Third-Party Risk
Manage the extended enterprise, without the questionnaire dying in an inbox.
Works with
What it does
Third-party assessment fails in the same place every time: a spreadsheet is emailed to a vendor, someone chases it for six weeks, and the answers are never scored consistently.
Here vendors answer in their own portal without needing an account in your tenant, campaigns chase them automatically, and answers are scored against the template you built.
Tiering drives how deep and how often each vendor is assessed, and the vendor-to-asset links mean an incident at a supplier scopes against your estate immediately.
Vendor inventory
Profiles with contacts, documents and contracts, including renewal dates.
Contract renewal is the only moment you have leverage to fix a security clause. Knowing the date in advance is the point.
VND-0087
Tiering
Criticality tiering that drives assessment depth and cadence rather than being a label on a profile.
Assessing every vendor to the same depth means the critical ones get the same attention as the stationery supplier. Tiering fixes the allocation.
Questionnaire templates
Build your own sectioned and scored questionnaires. A SIG-Lite-style starter template ships with the product.
Scoring at the template level is what makes two vendor responses comparable. Free-text answers never are.
Questionnaire campaigns
Issue to a set of vendors, chase automatically, score the returns and turn weak answers into findings.
Chasing is the work. Automating the chase is most of the value in this module.
Vendor self-service portal
An external portal where the vendor answers, uploads documents and responds to queries, without an account in your tenant.
Requiring a vendor to be provisioned in your identity system is why questionnaires come back as email attachments instead.
Questionnaire campaign
Issue campaign| ID | Vendor | Tier | Complete |
|---|---|---|---|
| VND-0087 | Wathba Data Services | Critical | 92% |
| VND-0104 | Falaj Payments | High | 61% |
| VND-0119 | Rustaq Cloud Hosting | Critical | 38% |
Vendor and asset links
Which vendors touch which assets, so an incident at a supplier scopes against your estate instantly.
When a supplier discloses a breach, this link is the difference between an answer in minutes and a week of asking around.
Re-assessments
Scheduled re-assessment driven by tier, with automatic reminders when one falls due.
A vendor assessed once at onboarding and never again is one of the most common third-party findings.
Vendor findings
Findings raised from vendor assessments, tracked to closure in the same findings model as audit and incident findings.
A vendor weakness and an internal audit weakness compete for the same remediation capacity. One model lets you prioritise across both.
Roles that live here
- Vendor Manager
- Procurement
- Risk Manager
- Compliance Officer
- External Vendor
Drawn from sixteen built-in roles, each scoped along the org tree. Access control
Related frameworks
See Third-Party Risk on your supplier list.
A 45-minute working session focused on the frameworks and requirements that matter to your organization.