Know when a vendor’s risk changes, not at the next review
An assessment is the inside-out view of a vendor’s controls at a point in time. Continuous Monitoring Services add the outside-in view in between: attack surface, shadow infrastructure, indicators of compromise, breaches, adverse news, regulatory actions and sanctions, confirmed before they alert, triaged by VendRisk360 and recorded on the vendor they belong to.
Outside-in monitoring, between inside-out reviews
A point-in-time review is only as current as its evidence. Monitoring keeps watch from the outside for the rest of the cycle, and both views live on the same vendor record.
Inside-out
Outside-in
360-degree coverage
A confirmed signal can raise a finding or pull the next reassessment forward, so coverage holds between and across assessments.
We watch. We confirm. We follow up.
Monitoring only helps if someone reads the signals and acts on them. With Continuous Monitoring Services, the VendRisk360 team does that work for you, and every outcome lands on the vendor record your team already uses.
Automated collection
Triaged by VendRisk360
Early reassessment
Visible on the platform
The signals that change a vendor’s risk
Monitoring spans nine categories. These are the headline families, the ones most likely to change a residual rating, a notification decision or a board conversation.
External attack surface
Shadow infrastructure
Indicators of compromise
Adverse news and litigation
Breaches and security incidents
Regulatory and enforcement actions
Sanctions screening
Fewer alerts. Every one of them real.
Monitoring tools fail when analysts stop reading the alerts. VendRisk360 confirms each signal before it reaches a person, so the feed stays short enough to act on.
Matched to the right vendor
Signals are resolved to the vendor entity on your register, not to a similarly named company.
Confirmed before alerting
Duplicates and stale items are filtered. Only a confirmed signal becomes an alert.
Routed with the evidence
The owner receives the source, the severity and the vendor context in one place, and records the response.
An outside-in view of every vendor’s exposure
What attackers can see of a vendor is often the first sign of weakness: a remote desktop port left open, an expired certificate, a deprecated TLS version on a customer-facing login, or a host nobody knew was still running.
- Score with category breakdown and trend, per vendor
- Exposed services listed with host, port and severity
- TLS certificate validity and protocol posture
- Score drops recorded on the vendor record, with the underlying evidence
- Shadow infrastructure surfaced alongside the vendor’s declared footprint
- Complements, never replaces, the evidence-based assessment
Exposed services
Internet-facing services and open ports, prioritized by what they expose.
TLS posture
Certificate validity, expiry and protocol configuration on vendor domains.
Footprint over time
Trend of the score, so a deteriorating vendor is visible before an incident.
How a signal reaches the vendor record
Monitoring is only useful if it changes something. Every confirmed signal lands on the vendor record and can reshape the assessment cycle.
Monitoring depth by tier: an example policy
- 01
Signal detected
CollectionSources are checked across nine monitoring categories. A raw signal is a candidate, not an alert. - 02
Signal confirmed
Before anyone is pagedThe signal is matched to the right vendor entity and confirmed. Name collisions, stale news and duplicates are filtered out, so your team sees only what is real. - 03
Scored and routed
To the right ownerThe confirmed signal is scored for severity and routed to the vendor owner with the source evidence attached. Monitoring depth per tier follows your policy. - 04
Recorded on the vendor
One recordThe signal, its evidence and the owner’s response are stored on the vendor record, next to the assessment and findings, and appear in executive reporting. - 05
Reassessment triggered
Outside-in meets inside-outA confirmed breach, an indicator of compromise, an enforcement action or a material drop in attack surface score can raise a finding or pull the next point-in-time reassessment forward, instead of waiting for the date your policy sets.
Works with the rest of the platform
Vendor Lifecycle Management Platform
Manage vendors, request evidence, review, record and sign off
Learn moreVendor lifecycle
Intake to offboarding in one governed record
Learn moreNth-Party Intelligence
Fourth parties, concentration and systemic risk, CUECs
Learn moreBoard & Executive Reporting
Board packs, executive briefings and examiner-ready exports
Learn moreComprehensive Vendor Risk Assessment
You onboard the vendor; our certified assessors do the rest
Learn moreReport-Specific Reviews
SOC report, information security and business continuity reviews
Learn moreFrequently asked questions
What is continuous vendor monitoring?
Continuous monitoring watches for changes in a vendor’s risk between scheduled assessments. It is the outside-in half of the VendRisk360 360 approach: the vendor’s external attack surface, shadow infrastructure, indicators of compromise, breaches and security incidents, adverse news and litigation, regulatory and enforcement actions, and sanctions screening, across nine monitoring categories.
How does monitoring relate to vendor assessments?
An assessment is an inside-out, point-in-time review of the vendor’s controls based on evidence such as SOC reports and penetration tests. Monitoring is the outside-in view that runs continuously between those reviews. Both land on the same vendor record, so a confirmed signal can raise a finding or bring the next reassessment forward. Together they give 360-degree coverage between and across assessments.
What is shadow infrastructure?
Internet-facing assets linked to a vendor that are unknown or unmanaged, such as forgotten hosts, stray subdomains or services outside the footprint the vendor declared. They are often less well maintained than the vendor’s known systems, which makes them a common entry point.
Who triages the signals?
For services customers, the VendRisk360 team triages confirmed signals, follows up with the vendor where needed and records the outcome on the vendor record, where your team sees it. If you run the Vendor Lifecycle Management Platform yourself, confirmed signals can instead be routed straight to your vendor owner.
Is the monitoring done by AI?
No. Monitoring relies on automated collection and scanning of external sources, and signals are matched and confirmed before they alert. Triage and any decision about a vendor are made by people: the VendRisk360 team for services customers, or your own vendor owner on the platform.
What does confirmed-only alerting mean?
A raw signal is not sent to your team until it has been matched to the correct vendor and confirmed. That filters out name collisions, duplicates and stale news, so analysts spend their time on real events rather than triaging noise.
What is the vendor attack surface score?
It summarizes the security posture of a vendor’s internet-facing footprint, such as exposed services and TLS configuration, into a single score with a category breakdown and trend. It is an outside-in indicator that complements, and does not replace, the inside-out, evidence-based assessment.
Can a monitoring signal trigger a reassessment?
Yes. A confirmed signal is recorded on the vendor record and can raise a finding or bring the next reassessment forward, for example after a disclosed breach or an enforcement action.
Is monitoring the same for every vendor?
No. Monitoring depth follows the tier and your policy. A common pattern is the full signal set for Critical vendors, key signals for Material vendors, and sanctions and public-source checks for Low-risk vendors.
Which regulations expect ongoing monitoring?
The US Interagency Guidance on Third-Party Relationships, the EBA Guidelines on outsourcing, DORA, APRA CPS 230, MAS and RBI outsourcing requirements all expect ongoing monitoring proportionate to risk. VendRisk360 is aligned to these expectations; each organization remains responsible for its compliance.
See VendRisk360 on your own vendors
A tailored walkthrough with a third-party risk specialist, built around your program, your regulators and your vendors.