Your sub-processors are your customers’ risk
SaaS and technology companies manage their own vendors and sub-processors, and have to prove it every time a customer runs a vendor assessment. VendRisk360 runs that program on one record per vendor, including your AI providers, and keeps the evidence ready for auditors and customers.
Vendor risk, from the vendor’s side of the table
Security, privacy and compliance teams at technology companies answer to auditors, regulators and customers at once, often with a team of a few people.
A sub-processor list you can stand behind
Customers read it, DPAs reference it and regulators may ask for it. It needs to be complete, current and backed by diligence.
Every deal brings a questionnaire
Enterprise and regulated customers ask how you manage your vendors. Evidence that is organized once answers them consistently.
SOC 2 and ISO audits
Your auditor tests vendor management every cycle. Inventory, tiering, reviews and sign-offs have to be there, with dates.
AI in the stack
Model providers, AI features inside existing tools and vendors that build AI into their products all touch customer data. You need to know where and how.
Regulated customers pass obligations down
Banks under DORA, health customers under HIPAA and essential entities under NIS2 flow their third-party requirements into your contracts.
Small team, fast company
New tools are adopted weekly. Intake and tiering have to keep pace without slowing engineering down.
A sub-processor register backed by diligence
Every sub-processor gets one record: what it does, what personal data it processes, where, under which DPA and transfer mechanism, and how it was assessed. When you add or change one, the record shows the diligence behind the decision before you notify customers.
- Intake scoped by business case and data types, so personal data processors are identified before contracting
- DPA and transfer evidence held on the record with dates
- Assessment depth by tier, with SOC 2 and ISO/IEC 27001 reports reviewed in-house or through expert SOC Report Review
- Offboarding with exit evidence, including data return or deletion
Answer customers from evidence, not memory
When a customer’s TPRM team assesses you, much of what they ask is about your own third parties. VendRisk360 is where that answer already lives.
- Your sub-processor inventory with purpose, data and location for each
- How you tier and assess vendors, with the evidence and sign-offs behind each review
- Assurance status of your critical providers, including SOC report exceptions and CUECs
- Outside-in monitoring of your vendors for breaches, attack surface, shadow infrastructure and adverse news
- Examiner package export for customers who ask for the full file
For auditors
SOC 2 CC9.2 and ISO/IEC 27001 supplier controls, evidenced with dates and approvals.
For privacy teams
GDPR Article 28 and ISO/IEC 27701 sub-processor obligations, in one register.
For regulated customers
Subcontractor oversight and concentration evidence for DORA and bank due diligence.
For your board
Executive briefing and KPI decks showing vendor risk trends and open findings.
Govern the AI you buy, not only the AI you build
AI now arrives through model providers, new vendors and features switched on inside tools you already use. VendRisk360 makes it visible and assesses it with the same discipline as any critical supplier.
Visible at intake
Intake asks whether the vendor provides or uses AI and which data it touches, so AI providers are tagged and tiered from day one.
Assessed on evidence
An AI-use control domain covers model governance, data use and human oversight. Model documentation, AI policies and ISO/IEC 42001 certificates are reviewed as evidence.
Aligned to the frameworks
Supports the third-party elements of the NIST AI RMF (GOVERN 6), ISO/IEC 42001 supplier controls and your obligations under the EU AI Act.
Your cloud is your customers’ fourth party
Customers increasingly ask about concentration: which clouds, identity providers and AI models your service depends on. Nth-party intelligence maps your supply chain and shows the blast radius of an outage before a customer asks.
- Subservice organizations from your vendors’ SOC reports added to the map
- Concentration by provider, service and region
- CUEC tracking for the controls your providers expect you to operate
Mapped to the frameworks your customers cite
What each framework expects of your vendor and sub-processor program, and how the platform supports it.
| Regime | What it expects of your third-party program | How VendRisk360 supports it |
|---|---|---|
| PrivacyGDPR Article 28 | ExpectsProcessors engage sub-processors only with the controller’s prior specific or general written authorization, inform controllers of intended changes, flow down the same data protection obligations and remain liable for sub-processors. | Platform supportSub-processor records with purpose, data categories, location and DPA evidence, assessed before engagement and monitored afterwards. |
| PrivacyISO/IEC 27701 | ExpectsPrivacy information management, including processor controls for disclosing and engaging subcontractors that process PII. | Platform supportA current sub-processor inventory and due diligence records that support your PIMS evidence. |
| AssuranceSOC 2 Trust Services Criteria (CC9.2) | ExpectsThe entity assesses and manages risks associated with vendors and business partners. | Platform supportInventory, risk tiering, artifact-based assessments, findings and periodic reviews, with a full audit trail for your auditor. |
| SecurityISO/IEC 27001:2022, Annex A 5.19 to 5.23 | ExpectsSupplier relationship security, supplier agreements, ICT supply chain, monitoring of supplier services and information security for cloud services. | Platform supportControl domains mapped to supplier controls, contract evidence, monitoring and reassessment cadence. |
| AIEU AI Act, Regulation (EU) 2024/1689 | ExpectsObligations for providers and deployers of AI systems phasing in from 2025, which require visibility of the AI you build on and buy. | Platform supportAI use captured at intake, an AI-use control domain and evidence review for AI providers. |
| AINIST AI RMF 1.0; ISO/IEC 42001 | ExpectsPolicies and processes for AI risks from third-party software, data and models (NIST GOVERN 6), and supplier controls within an AI management system. | Platform supportAI vendors tiered and assessed like any critical supplier, with a named reviewer signing off every conclusion. |
| CustomersDORA and NIS2 flow-downs from regulated customers | ExpectsFinancial and essential-entity customers must oversee their ICT supply chain, and pass contractual and oversight expectations down to you. | Platform supportEvidence of how you oversee your own subcontractors and concentration, ready for customer due diligence. |
VendRisk360 is aligned to and maps to the regulations and standards named on this page. It does not certify compliance, and it is not legal advice. Your organization remains responsible for its own regulatory obligations and for confirming how they apply to it.
- Sub-processors
- Processors
- Data processing agreements (DPAs)
- Vendor management (CC9.2)
- Supplier relationships
- ICT supply chain
- AI providers
- Customer assurance
- Security questionnaires
- ICT third-party service providers
- Fourth parties
- Concentration risk
Run it yourself, have us assess, or add a review
Security and compliance teams at growing companies rarely have spare analysts. Run the program yourself on the platform, or have VendRisk360 assess your vendors: our certified assessors collect evidence, follow up with vendors and run the assessments while you watch progress on every vendor.
Run it on the platform
Your team manages its vendors, sends due diligence and evidence requests through the vendor portal, performs the review, records it and signs off. Every step is tracked with a full audit trail.
- Intake, tiering, assessments and sign-off under your own policy
- Monitoring signals and nth-party intelligence on the same record
- Board decks, dashboards and examiner package export
Have VendRisk360 assess your vendors
You onboard the vendor. Our certified assessors do the rest, and you see near real-time progress for every vendor on the platform and keep final approval.
- Evidence collection and vendor follow-up
- Assessment scaled to the vendor’s tier, with a second-expert quality review
- Findings and remediation follow-up, with Continuous Monitoring Services available between assessments
- Assessors holding CISSP, CISA, CISM, CRISC and ISO/IEC 27001 Lead Auditor and Lead Implementer, with PCI DSS implementation experience
Add report-specific reviews
Targeted expert reviews, each with a written review report for the vendor, available standalone or alongside the platform and services.
- SOC Report Review, with optional AI assistance
- Information Security Program Review
- Business Continuity Program Review
Frequently asked questions
How does VendRisk360 help manage sub-processors?
Each sub-processor is a vendor record with its purpose, the personal data categories it processes, where it processes them, the DPA and transfer mechanism as evidence, its assessment and its monitoring history. That gives you a current, defensible sub-processor list and the diligence behind it when a customer or auditor asks.
Does it help with SOC 2 vendor management criteria?
Yes. The SOC 2 common criteria include assessing and managing risks from vendors and business partners (CC9.2). VendRisk360 gives your auditor a vendor inventory, risk tiering, due diligence evidence, findings, sign-offs and periodic review history, with a full audit trail.
Can it answer our customers’ security questionnaires?
VendRisk360 is a third-party risk platform, not a questionnaire-response tool. What it gives you is the evidence customers ask about your supply chain: your sub-processors, how you assess them, their assurance reports, open findings and your monitoring. Your team uses that evidence to answer consistently, and the examiner package export packages it for customers who ask for the file.
How do we oversee AI vendors?
Intake records whether a vendor provides or uses AI and what data it touches, so AI providers are visible and tiered. Assessments include an AI-use control domain, and evidence such as model documentation, AI policies and ISO/IEC 42001 certificates is reviewed like any other artifact. That supports the third-party elements of the NIST AI RMF, ISO/IEC 42001 and your EU AI Act obligations.
We sell to banks in the EU. Does DORA affect our vendor program?
DORA requires EU financial entities to include specific provisions in contracts with ICT third-party service providers, including rights around subcontracting, audit and exit. As a provider, you are often asked to show how you oversee your own subcontractors. VendRisk360 keeps that oversight organized and evidenced. Confirm your specific obligations with your counsel.
See VendRisk360 on your sub-processors
A tailored walkthrough with a third-party risk specialist, built around your program, your regulators and your vendors.