Skip to main content
Skip to main content

Wise Sanctions Screening & Vendor Risk Evaluation

UK-headquartered · FCA regulated, FinCEN licensed

Before you share customer data with Wise, your compliance team needs documented proof they can be trusted. ThirdProof investigated Wise across 27 intelligence sources — here's what we found.

⚠ FedRAMP Status: Not found in the FedRAMP Marketplace. Vendors handling government data or CUI must be FedRAMP authorized.

Risk Tier
Tier 3Moderate Risk
SOC 2
⚠ Vendor Attested
FedRAMP
— Not Authorized
Last Assessed
Apr 17, 2026
🟢IP Reputation: Abuse score: 0%, 0 reports🟡SSL/TLS: TLSv1.3🟢Domain Age: 32.1 years🟢Infrastructure: 10 open ports, 0 CVEs
FedRAMP Status
Wise is not listed on the FedRAMP Marketplace as of March 2026.
SOC 2 Status
Wise has not had a SOC 2 claim detected on their trust page.
Sanctions Screening
Wise returned no matches in OFAC SDN, EU Consolidated, and UN sanctions screening.
Risk Tier
ThirdProof assigned Wise a Moderate Risk tier with 100% confidence across 27 intelligence sources.

27 sources queried. 100% confidence. Every Wise investigation produces both a risk report and an auto-filled security questionnaire — no vendor follow-up required.

Get Wise's Full Report Free →
5 free investigations|Risk report + auto-filled questionnaire|Avg. 7 minutes

Certification & Compliance Status

Security Questionnaire — Auto-Filled

58 of 133 questions answered for Wise

Auto-filled from public evidence • 44% complete

See all answers — Start Free →

Q37

Do you have a current SOC 2 Type II report?

SOC 2 Type II: claimed_with_trust_page

Source: External Automedium confidence

Q38

Do you have ISO 27001 certification?

Wise has been officially certified by the British Standards Institution (BSI) for meeting the requirements of ISO/IEC 27001.

Source: External Autohigh confidenceEvidence: wise.is

Q41

Are you FedRAMP authorized? At what level?

Not found in FedRAMP marketplace

Source: External Automedium confidence

Q42

Are you GDPR compliant? Do you have a DPA available?

Wise offers a Data Processing Agreement (DPA) to all users located in EU/EEA, UK, and Switzerland, signed at client onboarding for GDPR compliance.

Source: External Autohigh confidenceEvidence: wise.live

Q28

Where is customer data physically stored? In which countries/regions?

Infrastructure detected: Cloudflare

Source: External Automedium confidence

+ 4 more compliance questions answered in the full report

Every investigation produces a full PDF report plus the complete 133-question questionnaire, mapped to SOC 2, HIPAA, PCI DSS, SIG, and more.

Get Wise's Full Report Free →
Not Listed on FedRAMP Marketplace

Verified against FedRAMP Marketplace API as of March 2026

Organizations with federal compliance requirements should verify this directly at marketplace.fedramp.gov.

Wise is not listed on the FedRAMP Marketplace. As a financial services provider, Wise operates under financial regulatory frameworks (FCA, FinCEN) rather than federal IT security frameworks.

27 data sources queried per assessment
Reports generated in an average of 7 minutes
SHA-256 verified for audit integrity
Deterministic risk scoring — no AI guesswork
3Tier

Moderate Risk

Wise

Vendor Risk Assessment

Confidence Score100%

Based on data availability and source coverage

27

Sources Queried

27

Sources With Data

April 17, 2026

Last Assessed

Executive Summary

AI-generated analysis for Wise

Wise (wise.com) is a global payment processing platform operating in 160+ countries and has been assessed at Risk Tier 3 (Moderate Risk), reflecting a vendor with strong foundational security controls offset by a pattern of regulatory enforcement actions and a gap in supply chain transparency. Wise presents several meaningful positive signals across security and compliance domains. The domain has an established security posture with TLS 1.3 enforcement, a clean IP reputation (abuse score 0/100), no active malware or phishing flags, and an HTTP security grade of B+ (80/100) with HSTS and CSP enabled. The vendor claims SOC 2 Type II compliance on their trust page and holds ISO 27001 certification from the British Standards Institution (BSI), though independent registry verification was not confirmed. Wise offers a Data Processing Agreement to EU/EEA, UK, and Swiss users at onboarding, demonstrating GDPR preparedness. API security is documented with mTLS, signing/encryption keys, and strong customer authentication (SCA). The vendor publicly states a data retention maximum of ten years from account termination, with deletion of data no longer required by regulation. The assessment identified three areas requiring attention:

Key Findings

  • **Regulatory enforcement pattern**: Wise has faced multiple regulatory actions across jurisdictions, including a $4.2M multistate fine for AML and BSA compliance lapses by six US state regulators and a CFPB enforcement action (subsequently reduced). While these are now older than 12 months and severity-adjusted, the pattern warrants monitoring.
  • **TLS certificate expiry**: The current TLS certificate for wise.com expires in 27 days, representing an imminent operational risk.
  • **Subprocessor transparency**: No public subprocessor list was found on wise.com, limiting independent supply chain risk assessment, though research indicates Wise does maintain subprocessor documentation in other contexts. Overall, Wise is a well-established fintech platform with mature infrastructure controls and meaningful compliance credentials, but the recurring regulatory enforcement history and subprocessor transparency gap support a conditional approval recommendation pending specific remediation steps.

Independence Statement

All evidence in this assessment was independently sourced from external data repositories, public registries, domain intelligence feeds, and open media without any participation, input, or review by Wise.

Investigation Findings

8 findings identified for Wise

3 high5 medium
high

Adverse Media: regulatory

Article from paymentexpert.com: "Wise sanctioned again before US debut"

high

Adverse Media: regulatory

Article from www.paymentsdive.com: "CFPB slashes Wise penalty | Payments Dive"

high

Adverse Media: regulatory

Article from www.americanbanker.com: "Wise fined $4.2 million for multistate compliance lapses | PaymentsSource | American Banker"

medium

SSL Certificate Expiring Soon

The SSL certificate for wise.com expires in 27 days.

medium

Tech Community Discussion: operational

2 Hacker News stories about "Wise" related to operational. Top story: "A change of address led to our Wise accounts being shut down" (332 points).

medium

Multiple Certificate Issuers (37)

wise.com has certificates from 37 different Certificate Authorities. This may indicate inconsistent certificate management practices.

medium

No Public Subprocessor Page Found

No accessible subprocessor page was found for wise.com. GDPR Article 28 requires data processors to maintain a list of subprocessors. Vendors with mature data governance typically publish this list.

medium

Historical Media Coverage: Wise fined $4.2M for multistate AML compliance failures

4 article(s) mention "Wise" with risk keywords, severity reduced due to article age: "Wise fined $4.2 million for multistate compliance lapses" (American Banker) https://news.google.com/rss/articles/CBMiowFBVV95cUxONFJSY0hVOFo2Y0VaZzBNdTdKOVFzb05oWmJNMUpsWjM2SmVaaE1lVnNrV0dzN1E3Mmc3SFhDVWlQdE5xVVJ2Y2h6ZDNib1JDNDRNTTdScW9CbGpOTUJfQTR6TzJPNzNmR2EwbWg3ZnJiYkVLSzQ0cVhZWnc5bVRSeElJZnZqUW12TGIyMTBZRy0zaEVYYnJRLUZLU3ZCTl9PLU5r?oc=5; "Wise fined $4.2 million in multi-state AML enforcement action" (Lexology) https://news.google.com/rss/articles/CBMinAFBVV95cUxQWkItMi1YUDBvbWNIOWhBeUlSdVl6OFl5aGZYRFpuLXlQQmI4S0dlQWZCSUNQcnVDOGtOT2dVYlhvMDV6WnJUaENFV2lxNVY2X1dLY1JjcnNQTGhidmx0VUJabnJsNGUzOWZjWWpyOU94cWJYaG1Eb3cyR1pBWE9SOFVUY2t6R2lScFZhVXh0N2NlbkZ4cjBOVWd0MU8?oc=5; "Wise fined in US by state regulators for anti-money laundering compliance failur..." (MLex) https://news.google.com/rss/articles/CBMiwwFBVV95cUxPMXdVVzdOODNSMmJwRU4yb0VvNExUZjdfTVVXZk52Z2RDcEpJX1hoMmVZYUU0YkRVdVFDZjY3UEE5bGFnSnBkUzkwd183TTlwTjJsYkVJUkRsSnVVYTRsMVF3endHNzFnMWgtVmZwMEdKbnlEWDNGQ3dRU0dBU0sxZWZxclNsZjdrRlRXQ2ZSeW03ZHlwc3VYX2ZZd0lFa1F3VHZNaEstUkxyMHRub2ZuUEdyM1FSX0tQMU53RUNZN1R6clnSAVpBVV95cUxPOHprNXJVbXpWVDNRNEZyUEtiOWdjQlRMejFLV2hvSW82aWJsdFotalg0N0p6b0VDRXViMkFraFBXU1hubFNkb0I2d3hRQzRGVkoxNDN3SzRGMEE?oc=5

Security Strengths

20 positive signals verified

Legal Entity Actively Registered

Business Registration

Sanctions Data Incomplete

Sanctions & Watchlist Screening

Low-Confidence Sanctions Matches Only

Sanctions & Watchlist Screening

Firmographic Data Available

Company Intelligence

10 Open Ports Detected

Infrastructure Exposure

Established Domain (32+ years)

Domain Registration

Clean domain reputation

Threat Intelligence

HTTP Security Grade: B+

HTTP Security Scan

Large Certificate Footprint (68 subdomains)

Certificate Transparency

Established Web Presence (28+ years)

Web Archive History

No Threat Intelligence Pulses

Threat Intelligence (OTX)

Clean IP Reputation

IP Reputation

Clean Safe Browsing Status

Malware & Phishing Check

Clean Website Security Scan

Website Security Scan

Trust Page Found, No Certifications Detected

Trust & Compliance Page Scan

Not Found as FDIC-Insured Institution

FDIC Institution Check

No SEC Enforcement Filings Found

SEC Filing Search

HITRUST Directory Match — Manual Verification Required

Certification Registry Verification

SOC 2 Compliance Claimed on Trust Page

Certification Registry Verification

Deep Document Crawler Results

Deep Document Analysis

Recommended Actions

Steps to address findings for Wise

  1. 1

    Obtain Wise's SOC 2 Type II report and bridge letter before final approval — contact their security team via [wise.com/security](https://wise.com/security) or check whether it is accessible through their trust portal. Ask for the most recent report and confirm the audit period covers the last 12 months.

  2. 2

    Verify TLS certificate renewal status within the next 14 days by re-running the [SSL/TLS analysis service analysis](https://www.SSL/TLS analysis service.com/ssltest/analyze.html?d=wise.com) or checking the certificate expiry date directly. If expiry occurs without renewal confirmation, escalate with Wise's technical team.

  3. 3

    Request Wise's AML/BSA remediation documentation tied to the 2025 multistate enforcement action — ask their legal or compliance team for a summary of corrective controls implemented, or review any public statements made in connection with their US banking license application.

  4. 4

    Request a copy of Wise's current subprocessor list as part of DPA execution. Confirm that subprocessors processing your organization's customer data are listed and that a change notification mechanism is in place. Review Wise's [privacy notice](https://wise.com/gb/legal/privacy-notice-personal-en) for any subprocessor linkage.

  5. 5

    Confirm ISO 27001 certification currency with Wise's compliance team — ask for the BSI certificate number, valid-through date, and scope statement. You can cross-reference independently at [IAF CertSearch](https://www.iafcertsearch.org) using the certificate number once obtained.

  6. 6

    Request Wise's written AI/ML data usage policy or data processing addendum that clarifies whether customer transaction data is used to train predictive or AI models, and whether an opt-out mechanism is available for enterprise customers.

Intelligence Sources Queried

27 sources in this assessment

27of 27 sources returned data
IP Reputation
AI Data Usage Policy
Threat Intelligence (OTX)
Adverse Media Scan
Certification Registry Verification
Certificate Transparency
Deep Document Analysis
Domain Analysis
FDIC Institution Check
Business Registration
Historical Media Search
Tech Community Sentiment
Company Intelligence
Adverse Media Scan (Fallback)
HTTP Security Scan
Sanctions & Watchlist Screening
AI Research Agent
Malware & Phishing Check
SEC Filing Search
Infrastructure Exposure
SSL/TLS Analysis
Supply Chain & Subprocessor Discovery
Trust & Compliance Page Scan
Website Security Scan
Threat Intelligence
Web Archive History
Domain Registration

Data Coverage Notes

Some data sources may have had limited availability during this assessment. This does not reflect negatively on the vendor.

  • ISO 27001 certification was not independently confirmed via the IAF CertSearch public registry during this assessment, though the vendor is reported to hold BSI-issued certification. Independent registry verification should be sought directly from the vendor's compliance team.
  • AI data usage policy was located at the vendor's privacy notice, but key fields — including training commitment, third-party AI providers, and retention policy for AI processing — were not explicitly stated in discoverable documentation. The vendor's position on customer data use for AI/ML model training could not be independently confirmed.
  • Subprocessor data discovered via supplementary research referenced a document from a separate entity context (wise.aero) and may not reflect the complete subprocessor list for Wise's core international payment platform.
  • The HITRUST directory search returned a possible match at 90% confidence, but the entity match could not be confirmed — this may represent a name collision with a different organization rather than Wise the fintech.
  • DORA compliance status was inferred from a job posting referencing resilience frameworks, not from official compliance documentation — this answer carries low confidence.
183+
Vendors assessed
98%
Average confidence
<2 min
Time to report

Security & Compliance Profile

44% complete · 58/133 questions answered from public sources

Are you Wise? Claim this profile to complete your security record. Buyers are reviewing this profile now.

Claim this profile →
What a ThirdProof assessment covers

Sanctions Screening

Is Wise on any OFAC, EU, or UN sanctions list? Are any officers or affiliates flagged?

Cyber Risk Assessment

What is Wise's security posture? Threat intelligence scanning, known vulnerabilities, and security header analysis.

Business Registration

Is Wise a legitimately registered business entity? Corporate status, jurisdiction, and officer verification.

Adverse Media Analysis

Has Wise appeared in negative news coverage? Data breaches, lawsuits, regulatory actions, and complaints.

Domain & Infrastructure

Is Wise's website secure? TLS configuration, DNS hygiene, security headers, and domain age analysis.

Company Intelligence

What are Wise's firmographics? Employee count, industry classification, technology stack, and corporate structure.

Trust & Compliance Verification

Does Wise claim SOC 2, ISO 27001, HITRUST, or FedRAMP? ThirdProof scans trust pages for certification claims and cross-references the FedRAMP public registry for independent verification.

Supply Chain & Subprocessor Discovery

Who does Wise depend on? ThirdProof discovers subprocessors from vendor-published pages and runs sanctions screening and safe browsing checks against each one.

Regulatory & Financial Filings

Has Wise appeared in SEC enforcement filings? Is it associated with any FDIC bank failures? ThirdProof searches regulatory databases with entity verification to confirm attribution.

Full methodology, rule engine, and AI disclosure: /methodology

Why Sanctions Screening Matters for Wise

Wise (formerly TransferWise) operates as a regulated financial services provider across 50+ countries, holding money transmission licenses in the US and authorization as an Electronic Money Institution in the EU. As a cross-border payments platform handling international fund transfers, Wise presents elevated sanctions screening complexity compared to typical SaaS vendors. Organizations using Wise for business payments must assess exposure to OFAC (US), EU consolidated sanctions, and UK financial sanctions regimes — each with distinct compliance obligations.

ThirdProof's Assessment Approach for Wise

ThirdProof's autonomous assessment of Wise queries OFAC SDN and sectoral sanctions lists with fuzzy name matching, screens against the OpenSanctions consolidated database covering 80+ international sanctions regimes, verifies business registration across relevant jurisdictions, analyzes cyber risk posture through external scanning, and reviews adverse media for regulatory enforcement actions. All evidence is independently sourced — Wise does not participate in or influence the assessment.

Key Compliance Considerations

Organizations evaluating Wise as a vendor should consider: (1) PCI DSS implications if Wise processes cardholder data on your behalf, (2) multi-jurisdictional sanctions exposure given Wise's operations across US, EU, UK, and APAC regulatory regimes, (3) SOC 2 coverage for the specific Wise services your organization uses, and (4) data residency requirements given cross-border data flows inherent to international payment processing. ThirdProof's assessment covers all of these dimensions in a single automated assessment.

Evaluate Wise for Your Vendor Program

Your first 5 Wise assessments are free — no credit card, no vendor participation required. ThirdProof queries 27 intelligence sources autonomously: OFAC SDN screening, EU and UN sanctions, business registration verification, adverse media analysis, cyber risk scoring, SSL/TLS configuration, and more. Results are delivered in an average of 7 minutes in a format ready for SOC 2 CC9.2, PCI DSS 12.8, and HIPAA BAA compliance evidence packages.

Seeing this in an audit? ThirdProof lets you investigate Wise and every other vendor in your stack — average report time: 7 minutes. Get Wise's Full Report Free →

Frequently asked about Wise

Is Wise FedRAMP authorized?+
Wise is not currently listed on the FedRAMP Marketplace as of April 2026.
Does Wise have SOC 2 Type II?+
No SOC 2 found. Wise rated Moderate Risk — Regulatory enforcement action in medi.... See all 4 findings →
Is Wise on the OFAC sanctions list?+
Wise returned no matches in ThirdProof's OFAC SDN, EU Consolidated, and UN sanctions screening as of April 2026.
What is Wise's vendor risk tier?+
ThirdProof assigned Wise a risk tier of Moderate Risk with 100% confidence based on assessment across 27 intelligence sources as of April 2026.
Is Wise OFAC sanctioned?+
ThirdProof's assessment screened Wise against the OFAC SDN list, sectoral sanctions programs, and the OpenSanctions consolidated database. Wise is not sanctioned — no confirmed matches were found. However, Wise has disclosed historical AML enforcement actions in regulatory filings. Organizations should review the full ThirdProof report for details on regulatory history and current compliance posture.
Is Wise safe for international business payments?+
Wise holds money transmission licenses in the US and Electronic Money Institution authorization in the EU, operating across 50+ countries. ThirdProof's assessment found clear sanctions screening, clean domain reputation, and no active enforcement actions. Wise's PCI DSS and SOC 2 compliance claims should be verified directly — request current audit reports from Wise before onboarding.
Does Wise comply with anti-money laundering regulations?+
Wise operates under AML/KYC regulatory frameworks enforced by FinCEN (US) and the FCA (UK). ThirdProof's adverse media scan flagged historical AML enforcement actions in Wise's regulatory history. While Wise currently maintains active licenses across all operating jurisdictions, organizations should review the specific enforcement details in the full assessment report and assess whether Wise's current compliance controls meet your risk appetite.
Can I get an auto-filled security questionnaire for Wise?+
Yes. Every ThirdProof investigation of Wise produces two deliverables: an audit-ready risk report and a 133-question security questionnaire pre-filled with evidence from 27 independent sources. The questionnaire is mapped to SIG, SOC 2, HIPAA, PCI DSS and 9 other frameworks — answered without sending Wise a single email or waiting for a vendor response.
Is Wise safe to use as a vendor?+
Wise is a payments vendor that handles payment card and transaction data. Safety depends on their current security posture, certification status, and how they handle your specific data. ThirdProof automates this evaluation across 27 intelligence sources — sanctions databases (OFAC, EU, UN), business registration verification, adverse media scanning, and cyber risk assessment — producing a deterministic risk tier with confidence score plus an auto-filled security questionnaire. Run a free investigation to see Wise's full risk profile.
Does Wise have SOC 2 certification?+
No SOC 2 found. Wise rated Moderate Risk — Regulatory enforcement action in medi.... See all 4 findings →
Has Wise had any data breaches?+
Data breach history is an important signal for any vendor, particularly payments platforms like Wise that handle payment card and transaction data. ThirdProof's adverse media analysis searches multiple news APIs and public records for data breaches, security incidents, lawsuits, regulatory enforcement actions, and financial distress signals. Each finding is linked to its original source with severity classification.
Is Wise on any sanctions lists?+
Sanctions screening is particularly critical for payments vendors. ThirdProof screens Wise against OFAC SDN, consolidated international sanctions lists, and PEP databases. The screening uses entity name verification to reduce false positives. If Wise or any associated officers appear on a sanctions list, this triggers automatic escalation to the highest risk tier.
How do I assess Wise for vendor risk?+
Assessing Wise as a payments vendor involves verifying PCI-DSS and SOC 2 Type II compliance, reviewing their subprocessor chain, and checking sanctions exposure. ThirdProof automates this across 27 intelligence sources in an average of 7 minutes — no questionnaires or vendor participation required. Your first 5 investigations are free.
How long does a ThirdProof assessment take?+
A ThirdProof assessment completes in an average of 7 minutes. 27 intelligence sources are queried in parallel — sanctions databases, business registries, threat intelligence feeds, certificate transparency logs, and more. The result is a deterministic risk tier with confidence score and audit-ready PDF report.
Is ThirdProof free?+
ThirdProof offers 5 free vendor assessments with no credit card required. Each assessment includes the full report — risk tier, confidence score, individual findings, executive summary, and PDF export. Paid plans start at $399/month for teams that need ongoing vendor monitoring.
Can I use a ThirdProof report as SOC 2 audit evidence?+
Yes. ThirdProof reports are designed to satisfy SOC 2 CC9.2 (vendor risk management) requirements. Each report includes SHA-256 integrity verification, methodology disclosure, source attribution for every finding, and AI content labeling. Auditors can independently verify the report's authenticity and trace each finding to its original source.
How is ThirdProof different from a security questionnaire?+
Security questionnaires require vendor participation, take weeks, and produce self-reported answers. ThirdProof queries 27 independent intelligence sources — no vendor involvement needed. Risk tiers are assigned by a deterministic rules engine (not AI opinion), and every finding links to its original source. You get an audit-ready report in an average of 7 minutes instead of waiting weeks for a questionnaire response.

Wise is in your vendor stack. Can you prove you assessed them?

SOC 2 CC9.2, HIPAA, PCI-DSS, and CMMC all require documented vendor due diligence — not just knowing the answer, but having audit-ready evidence you verified it. Most compliance teams can't produce that documentation on demand.

ThirdProof investigates Wise across 27 intelligence sources in an average of 7 minutes — sanctions screening, cyber posture, SOC 2 verification, FedRAMP status, and more. Every investigation produces two deliverables: an audit-ready risk report and an auto-filled security questionnaire your prospects and auditors expect to see.

✓ 5 free investigations✓ Risk report + auto-filled questionnaire✓ No credit card required✓ Average report time: 7 minutes

Replaces $600–$900 in manual compliance consulting time per vendor assessed.