Skip to content
Vendor Lifecycle Management Platform

One platform for the whole third-party lifecycle

Your team manages vendors, sends due diligence and evidence requests through the vendor portal, performs the review, records it and signs off, from intake to offboarding, on one governed record per vendor with a full audit trail. Add VendRisk360 services whenever you want experts to do part of the work.

How it works

The lifecycle, in the order regulators expect it

Interagency guidance in the US, the EBA outsourcing guidelines, DORA, APRA CPS 230, MAS and RBI all describe the same arc: plan, diligence, contract, monitor, exit. VendRisk360 runs it as one sequence, with each stage feeding the next.

  1. 01

    Intake

    Scope before you assess
    The business owner submits a request with the business case, the services in scope and the data types the vendor will touch (customer PII, cardholder data, protected health information, confidential business data). Those two answers decide which control domains apply, so a marketing tool and a card processor never get the same questionnaire.
  2. 02

    Due diligence

    Tier and gather
    Inherent risk and criticality set the tier: Critical, Material or Low risk. Your policy defines what each tier requires (evidence list, questionnaire depth, sign-off chain), and the platform applies it. Sanctions screening and public-source checks run at the start, and the vendor receives its requests through the vendor portal.
  3. 03

    Assessment

    Evidence, not opinions
    Controls are assessed across 30+ control domains using the artifacts the vendor provided. Your analysts perform the review, record ratings, findings and notes, and sign off. SOC reports are reviewed for exceptions, carve-outs, subservice organizations and complementary user entity controls (CUECs). If you prefer, VendRisk360 assessors can do this work for you through Comprehensive Vendor Risk Assessment Services or a SOC Report Review.
  4. 04

    Contracting

    Decide with conditions
    Findings that must close before signature are tracked as pre-contract conditions, residual risk is accepted or rejected through a formal risk acceptance workflow, and multi-stage sign-off produces a sign-off certificate. Contract and renewal dates land on the vendor record.
  5. 05

    Monitoring

    Between assessments
    Continuous monitoring adds the outside-in view: the vendor’s external attack surface, shadow infrastructure, indicators of compromise, breaches and security incidents, adverse news, regulatory and enforcement actions and sanctions. Only confirmed signals alert, and each one is routed to the vendor owner with the evidence attached.
  6. 06

    Reassessment

    On cadence or on trigger
    Each tier is reassessed on the cadence your policy sets (for example, annually for Critical vendors), and the platform tracks every due date. A confirmed signal, a scope change or a new data type can pull a reassessment forward. Recertification reconciles owners, services and tiers so the register stays true.
  7. 07

    Offboarding

    Exit with evidence
    Offboarding cases track access revocation, data return or destruction certificates and final obligations, with exit evidence stored on the record. The relationship closes, and its history stays available to auditors and examiners.
Risk-tiered due diligence

The right depth for every vendor

Criticality drives the scope, the evidence and the cadence, so your team spends its time where the risk is, and can show a regulator why. Every tier's evidence, cadence and sign-off follow your own policy: the platform enforces what you configure, not a one-size-fits-all rule.

Critical vendors

Full assessment

Evidence
SOC 1 and SOC 2 reports, penetration tests, BCP and DR tests, financials, subservice and fourth-party analysis
Cadence
Set by your policy, for example annual reassessment with continuous monitoring
Sign-off
Analyst, reviewer and risk owner sign-off
Material vendors

Focused assessment

Evidence
Security questionnaire, key certifications and targeted evidence
Cadence
Set by your policy, for example every two years with monitoring on key signals
Sign-off
Analyst and reviewer sign-off
Low-risk vendors

Streamlined review

Evidence
Attestation, sanctions and public-source checks
Cadence
Set by your policy, for example at contract renewal
Sign-off
Relationship owner sign-off
The data model

One vendor record. Everything connected to it.

Spreadsheets and point tools split a vendor across a questionnaire tool, a shared drive, a ticket queue and a monitoring feed. VendRisk360 keeps one record per vendor, and every assessment, document, finding, signal and fourth party hangs off it.

  • A breach at a fourth party shows up on every vendor that depends on it
  • A confirmed monitoring signal updates the record and can trigger reassessment
  • Board figures roll up from the same records analysts work in
  • The register of vendors and services stays current without a separate inventory project

Relationships and services

Business owner, business units, services consumed, data types, criticality and contract dates. One vendor, many engagements, one risk view.

Evidence

Every document the vendor provided, filed by type against the request it answers, with effective and expiry dates tracked.

Assessments and findings

Assessment history, control results, findings, remediation plans, risk acceptances and sign-off certificates.

Monitoring signals

Confirmed signals across attack surface, shadow infrastructure, indicators of compromise, breaches, news, regulatory actions and sanctions, with the vendor attack surface score.

Fourth parties

Subservice organizations and nth parties the vendor relies on, shared with every other vendor that uses them.

Decisions and audit trail

Who approved what, when, on which evidence. Every change is logged and exportable.
The 360 approach

Inside-out plus outside-in, on one record

A point-in-time review tells you how a vendor’s controls were designed and tested. Continuous monitoring tells you what changed since. VendRisk360 combines both, so coverage holds between and across assessments.

Inside-out: evidence-based review

A point-in-time assessment of the vendor’s controls from SOC reports, penetration tests, policies, certificates and questionnaires, scaled by tier and repeated on the cadence your policy sets.

Outside-in: continuous monitoring

An ongoing view from the outside: the vendor’s external attack surface, shadow infrastructure (unknown or unmanaged internet-facing assets), indicators of compromise, breaches and security incidents, adverse news and regulatory actions.
Together

360-degree coverage

Both views land on the same vendor record. A confirmed signal can raise a finding or pull the next reassessment forward, and the board sees one picture of each vendor, not two disconnected reports.

Vendor portal

Vendors do their part in one place

No questionnaires by email, no evidence in inboxes. Vendors get a focused workspace for everything you ask of them, and your team sees progress without chasing.

  • One-time-code access: no vendor passwords to manage
  • Questionnaires scoped to the tier and the data types in play
  • Evidence uploaded against each request, with effective and expiry dates tracked
  • Remediation items assigned to the vendor, with due dates and status
  • Vendors see only their own requests, never your internal ratings
Board & executive reporting

From analyst workbench to board pack, same data

Nine ready-made decks, executive dashboards and scheduled reports draw directly from the vendor records, so the number in the board pack is the number in the register.

  • Monthly VRM Board Report, Executive Risk Briefing, Concentration Risk Briefing and six more
  • Present in-app, or export to PDF and editable PowerPoint
  • Heat map, trend and program health dashboards for executives
  • Every figure traceable to the vendor records behind it
See board and executive reporting
Services you can add

Add experts where you need them

The platform stands on its own. When you want VendRisk360 to do part of the work, the results land on the same vendor records, audit trail and reports.

Comprehensive Vendor Risk Assessment Services

You onboard the vendor. Our certified assessors collect the evidence, follow up with the vendor, assess it at the depth its tier requires with a second-expert quality review and follow findings through remediation. You keep final approval.

Continuous Monitoring Services

Outside-in monitoring between assessments: attack surface, shadow infrastructure, indicators of compromise, breaches, adverse news, regulatory actions and sanctions, confirmed before they alert and triaged by VendRisk360.

Report-Specific Reviews

SOC Report Review (with optional AI assistance), Information Security Program Review and Business Continuity Program Review, each with a written review report for the vendor.
Where AI is used

Optional, and only in two places

The platform workflow does not depend on AI. It is a capability you choose to opt into, and every review, rating and sign-off is made by your own reviewers or by an expert assessor.

Evidence completeness and key dates

Expiration and effective dates, period covered, issuer, document type and scope, with missing, expired or out-of-scope items flagged.

SOC Report Review first pass

An AI-assisted first pass on the SOC report that the expert assessor verifies before anything is recorded.

Security & trust

Built to hold your most sensitive vendor evidence

SOC reports, penetration test results and breach details are some of the most sensitive documents a company holds. The platform is designed around that.

SSO and mandatory MFA

SAML and OIDC single sign-on with your identity provider. A second factor is required on every password login.

Tenant isolation

Database row-level security keeps each customer’s records separate at the data layer, not only in application code.

Encryption

TLS in transit and encryption at rest for records and uploaded evidence.

Custom roles

Least-privilege access with custom roles, and segregation of duties enforced in sign-off.

Full audit trail

Every decision, sign-off and change is logged and exportable for auditors.

Optional, governed AI

AI only where you opt in, and every review, rating and sign-off made by a named person.

Integrations & exports

Gets data in securely. Gets evidence out cleanly.

Sign-in plugs into your identity provider. Outputs arrive in the formats boards, auditors and examiners already use.

Single sign-on

SAML 2.0 and OpenID Connect with your identity provider, so joiners, movers and leavers are governed where you already manage them.

PDF reports

Board decks, vendor risk assessment reports and sign-off certificates as PDF, ready for committee papers and file retention.

Editable PowerPoint

Every deck exports as native, editable PowerPoint so the CRO can add commentary before the meeting.

Excel exports

Vendor registers, findings, questionnaire responses, control matrices and performance data, formatted for analysis and audit sampling.

Examiner package

Assessments, evidence, findings, sign-offs and audit trail for a vendor or the whole program, assembled for an exam or internal audit request.

Scheduled reports

Recurring delivery of reports to named recipients on the cadence your committees meet.
FAQ

Frequently asked questions

How the platform is structured, how it works with VendRisk360 services, where AI is used and what vendors, boards and examiners receive.

What is a third-party risk management (TPRM) platform?

A TPRM platform is the system of record for how an organization identifies, assesses, monitors and exits its vendor, supplier and outsourcing relationships. VendRisk360 keeps one record per vendor and runs intake, due diligence, risk-tiered assessments, continuous monitoring, nth-party mapping, offboarding and board reporting from that same record.

How does VendRisk360 decide how deeply to assess each vendor?

Intake captures the business case and the data types the vendor will handle. Those drive which control domains apply. Criticality tiering (Critical, Material or Low risk) then sets the evidence required, questionnaire depth, sign-off chain and reassessment cadence. Those settings come from your own TPRM policy (for example, annual reassessment for Critical vendors), and the platform enforces whatever policy you configure.

What is the difference between the platform and the VendRisk360 services?

On the Vendor Lifecycle Management Platform, your own team manages vendors, sends due diligence and evidence requests through the vendor portal, performs the review, records it and signs off, with every step tracked in the audit trail. With Comprehensive Vendor Risk Assessment Services, you onboard the vendor and VendRisk360’s certified assessors collect the evidence, follow up with the vendor, perform the assessment with a second-expert quality review and follow findings through remediation, while you see progress in near real time and keep final approval. Continuous Monitoring Services and Report-Specific Reviews can be added to either.

Where is AI used, and does the platform depend on it?

The platform workflow does not depend on AI. AI is an optional capability you choose to opt into. Where you opt in, it assists in two places: completeness checks and key-date extraction on vendor evidence (dates, period covered, issuer, document type and scope, with missing, expired or out-of-scope items flagged), and an AI-assisted first pass within SOC Report Review that the expert assessor verifies. Every review, rating and sign-off is performed by your own reviewers or by an expert assessor, and the audit trail records who did so.

What do vendors see?

Vendors use the vendor portal, reached with one-time-code access. They answer questionnaires, upload evidence and work on remediation items assigned to them. They see only their own requests, never your internal ratings, notes or other vendors.

Which exports are available for boards and examiners?

Nine ready-made board and executive decks export as PDF and editable PowerPoint. Registers, findings and assessment data export to Excel. The examiner package bundles assessments, evidence, sign-offs and audit trail for a regulator or internal audit request. Reports can also be scheduled.

How is customer data protected?

Single sign-on with SAML or OIDC, mandatory multi-factor authentication, tenant isolation enforced with database row-level security, encryption in transit and at rest, custom roles and a full audit trail. Details are on the Security and Trust page.

Get started

See VendRisk360 on your own vendors

A tailored walkthrough with a third-party risk specialist, built around your program, your regulators and your vendors.