, vendor oversight briefs, and assurance-report analysis.
  • Contract renewal tracking and a Regulation S-P clause checklist.
  • Incident workflows, findings, remediation conditions, and assigned tasks.
  • Examination request tracking and a permanent production log.
  • Deficiency response workflows with linked remediation steps and evidence.
  • A compliance calendar with recurring obligations and existing oversight deadlines.
  • Day One vendor summaries, annual review evidence packs, and source-record indexes.
  • Multi-firm consultancy access, role-based permissions, and account security controls.
  • Expanded Help Center guidance and Ask AI answers with inline citations and article previews.

01

Vendor inventory and ownership

Where to begin

  • Vendors → Add vendor.

One record for each service provider

Maintain vendor details, services, contacts, business ownership, compliance ownership, risk information, customer-information access, and supporting records in a single place. Contracts, reviews, documents, findings, and incidents remain connected to the vendor they concern.

Business owner and Compliance owner selectors show teammates with their roles and membership status, helping your team distinguish an active colleague from an invited teammate.

Risk information with a recorded rationale

Record customer-information access, service criticality, and other oversight details. ThirdNexa can suggest a risk tier; your firm reviews that suggestion and records a reason when overriding it. Scored risk assessments support a structured record of the factors behind a classification.

The Add vendor form identifies unanswered required questions before saving, including “Accesses customer information?” Your team can answer Yes, No, or Unknown rather than leaving the field blank.

Fill from website

Enter a vendor’s website and use Fill from website to suggest identifying details such as its name, legal name, type, description, and services. The tool fills empty fields without overwriting what you entered and reports which fields it populated.

Some websites block automated reading. When a clearly recognized company is identified using general knowledge instead, the tool discloses that basis. Suggested information still requires review.

02

Imports that keep your team in control

Where to begin

  • Vendors → Import (or select “Import contracts instead” / “Import everything at once”).

More ways to bring in vendor information

Import vendor lists from CSV and Excel files, PDFs, Word documents (.docx), and supported images such as screenshots. Use Paste a list for clipboard text rather than creating a file first.

The full import tools are available after a workspace is created. The initial signup vendor step remains CSV-only.

Review, verify, and reconcile before saving

The three-pass import workflow preserves source values alongside proposed values, checks for missing or conflicting information, and reconciles the outcome before commit. Your team can:

  • Inspect original values beside normalized or edited values.
  • Review mapping confidence and flagged issues.
  • Resolve likely duplicates without automatic merging.
  • Accept records, merge selected values, keep records separate, retain existing values, or skip rows.
  • Explicitly clear an existing field when intended; incoming blanks do not silently erase existing information.
  • Confirm that every source row is accounted for before saving.

Spreadsheet commits are all-or-nothing for the reviewed import scope. Multi-worksheet workbooks review and save vendors first, then process the contracts worksheet against the vendor inventory. Each worksheet has its own commit and audit entry.

Contract documents and batch retries

Upload several contract PDFs for AI-assisted extraction and review. Check the extracted terms, resolve the vendor match, and approve the contracts you want to create. Contract imports link to vendor records; they do not silently create new vendors.

Each PDF batch receives an Import audit entry listing its files, outcomes, and failures. Retry failed saves without re-uploading the batch or saving successful contracts again. Unreadable files can be re-read, and retries receive their own audit entries.

Combined document imports extract vendor details only. Use the contract import workflow for contract documents.

A permanent import record

The Import audit records counts, reconciliation results, row or file outcomes, and relevant source-to-value changes. Export audit details as CSV for later review.

03

Due diligence reviews and questionnaires

Where to begin

  • Questionnaires to manage templates; Reviews to start due diligence.

Structured initial and recurring reviews

Use reviews to collect vendor responses, examine supporting evidence, record issues, and preserve the firm’s final decision. Reviews retain their status and decision context rather than treating a completed questionnaire as automatic approval.

Customizable questionnaires

Start from the financial-services questionnaire library, copy a template, create one from blank, or upload questionnaire questions from a spreadsheet. Organize questions into sections and configure question types, required responses, help text, and applicable risk tiers.

Questionnaires support Draft, Active, and Retired states. Drafts remain editable before use; Active questionnaires are available for new reviews; retiring a template does not remove answers from historical reviews.

Conditional questions and exception flags

Conditional questions appear based on prior answers, reducing irrelevant follow-up questions. Exception rules help reviewers identify responses that need attention, including unknown answers and missing required evidence.

Vendors respond through secure links without creating a ThirdNexa account. Section assignments help organize questionnaire work and follow-up.

04

AI assistance with human review

Where to begin

  • Open a vendor for the AI brief; open its Documents area for report analysis.

Vendor oversight brief

Generate a plain-English brief from a vendor’s existing oversight records, including reviews, findings, incidents, contracts, and documents. Copy the brief for internal discussion or use it as a starting point for a review.

The brief summarizes recorded facts. It is not a vendor approval, risk acceptance, or regulatory conclusion.

SOC and assurance-report analysis

From a vendor’s Documents area, use Analyze report to extract information from an assurance report, including:

  • Report type, auditor, reporting period, and stated opinion.
  • Scope and relevant criteria.
  • Complementary user entity controls (CUECs).
  • Auditor testing exceptions and stated management responses.
  • Named subservice organizations.

Your team records its response to each CUEC, with who recorded the status and when. Existing CUEC sign-offs are preserved when a report is analyzed again. Create a finding from an extracted exception when your team decides follow-up is needed.

AI extraction may omit or misread information. Review the original document before relying on an extraction or summary. Identifying a subservice organization in a report is not the same as continuously monitoring that organization.

05

Contracts and Regulation S-P oversight tools

Where to begin

  • Contracts for individual records; Reg S-P clauses for the checklist view.

Track contract terms, renewal dates, notice periods, and cancel-by dates alongside the vendor record. AI-assisted document extraction provides proposed terms for review rather than silently accepting them.

The Regulation S-P contract checklist records clause status and supporting context. Its revised notification description reads:

Vendor notifies the firm within 72 hours of becoming aware of unauthorized access to or use of customer information.

The checklist records your team’s assessment of contract language. It does not decide whether the rule applies or whether a contract satisfies a regulatory requirement.

06

Incidents, findings, and remediation

Where to begin

  • Open the vendor’s incident or finding records; use Tasks for assigned follow-up work.

Incident response records

Record vendor incidents, response activity, decisions, and notice information. The incident workflow organizes assessment, containment, decision-making, notices, and closure, with notice timers to help track recorded dates.

The firm must determine applicability, relevant timing, recipients, and required actions. A timer is a tracking aid, not a legal determination.

Findings and follow-up work

Create findings with severity, ownership, due dates, remediation conditions, and supporting context. Track the lifecycle from investigation and remediation through verification, closure, or recorded risk acceptance.

Assign tasks to teammates and preserve the rationale behind material decisions. Findings, tasks, and related deadlines remain connected to the oversight record.

07

Examination request tracker and production log

Where to begin

  • Exams → select or create an exam → add requests and production log entries.

Keep every request visible

Create an exam and enter each request with an owner, due date, and status. Link the vendor records, contracts, reviews, findings, and documents supporting the response. Past-due highlighting helps your team identify requests needing attention.

Record what was sent

The production log preserves what your firm sent to examiners, when it was sent, the delivery method, the associated request, scope notes, and the person who recorded the entry.

Production log entries cannot be edited or deleted. Export the log as CSV for a consolidated record of submissions.

The log records submissions entered by your team; it does not itself transmit materials to regulators or prove receipt.

08

Deficiency response and supporting evidence

Where to begin

  • Exams → select an exam → Deficiency response → Generate evidence pack (PDF).

When a deficiency letter arrives, use the exam’s Deficiency response section to:

  1. 1Record each deficiency as stated, with an owner, due date, and status.
  2. 2Add remediation steps with their own owners, due dates, and progress.
  3. 3Link documents, findings, reviews, contracts, or vendors to the deficiency or a specific step.
  4. 4Record the firm’s written response.
  5. 5Generate a PDF evidence pack summarizing deficiencies, remediation steps, and linked evidence.

Step completion records the completion timestamp, and generating the pack is recorded in the activity log. The pack organizes the firm’s records; it does not judge whether remediation or a response is adequate. Referenced evidence is listed in the pack rather than represented as a guarantee that every original file is embedded.

09

Compliance calendar and recurring obligations

Where to begin

  • Calendar.

Bring recurring obligations together with deadlines already recorded in vendor oversight.

The calendar includes vendor review dates, contract renewals and cancel-by dates, document expirations, findings, tasks, conditions, and exam request deadlines. Add custom recurring obligations with owners and due dates. Completing a recurring obligation schedules its next occurrence automatically.

Dates drawn from existing records remain governed by those source records. The calendar does not independently determine which filings, certifications, training, or reviews your firm is legally required to perform.

10

Reports and evidence packs

Where to begin

  • Reports → Day One summary.
  • Reports → Annual evidence pack.

Day One vendor summary

Export a concise, one-page summary of active key service providers and their oversight details as PDF or CSV. Optionally include critical and high-risk vendors. Vendor relevance flags determine which key providers appear, so review those flags if the report is empty.

Annual review evidence pack

Select a year to summarize vendor reviews, findings, incidents, and decisions. The evidence index links to source records and supporting documents; the PDF includes an index appendix, and CSV provides the corresponding record list.

This pack supports gathering evidence for the firm’s annual review. It is not the annual review itself and does not establish that the review meets a regulatory requirement.

Broader oversight reporting

Exam evidence packs and Service provider oversight reports bring together inventory, risk tiers, customer-information access, contract clause status, incidents, review coverage, and activity. Vendor evidence packs organize an individual vendor’s record for internal review or examinations.

Report downloads are recorded in the activity log. Links to source records remain subject to workspace access permissions.

11

Consultancy workspaces, permissions, and communications

Multi-firm work without mixing records

Consultants can work across authorized client workspaces from one account. The workspace switcher identifies which firm is open, while firm-level access boundaries govern the records available there. Final vendor approval authority remains with the client firm’s administrators.

Firm Administrator, Reviewer, Contributor, and Read Only roles support different responsibilities. Two-step verification adds an account security control.

Messages, reminders, and branding

Use customizable message templates, merge fields, and previews for supported communications. Staff work summaries help organize assigned work, including cross-client summaries for consultants. Vendor-facing reminders are opt-in.

Supported emails use a “Name via ThirdNexa” sender display with replies directed to the sender. Eligible plans can customize email sender names, signatures, and footers; this is not a connection to the sender’s Outlook or Gmail mailbox.

Notifications now open the related oversight record where available, helping recipients move directly from an alert to the work needing attention.

12

Help Center and Ask AI

The expanded Help Center covers imports, vendor setup, reviews, contracts, incidents, exams, reports, calendars, AI tools, roles, billing, and troubleshooting.

Ask AI answers application questions using Help Center guidance. Inline numbered citations identify supporting articles beside specific claims or steps. Citation previews let users inspect an article without leaving the answer, with an option to open the full article.

When guidance is insufficient, the support path remains available. Ask AI is application assistance, not legal or regulatory advice.

Rollout

A practical rollout checklist.

For a firm adopting these capabilities, in the order the work usually happens.

  1. 1Review team roles and assign vendor business and compliance owners.
  2. 2Import the vendor inventory and resolve flagged rows before committing.
  3. 3Record customer-information access and review risk classifications.
  4. 4Attach contracts and assurance documents; verify AI-extracted information against originals.
  5. 5Configure questionnaires and schedule recurring due diligence.
  6. 6Assign findings and tasks, then review upcoming dates in Calendar.
  7. 7For an examination, create requests and record submissions in the production log.
  8. 8Link remediation evidence to any deficiencies and export the relevant evidence pack.
  9. 9Generate the annual pack for the selected year and review its evidence index.

Scope and availability

What this guide covers, and what it does not.

This guide describes implemented product capabilities, not a promise that every feature is included in every subscription. Consult current pricing and workspace permissions for availability.

Customer-facing API integrations, SSO/SCIM provisioning, mock exam mode, and a dedicated change management log are not included in this release roundup. Employee personal-trading surveillance and code-of-ethics monitoring are not current vendor-oversight capabilities.

ThirdNexa’s analysis of a vendor’s SOC report should not be read as a statement that ThirdNexa itself holds SOC 2 certification.

Keep vendor oversight work, examination requests, and supporting evidence connected—while your firm retains control of every decision.

ThirdNexa is a software platform provided by ThirdNexa LLC. ThirdNexa does not provide legal, regulatory, or compliance advice, and use of the platform does not guarantee compliance with any law or regulation or any particular examination outcome. Each firm remains solely responsible for establishing and maintaining policies, procedures, supervision, controls, and oversight appropriate to its regulatory obligations. ThirdNexa LLC is not affiliated with or endorsed by the SEC, FINRA, or any other regulatory authority.