The board pack, built from live data
Boards and risk committees are accountable for third-party risk, and regulators expect them to show it. VendRisk360 gives directors, executives and examiners the view they need, from the same records your analysts work in, in the formats they already read.
Six questions every board pack must answer
Directors do not need the vendor list. They need to know whether third-party risk is within appetite, what changed and what is being asked of them.
Where are we exposed?
Critical and high residual-risk vendors, the services they support and the data they hold.
What changed since last time?
New critical vendors, rating changes, confirmed monitoring signals and incidents.
Are we doing what our policy says?
Assessments on cadence, overdue reviews, open and past-due findings, SLA adherence.
Where are we concentrated?
Providers, fourth parties and regions that sit under many critical services.
What risk have we accepted?
Active risk acceptances, who approved them and when they expire.
What do you need from us?
Decisions, approvals and escalations for the board or committee to act on.
The whole program on one screen
For the CRO, CISO and head of TPRM between board meetings: where risk sits, which way it is moving and whether the program is keeping up.
Risk heat map
Vendors plotted by likelihood and impact, so concentrations of high residual risk are visible at a glance.
Trends
High residual risk, open findings and overdue reviews over time, to show whether the program is improving.
Program health
Assessment timeliness, SLA adherence, exceptions and open findings, each with a clear on-track, watch or act-now status.
Built the way directors read
Every pack opens with the answer, shows where the organization is exposed and how that is changing, and ends with the decisions the board is asked to make. Exported as PDF or editable PowerPoint in the VendRisk360 format.
A deck for every room you report to
Each deck is written for a specific audience and the decisions it makes. Present in the platform, or export to PDF and editable PowerPoint.
- Generated from live data, not a copy of last quarter
- Present in-app, export to PDF, or export editable PowerPoint
- Consistent structure, so directors know where to look
| Deck | Who it is for | What it answers |
|---|---|---|
| Monthly VRM Board Report | Board and board risk committee | Portfolio at a glance, critical vendors, residual risk trend, overdue items and decisions needed. |
| Executive Risk Briefing | CRO, CEO and executive committee | Top vendor risks, material changes, incidents and the actions under way. |
| Audit Committee / Examiner Readiness | Audit committee and internal audit | Program coverage, assessment timeliness, sign-off evidence and open issues against policy. |
| Regulator / Examiner Meeting | Supervisors and examiners, with compliance | Program structure, inventory, critical relationships, testing and remediation status. |
| Concentration Risk Briefing | Risk committee and operational resilience leads | Provider, fourth-party and regional concentration, and blast radius for key providers. |
| Vendor Incident / Breach Briefing | CISO, incident response and executives | What happened, which vendors and data are affected, notification decisions and next steps. |
| Vendor KPI & Performance Review | Business owners, vendor managers and procurement | Service performance, SLA adherence, open findings and relationship health by vendor. |
| Vendor Approval Pipeline | Procurement, business line heads and TPRM | Vendors in intake, due diligence and assessment, with blockers and expected decisions. |
| Annual TPRM Program Review | Board, for annual program approval | The year in review: program scope, outcomes, trends, policy changes and next year’s priorities. |
In the format the meeting needs, on the day it needs it
Committee secretaries want PDF. CROs want to edit the slides. Analysts want the data. Everyone wants it on time.
Present in the platform
Walk the committee through a deck live, straight from the platform, with no file versions to reconcile.
Board-paper-ready PDF, including vendor risk assessment reports and sign-off certificates.
Editable PowerPoint
Native PowerPoint, not images of slides, so commentary can be added before distribution.
Excel
Registers, findings, performance and questionnaire data for analysis, reconciliation and audit sampling.
Scheduled delivery
Recurring reports to named recipients on your committee calendar.
Every figure traceable. Every exam request answered from the record.
The number on slide three should lead back to the vendors behind it, and the vendor should lead back to the evidence, the finding and the person who signed. That chain is what examiners and internal audit test.
Traceable figures
Board and dashboard figures are calculated from vendor records, so any number can be broken down to the vendors, assessments and findings that produce it.
Examiner package
Assessments, evidence, findings, remediation, risk acceptances, sign-off certificates and audit trail for a vendor or the whole program, assembled on request.
Complete audit trail
Who changed what, who reviewed each item and who approved each stage, with timestamps, exportable for examiners.
Audit Committee / Examiner Readiness
A standing view of whether the program would stand up to an exam today: coverage, timeliness, sign-off evidence and open issues.
Regulator / Examiner Meeting
The opening deck for a supervisory meeting: how the program is structured, what it covers and how critical relationships are overseen.
One source of truth, many audiences
Boards and risk committees
CROs and CISOs
Heads of TPRM
Internal audit and examiners
Figures shown in product screens are illustrative.
Works with the rest of the platform
Vendor Lifecycle Management Platform
Manage vendors, request evidence, review, record and sign off
Learn moreVendor lifecycle
Intake to offboarding in one governed record
Learn moreNth-Party Intelligence
Fourth parties, concentration and systemic risk, CUECs
Learn moreComprehensive Vendor Risk Assessment
You onboard the vendor; our certified assessors do the rest
Learn moreContinuous Monitoring
Outside-in monitoring: attack surface, shadow infrastructure, compromise
Learn moreReport-Specific Reviews
SOC report, information security and business continuity reviews
Learn moreFrequently asked questions
What should a third-party risk board report include?
Directors need a short answer to six questions: where are we exposed, what changed, are we following our policy, where are we concentrated, what risk have we accepted and what decisions do you need from us. The Monthly VRM Board Report is structured around those questions, with detail available behind every figure.
Which decks are included?
Nine ready-made decks: Monthly VRM Board Report, Vendor KPI & Performance Review, Executive Risk Briefing, Audit Committee / Examiner Readiness, Vendor Approval Pipeline, Vendor Incident / Breach Briefing, Concentration Risk Briefing, Annual TPRM Program Review and Regulator / Examiner Meeting.
Can we edit the decks before the meeting?
Yes. Every deck can be presented in the platform, exported to PDF for committee papers, or exported as an editable PowerPoint file so the CRO or head of TPRM can add commentary and context.
Where do the numbers come from?
From the same vendor records analysts work in: assessments, findings, risk acceptances, monitoring signals and fourth-party data. There is no separate reporting spreadsheet, so each figure can be traced back to the vendors behind it.
Can reports be delivered automatically?
Yes. Reports can be scheduled to named recipients on a recurring cadence, such as monthly for the board risk committee or quarterly for the audit committee.
What is in the examiner package?
The examiner package assembles assessments, evidence, findings, remediation, risk acceptances, sign-off certificates and the audit trail for a vendor or for the program, so an exam or internal audit request is answered from the record rather than rebuilt by hand.
See VendRisk360 on your own vendors
A tailored walkthrough with a third-party risk specialist, built around your program, your regulators and your vendors.