Skip to content
Continuous Monitoring Services

Know when a vendor’s risk changes, not at the next review

An assessment is the inside-out view of a vendor’s controls at a point in time. Continuous Monitoring Services add the outside-in view in between: attack surface, shadow infrastructure, indicators of compromise, breaches, adverse news, regulatory actions and sanctions, confirmed before they alert, triaged by VendRisk360 and recorded on the vendor they belong to.

The 360 approach

Outside-in monitoring, between inside-out reviews

A point-in-time review is only as current as its evidence. Monitoring keeps watch from the outside for the rest of the cycle, and both views live on the same vendor record.

Inside-out

Evidence-based review of the vendor’s controls from SOC reports, penetration tests, policies and questionnaires, repeated on the cadence your policy sets.

Outside-in

Continuous watch on attack surface, shadow infrastructure, indicators of compromise, breaches and incidents, adverse news and regulatory actions.
Together

360-degree coverage

A confirmed signal can raise a finding or pull the next reassessment forward, so coverage holds between and across assessments.

Delivered as a service

We watch. We confirm. We follow up.

Monitoring only helps if someone reads the signals and acts on them. With Continuous Monitoring Services, the VendRisk360 team does that work for you, and every outcome lands on the vendor record your team already uses.

Automated collection

External sources are scanned and checked continuously for every vendor in scope, at the depth your policy sets for each tier.

Triaged by VendRisk360

Confirmed signals are reviewed by our team, who assess relevance and severity and follow up with the vendor where needed.

Early reassessment

A material signal can raise a finding or bring the vendor’s next assessment forward, instead of waiting for the scheduled date.

Visible on the platform

Signals, their evidence and the outcome are recorded on the vendor record and flow into executive and board reporting.
Pair monitoring with Comprehensive Vendor Risk Assessment Services
Nine monitoring categories

The signals that change a vendor’s risk

Monitoring spans nine categories. These are the headline families, the ones most likely to change a residual rating, a notification decision or a board conversation.

External attack surface

Exposed services, open remote-access and database ports, TLS certificate and protocol posture across the vendor’s internet-facing domains. Rolled into the vendor attack surface score.

Shadow infrastructure

Unknown or unmanaged internet-facing assets tied to the vendor: forgotten hosts, stray subdomains and services outside the footprint the vendor declared.

Indicators of compromise

Signs that a vendor may already be compromised, such as infrastructure associated with malicious activity, so a possible incident is visible before it is disclosed.

Adverse news and litigation

Litigation, leadership change, financial distress, ownership change and reputational events that can change a vendor’s risk or viability.

Breaches and security incidents

Disclosed breaches, security incidents and exposed credentials linked to vendor domains, the signals most likely to require a notification decision.

Regulatory and enforcement actions

Consent orders, fines, enforcement actions and regulatory findings against the vendor, which often precede service or compliance impact for you.

Sanctions screening

Screening of vendors against sanctions lists at onboarding and on an ongoing basis, so a new designation does not wait for the next review.
Confirmed-only alerting

Fewer alerts. Every one of them real.

Monitoring tools fail when analysts stop reading the alerts. VendRisk360 confirms each signal before it reaches a person, so the feed stays short enough to act on.

Matched to the right vendor

Signals are resolved to the vendor entity on your register, not to a similarly named company.

Confirmed before alerting

Duplicates and stale items are filtered. Only a confirmed signal becomes an alert.

Routed with the evidence

The owner receives the source, the severity and the vendor context in one place, and records the response.

Vendor attack surface

An outside-in view of every vendor’s exposure

What attackers can see of a vendor is often the first sign of weakness: a remote desktop port left open, an expired certificate, a deprecated TLS version on a customer-facing login, or a host nobody knew was still running.

  • Score with category breakdown and trend, per vendor
  • Exposed services listed with host, port and severity
  • TLS certificate validity and protocol posture
  • Score drops recorded on the vendor record, with the underlying evidence
  • Shadow infrastructure surfaced alongside the vendor’s declared footprint
  • Complements, never replaces, the evidence-based assessment

Exposed services

Internet-facing services and open ports, prioritized by what they expose.

TLS posture

Certificate validity, expiry and protocol configuration on vendor domains.

Footprint over time

Trend of the score, so a deteriorating vendor is visible before an incident.

From signal to decision

How a signal reaches the vendor record

Monitoring is only useful if it changes something. Every confirmed signal lands on the vendor record and can reshape the assessment cycle.

Monitoring depth by tier: an example policy

CriticalFull signal set
MaterialKey signals
Low riskSanctions and public sources
  1. 01

    Signal detected

    Collection
    Sources are checked across nine monitoring categories. A raw signal is a candidate, not an alert.
  2. 02

    Signal confirmed

    Before anyone is paged
    The signal is matched to the right vendor entity and confirmed. Name collisions, stale news and duplicates are filtered out, so your team sees only what is real.
  3. 03

    Scored and routed

    To the right owner
    The confirmed signal is scored for severity and routed to the vendor owner with the source evidence attached. Monitoring depth per tier follows your policy.
  4. 04

    Recorded on the vendor

    One record
    The signal, its evidence and the owner’s response are stored on the vendor record, next to the assessment and findings, and appear in executive reporting.
  5. 05

    Reassessment triggered

    Outside-in meets inside-out
    A confirmed breach, an indicator of compromise, an enforcement action or a material drop in attack surface score can raise a finding or pull the next point-in-time reassessment forward, instead of waiting for the date your policy sets.
FAQ

Frequently asked questions

What is continuous vendor monitoring?

Continuous monitoring watches for changes in a vendor’s risk between scheduled assessments. It is the outside-in half of the VendRisk360 360 approach: the vendor’s external attack surface, shadow infrastructure, indicators of compromise, breaches and security incidents, adverse news and litigation, regulatory and enforcement actions, and sanctions screening, across nine monitoring categories.

How does monitoring relate to vendor assessments?

An assessment is an inside-out, point-in-time review of the vendor’s controls based on evidence such as SOC reports and penetration tests. Monitoring is the outside-in view that runs continuously between those reviews. Both land on the same vendor record, so a confirmed signal can raise a finding or bring the next reassessment forward. Together they give 360-degree coverage between and across assessments.

What is shadow infrastructure?

Internet-facing assets linked to a vendor that are unknown or unmanaged, such as forgotten hosts, stray subdomains or services outside the footprint the vendor declared. They are often less well maintained than the vendor’s known systems, which makes them a common entry point.

Who triages the signals?

For services customers, the VendRisk360 team triages confirmed signals, follows up with the vendor where needed and records the outcome on the vendor record, where your team sees it. If you run the Vendor Lifecycle Management Platform yourself, confirmed signals can instead be routed straight to your vendor owner.

Is the monitoring done by AI?

No. Monitoring relies on automated collection and scanning of external sources, and signals are matched and confirmed before they alert. Triage and any decision about a vendor are made by people: the VendRisk360 team for services customers, or your own vendor owner on the platform.

What does confirmed-only alerting mean?

A raw signal is not sent to your team until it has been matched to the correct vendor and confirmed. That filters out name collisions, duplicates and stale news, so analysts spend their time on real events rather than triaging noise.

What is the vendor attack surface score?

It summarizes the security posture of a vendor’s internet-facing footprint, such as exposed services and TLS configuration, into a single score with a category breakdown and trend. It is an outside-in indicator that complements, and does not replace, the inside-out, evidence-based assessment.

Can a monitoring signal trigger a reassessment?

Yes. A confirmed signal is recorded on the vendor record and can raise a finding or bring the next reassessment forward, for example after a disclosed breach or an enforcement action.

Is monitoring the same for every vendor?

No. Monitoring depth follows the tier and your policy. A common pattern is the full signal set for Critical vendors, key signals for Material vendors, and sanctions and public-source checks for Low-risk vendors.

Which regulations expect ongoing monitoring?

The US Interagency Guidance on Third-Party Relationships, the EBA Guidelines on outsourcing, DORA, APRA CPS 230, MAS and RBI outsourcing requirements all expect ongoing monitoring proportionate to risk. VendRisk360 is aligned to these expectations; each organization remains responsible for its compliance.

Get started

See VendRisk360 on your own vendors

A tailored walkthrough with a third-party risk specialist, built around your program, your regulators and your vendors.