Q37
Do you have a current SOC 2 Type II report?
SOC 2 Type II: claimed_with_trust_page
UK-headquartered · FCA regulated, FinCEN licensed
Before you share customer data with Wise, your compliance team needs documented proof they can be trusted. ThirdProof investigated Wise across 27 intelligence sources — here's what we found.
⚠ FedRAMP Status: Not found in the FedRAMP Marketplace. Vendors handling government data or CUI must be FedRAMP authorized.
27 sources queried. 100% confidence. Every Wise investigation produces both a risk report and an auto-filled security questionnaire — no vendor follow-up required.
Get Wise's Full Report Free →Security Questionnaire — Auto-Filled
Auto-filled from public evidence • 44% complete
Q37
SOC 2 Type II: claimed_with_trust_page
Q38
Wise has been officially certified by the British Standards Institution (BSI) for meeting the requirements of ISO/IEC 27001.
Q41
Not found in FedRAMP marketplace
Q42
Wise offers a Data Processing Agreement (DPA) to all users located in EU/EEA, UK, and Switzerland, signed at client onboarding for GDPR compliance.
Q28
Infrastructure detected: Cloudflare
+ 4 more compliance questions answered in the full report
Every investigation produces a full PDF report plus the complete 133-question questionnaire, mapped to SOC 2, HIPAA, PCI DSS, SIG, and more.
Get Wise's Full Report Free →Verified against FedRAMP Marketplace API as of March 2026
Organizations with federal compliance requirements should verify this directly at marketplace.fedramp.gov.
Wise is not listed on the FedRAMP Marketplace. As a financial services provider, Wise operates under financial regulatory frameworks (FCA, FinCEN) rather than federal IT security frameworks.
Moderate Risk
Vendor Risk Assessment
Based on data availability and source coverage
27
Sources Queried
27
Sources With Data
April 17, 2026
Last Assessed
AI-generated analysis for Wise
Wise (wise.com) is a global payment processing platform operating in 160+ countries and has been assessed at Risk Tier 3 (Moderate Risk), reflecting a vendor with strong foundational security controls offset by a pattern of regulatory enforcement actions and a gap in supply chain transparency. Wise presents several meaningful positive signals across security and compliance domains. The domain has an established security posture with TLS 1.3 enforcement, a clean IP reputation (abuse score 0/100), no active malware or phishing flags, and an HTTP security grade of B+ (80/100) with HSTS and CSP enabled. The vendor claims SOC 2 Type II compliance on their trust page and holds ISO 27001 certification from the British Standards Institution (BSI), though independent registry verification was not confirmed. Wise offers a Data Processing Agreement to EU/EEA, UK, and Swiss users at onboarding, demonstrating GDPR preparedness. API security is documented with mTLS, signing/encryption keys, and strong customer authentication (SCA). The vendor publicly states a data retention maximum of ten years from account termination, with deletion of data no longer required by regulation. The assessment identified three areas requiring attention:
Independence Statement
All evidence in this assessment was independently sourced from external data repositories, public registries, domain intelligence feeds, and open media without any participation, input, or review by Wise.
8 findings identified for Wise
Article from paymentexpert.com: "Wise sanctioned again before US debut"
Article from www.paymentsdive.com: "CFPB slashes Wise penalty | Payments Dive"
Article from www.americanbanker.com: "Wise fined $4.2 million for multistate compliance lapses | PaymentsSource | American Banker"
The SSL certificate for wise.com expires in 27 days.
2 Hacker News stories about "Wise" related to operational. Top story: "A change of address led to our Wise accounts being shut down" (332 points).
wise.com has certificates from 37 different Certificate Authorities. This may indicate inconsistent certificate management practices.
No accessible subprocessor page was found for wise.com. GDPR Article 28 requires data processors to maintain a list of subprocessors. Vendors with mature data governance typically publish this list.
4 article(s) mention "Wise" with risk keywords, severity reduced due to article age: "Wise fined $4.2 million for multistate compliance lapses" (American Banker) https://news.google.com/rss/articles/CBMiowFBVV95cUxONFJSY0hVOFo2Y0VaZzBNdTdKOVFzb05oWmJNMUpsWjM2SmVaaE1lVnNrV0dzN1E3Mmc3SFhDVWlQdE5xVVJ2Y2h6ZDNib1JDNDRNTTdScW9CbGpOTUJfQTR6TzJPNzNmR2EwbWg3ZnJiYkVLSzQ0cVhZWnc5bVRSeElJZnZqUW12TGIyMTBZRy0zaEVYYnJRLUZLU3ZCTl9PLU5r?oc=5; "Wise fined $4.2 million in multi-state AML enforcement action" (Lexology) https://news.google.com/rss/articles/CBMinAFBVV95cUxQWkItMi1YUDBvbWNIOWhBeUlSdVl6OFl5aGZYRFpuLXlQQmI4S0dlQWZCSUNQcnVDOGtOT2dVYlhvMDV6WnJUaENFV2lxNVY2X1dLY1JjcnNQTGhidmx0VUJabnJsNGUzOWZjWWpyOU94cWJYaG1Eb3cyR1pBWE9SOFVUY2t6R2lScFZhVXh0N2NlbkZ4cjBOVWd0MU8?oc=5; "Wise fined in US by state regulators for anti-money laundering compliance failur..." (MLex) https://news.google.com/rss/articles/CBMiwwFBVV95cUxPMXdVVzdOODNSMmJwRU4yb0VvNExUZjdfTVVXZk52Z2RDcEpJX1hoMmVZYUU0YkRVdVFDZjY3UEE5bGFnSnBkUzkwd183TTlwTjJsYkVJUkRsSnVVYTRsMVF3endHNzFnMWgtVmZwMEdKbnlEWDNGQ3dRU0dBU0sxZWZxclNsZjdrRlRXQ2ZSeW03ZHlwc3VYX2ZZd0lFa1F3VHZNaEstUkxyMHRub2ZuUEdyM1FSX0tQMU53RUNZN1R6clnSAVpBVV95cUxPOHprNXJVbXpWVDNRNEZyUEtiOWdjQlRMejFLV2hvSW82aWJsdFotalg0N0p6b0VDRXViMkFraFBXU1hubFNkb0I2d3hRQzRGVkoxNDN3SzRGMEE?oc=5
20 positive signals verified
Legal Entity Actively Registered
Business Registration →Sanctions Data Incomplete
Sanctions & Watchlist Screening →Low-Confidence Sanctions Matches Only
Sanctions & Watchlist Screening →Firmographic Data Available
Company Intelligence →10 Open Ports Detected
Infrastructure Exposure →Established Domain (32+ years)
Domain Registration →Clean domain reputation
Threat Intelligence →HTTP Security Grade: B+
HTTP Security Scan →Large Certificate Footprint (68 subdomains)
Certificate Transparency →Established Web Presence (28+ years)
Web Archive History →No Threat Intelligence Pulses
Threat Intelligence (OTX) →Clean IP Reputation
IP Reputation →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Trust Page Found, No Certifications Detected
Trust & Compliance Page Scan →Not Found as FDIC-Insured Institution
FDIC Institution Check →No SEC Enforcement Filings Found
SEC Filing Search →HITRUST Directory Match — Manual Verification Required
Certification Registry Verification →SOC 2 Compliance Claimed on Trust Page
Certification Registry Verification →Deep Document Crawler Results
Deep Document Analysis →Steps to address findings for Wise
Obtain Wise's SOC 2 Type II report and bridge letter before final approval — contact their security team via [wise.com/security](https://wise.com/security) or check whether it is accessible through their trust portal. Ask for the most recent report and confirm the audit period covers the last 12 months.
Verify TLS certificate renewal status within the next 14 days by re-running the [SSL/TLS analysis service analysis](https://www.SSL/TLS analysis service.com/ssltest/analyze.html?d=wise.com) or checking the certificate expiry date directly. If expiry occurs without renewal confirmation, escalate with Wise's technical team.
Request Wise's AML/BSA remediation documentation tied to the 2025 multistate enforcement action — ask their legal or compliance team for a summary of corrective controls implemented, or review any public statements made in connection with their US banking license application.
Request a copy of Wise's current subprocessor list as part of DPA execution. Confirm that subprocessors processing your organization's customer data are listed and that a change notification mechanism is in place. Review Wise's [privacy notice](https://wise.com/gb/legal/privacy-notice-personal-en) for any subprocessor linkage.
Confirm ISO 27001 certification currency with Wise's compliance team — ask for the BSI certificate number, valid-through date, and scope statement. You can cross-reference independently at [IAF CertSearch](https://www.iafcertsearch.org) using the certificate number once obtained.
Request Wise's written AI/ML data usage policy or data processing addendum that clarifies whether customer transaction data is used to train predictive or AI models, and whether an opt-out mechanism is available for enterprise customers.
27 sources in this assessment
Some data sources may have had limited availability during this assessment. This does not reflect negatively on the vendor.
Are you Wise? Claim this profile to complete your security record. Buyers are reviewing this profile now.
Claim this profile →Is Wise on any OFAC, EU, or UN sanctions list? Are any officers or affiliates flagged?
What is Wise's security posture? Threat intelligence scanning, known vulnerabilities, and security header analysis.
Is Wise a legitimately registered business entity? Corporate status, jurisdiction, and officer verification.
Has Wise appeared in negative news coverage? Data breaches, lawsuits, regulatory actions, and complaints.
Is Wise's website secure? TLS configuration, DNS hygiene, security headers, and domain age analysis.
What are Wise's firmographics? Employee count, industry classification, technology stack, and corporate structure.
Does Wise claim SOC 2, ISO 27001, HITRUST, or FedRAMP? ThirdProof scans trust pages for certification claims and cross-references the FedRAMP public registry for independent verification.
Who does Wise depend on? ThirdProof discovers subprocessors from vendor-published pages and runs sanctions screening and safe browsing checks against each one.
Has Wise appeared in SEC enforcement filings? Is it associated with any FDIC bank failures? ThirdProof searches regulatory databases with entity verification to confirm attribution.
Full methodology, rule engine, and AI disclosure: /methodology
Wise (formerly TransferWise) operates as a regulated financial services provider across 50+ countries, holding money transmission licenses in the US and authorization as an Electronic Money Institution in the EU. As a cross-border payments platform handling international fund transfers, Wise presents elevated sanctions screening complexity compared to typical SaaS vendors. Organizations using Wise for business payments must assess exposure to OFAC (US), EU consolidated sanctions, and UK financial sanctions regimes — each with distinct compliance obligations.
ThirdProof's autonomous assessment of Wise queries OFAC SDN and sectoral sanctions lists with fuzzy name matching, screens against the OpenSanctions consolidated database covering 80+ international sanctions regimes, verifies business registration across relevant jurisdictions, analyzes cyber risk posture through external scanning, and reviews adverse media for regulatory enforcement actions. All evidence is independently sourced — Wise does not participate in or influence the assessment.
Organizations evaluating Wise as a vendor should consider: (1) PCI DSS implications if Wise processes cardholder data on your behalf, (2) multi-jurisdictional sanctions exposure given Wise's operations across US, EU, UK, and APAC regulatory regimes, (3) SOC 2 coverage for the specific Wise services your organization uses, and (4) data residency requirements given cross-border data flows inherent to international payment processing. ThirdProof's assessment covers all of these dimensions in a single automated assessment.
Your first 5 Wise assessments are free — no credit card, no vendor participation required. ThirdProof queries 27 intelligence sources autonomously: OFAC SDN screening, EU and UN sanctions, business registration verification, adverse media analysis, cyber risk scoring, SSL/TLS configuration, and more. Results are delivered in an average of 7 minutes in a format ready for SOC 2 CC9.2, PCI DSS 12.8, and HIPAA BAA compliance evidence packages.
Seeing this in an audit? ThirdProof lets you investigate Wise and every other vendor in your stack — average report time: 7 minutes. Get Wise's Full Report Free →
SOC 2 CC9.2, HIPAA, PCI-DSS, and CMMC all require documented vendor due diligence — not just knowing the answer, but having audit-ready evidence you verified it. Most compliance teams can't produce that documentation on demand.
ThirdProof investigates Wise across 27 intelligence sources in an average of 7 minutes — sanctions screening, cyber posture, SOC 2 verification, FedRAMP status, and more. Every investigation produces two deliverables: an audit-ready risk report and an auto-filled security questionnaire your prospects and auditors expect to see.
Replaces $600–$900 in manual compliance consulting time per vendor assessed.