Vendor SLAs are not continuity plans
Payment processors, cloud hosts, and KYC providers appear in almost every fintech continuity appendix. Quoting their SLA is common. Knowing your manual workaround, customer message, and escalation clock when they breach it is rarer.
Ask three questions for each critical vendor: what customer impact starts at minute thirty, who inside your firm owns the workaround, and when did you last rehearse that path? If answers live only in a contract PDF, continuity is incomplete.
Disaster recovery and continuity audits treat vendor dependency as an operations problem first — contracts second — so remediation targets people and processes you control.