One platform for the whole third-party lifecycle
Your team manages vendors, sends due diligence and evidence requests through the vendor portal, performs the review, records it and signs off, from intake to offboarding, on one governed record per vendor with a full audit trail. Add VendRisk360 services whenever you want experts to do part of the work.
The lifecycle, in the order regulators expect it
Interagency guidance in the US, the EBA outsourcing guidelines, DORA, APRA CPS 230, MAS and RBI all describe the same arc: plan, diligence, contract, monitor, exit. VendRisk360 runs it as one sequence, with each stage feeding the next.
- 01
Intake
Scope before you assessThe business owner submits a request with the business case, the services in scope and the data types the vendor will touch (customer PII, cardholder data, protected health information, confidential business data). Those two answers decide which control domains apply, so a marketing tool and a card processor never get the same questionnaire. - 02
Due diligence
Tier and gatherInherent risk and criticality set the tier: Critical, Material or Low risk. Your policy defines what each tier requires (evidence list, questionnaire depth, sign-off chain), and the platform applies it. Sanctions screening and public-source checks run at the start, and the vendor receives its requests through the vendor portal. - 03
Assessment
Evidence, not opinionsControls are assessed across 30+ control domains using the artifacts the vendor provided. Your analysts perform the review, record ratings, findings and notes, and sign off. SOC reports are reviewed for exceptions, carve-outs, subservice organizations and complementary user entity controls (CUECs). If you prefer, VendRisk360 assessors can do this work for you through Comprehensive Vendor Risk Assessment Services or a SOC Report Review. - 04
Contracting
Decide with conditionsFindings that must close before signature are tracked as pre-contract conditions, residual risk is accepted or rejected through a formal risk acceptance workflow, and multi-stage sign-off produces a sign-off certificate. Contract and renewal dates land on the vendor record. - 05
Monitoring
Between assessmentsContinuous monitoring adds the outside-in view: the vendor’s external attack surface, shadow infrastructure, indicators of compromise, breaches and security incidents, adverse news, regulatory and enforcement actions and sanctions. Only confirmed signals alert, and each one is routed to the vendor owner with the evidence attached. - 06
Reassessment
On cadence or on triggerEach tier is reassessed on the cadence your policy sets (for example, annually for Critical vendors), and the platform tracks every due date. A confirmed signal, a scope change or a new data type can pull a reassessment forward. Recertification reconciles owners, services and tiers so the register stays true. - 07
Offboarding
Exit with evidenceOffboarding cases track access revocation, data return or destruction certificates and final obligations, with exit evidence stored on the record. The relationship closes, and its history stays available to auditors and examiners.
The right depth for every vendor
Criticality drives the scope, the evidence and the cadence, so your team spends its time where the risk is, and can show a regulator why. Every tier's evidence, cadence and sign-off follow your own policy: the platform enforces what you configure, not a one-size-fits-all rule.
Full assessment
- Evidence
- SOC 1 and SOC 2 reports, penetration tests, BCP and DR tests, financials, subservice and fourth-party analysis
- Cadence
- Set by your policy, for example annual reassessment with continuous monitoring
- Sign-off
- Analyst, reviewer and risk owner sign-off
Focused assessment
- Evidence
- Security questionnaire, key certifications and targeted evidence
- Cadence
- Set by your policy, for example every two years with monitoring on key signals
- Sign-off
- Analyst and reviewer sign-off
Streamlined review
- Evidence
- Attestation, sanctions and public-source checks
- Cadence
- Set by your policy, for example at contract renewal
- Sign-off
- Relationship owner sign-off
One vendor record. Everything connected to it.
Spreadsheets and point tools split a vendor across a questionnaire tool, a shared drive, a ticket queue and a monitoring feed. VendRisk360 keeps one record per vendor, and every assessment, document, finding, signal and fourth party hangs off it.
- A breach at a fourth party shows up on every vendor that depends on it
- A confirmed monitoring signal updates the record and can trigger reassessment
- Board figures roll up from the same records analysts work in
- The register of vendors and services stays current without a separate inventory project
Relationships and services
Evidence
Assessments and findings
Monitoring signals
Fourth parties
Decisions and audit trail
Inside-out plus outside-in, on one record
A point-in-time review tells you how a vendor’s controls were designed and tested. Continuous monitoring tells you what changed since. VendRisk360 combines both, so coverage holds between and across assessments.
Inside-out: evidence-based review
Outside-in: continuous monitoring
360-degree coverage
Both views land on the same vendor record. A confirmed signal can raise a finding or pull the next reassessment forward, and the board sees one picture of each vendor, not two disconnected reports.
Vendors do their part in one place
No questionnaires by email, no evidence in inboxes. Vendors get a focused workspace for everything you ask of them, and your team sees progress without chasing.
- One-time-code access: no vendor passwords to manage
- Questionnaires scoped to the tier and the data types in play
- Evidence uploaded against each request, with effective and expiry dates tracked
- Remediation items assigned to the vendor, with due dates and status
- Vendors see only their own requests, never your internal ratings
From analyst workbench to board pack, same data
Nine ready-made decks, executive dashboards and scheduled reports draw directly from the vendor records, so the number in the board pack is the number in the register.
- Monthly VRM Board Report, Executive Risk Briefing, Concentration Risk Briefing and six more
- Present in-app, or export to PDF and editable PowerPoint
- Heat map, trend and program health dashboards for executives
- Every figure traceable to the vendor records behind it
Add experts where you need them
The platform stands on its own. When you want VendRisk360 to do part of the work, the results land on the same vendor records, audit trail and reports.
Comprehensive Vendor Risk Assessment Services
Continuous Monitoring Services
Report-Specific Reviews
Optional, and only in two places
The platform workflow does not depend on AI. It is a capability you choose to opt into, and every review, rating and sign-off is made by your own reviewers or by an expert assessor.
Evidence completeness and key dates
Expiration and effective dates, period covered, issuer, document type and scope, with missing, expired or out-of-scope items flagged.
SOC Report Review first pass
An AI-assisted first pass on the SOC report that the expert assessor verifies before anything is recorded.
Built to hold your most sensitive vendor evidence
SOC reports, penetration test results and breach details are some of the most sensitive documents a company holds. The platform is designed around that.
SSO and mandatory MFA
SAML and OIDC single sign-on with your identity provider. A second factor is required on every password login.
Tenant isolation
Database row-level security keeps each customer’s records separate at the data layer, not only in application code.
Encryption
TLS in transit and encryption at rest for records and uploaded evidence.
Custom roles
Least-privilege access with custom roles, and segregation of duties enforced in sign-off.
Full audit trail
Every decision, sign-off and change is logged and exportable for auditors.
Optional, governed AI
AI only where you opt in, and every review, rating and sign-off made by a named person.
Gets data in securely. Gets evidence out cleanly.
Sign-in plugs into your identity provider. Outputs arrive in the formats boards, auditors and examiners already use.
Single sign-on
PDF reports
Editable PowerPoint
Excel exports
Examiner package
Scheduled reports
Explore each part of VendRisk360
Vendor lifecycle
Intake to offboarding in one governed record
Learn moreNth-Party Intelligence
Fourth parties, concentration and systemic risk, CUECs
Learn moreBoard & Executive Reporting
Board packs, executive briefings and examiner-ready exports
Learn moreComprehensive Vendor Risk Assessment
You onboard the vendor; our certified assessors do the rest
Learn moreContinuous Monitoring
Outside-in monitoring: attack surface, shadow infrastructure, compromise
Learn moreReport-Specific Reviews
SOC report, information security and business continuity reviews
Learn moreFrequently asked questions
How the platform is structured, how it works with VendRisk360 services, where AI is used and what vendors, boards and examiners receive.
What is a third-party risk management (TPRM) platform?
A TPRM platform is the system of record for how an organization identifies, assesses, monitors and exits its vendor, supplier and outsourcing relationships. VendRisk360 keeps one record per vendor and runs intake, due diligence, risk-tiered assessments, continuous monitoring, nth-party mapping, offboarding and board reporting from that same record.
How does VendRisk360 decide how deeply to assess each vendor?
Intake captures the business case and the data types the vendor will handle. Those drive which control domains apply. Criticality tiering (Critical, Material or Low risk) then sets the evidence required, questionnaire depth, sign-off chain and reassessment cadence. Those settings come from your own TPRM policy (for example, annual reassessment for Critical vendors), and the platform enforces whatever policy you configure.
What is the difference between the platform and the VendRisk360 services?
On the Vendor Lifecycle Management Platform, your own team manages vendors, sends due diligence and evidence requests through the vendor portal, performs the review, records it and signs off, with every step tracked in the audit trail. With Comprehensive Vendor Risk Assessment Services, you onboard the vendor and VendRisk360’s certified assessors collect the evidence, follow up with the vendor, perform the assessment with a second-expert quality review and follow findings through remediation, while you see progress in near real time and keep final approval. Continuous Monitoring Services and Report-Specific Reviews can be added to either.
Where is AI used, and does the platform depend on it?
The platform workflow does not depend on AI. AI is an optional capability you choose to opt into. Where you opt in, it assists in two places: completeness checks and key-date extraction on vendor evidence (dates, period covered, issuer, document type and scope, with missing, expired or out-of-scope items flagged), and an AI-assisted first pass within SOC Report Review that the expert assessor verifies. Every review, rating and sign-off is performed by your own reviewers or by an expert assessor, and the audit trail records who did so.
What do vendors see?
Vendors use the vendor portal, reached with one-time-code access. They answer questionnaires, upload evidence and work on remediation items assigned to them. They see only their own requests, never your internal ratings, notes or other vendors.
Which exports are available for boards and examiners?
Nine ready-made board and executive decks export as PDF and editable PowerPoint. Registers, findings and assessment data export to Excel. The examiner package bundles assessments, evidence, sign-offs and audit trail for a regulator or internal audit request. Reports can also be scheduled.
How is customer data protected?
Single sign-on with SAML or OIDC, mandatory multi-factor authentication, tenant isolation enforced with database row-level security, encryption in transit and at rest, custom roles and a full audit trail. Details are on the Security and Trust page.
See VendRisk360 on your own vendors
A tailored walkthrough with a third-party risk specialist, built around your program, your regulators and your vendors.