Skip to content
Board & executive reporting

The board pack, built from live data

Boards and risk committees are accountable for third-party risk, and regulators expect them to show it. VendRisk360 gives directors, executives and examiners the view they need, from the same records your analysts work in, in the formats they already read.

What directors ask

Six questions every board pack must answer

Directors do not need the vendor list. They need to know whether third-party risk is within appetite, what changed and what is being asked of them.

01

Where are we exposed?

Critical and high residual-risk vendors, the services they support and the data they hold.

02

What changed since last time?

New critical vendors, rating changes, confirmed monitoring signals and incidents.

03

Are we doing what our policy says?

Assessments on cadence, overdue reviews, open and past-due findings, SLA adherence.

04

Where are we concentrated?

Providers, fourth parties and regions that sit under many critical services.

05

What risk have we accepted?

Active risk acceptances, who approved them and when they expire.

06

What do you need from us?

Decisions, approvals and escalations for the board or committee to act on.

Executive dashboards

The whole program on one screen

For the CRO, CISO and head of TPRM between board meetings: where risk sits, which way it is moving and whether the program is keeping up.

Risk heat map

Vendors plotted by likelihood and impact, so concentrations of high residual risk are visible at a glance.

Trends

High residual risk, open findings and overdue reviews over time, to show whether the program is improving.

Program health

Assessment timeliness, SLA adherence, exceptions and open findings, each with a clear on-track, watch or act-now status.

Inside the board pack

Built the way directors read

Every pack opens with the answer, shows where the organization is exposed and how that is changing, and ends with the decisions the board is asked to make. Exported as PDF or editable PowerPoint in the VendRisk360 format.

Nine ready-made decks

A deck for every room you report to

Each deck is written for a specific audience and the decisions it makes. Present in the platform, or export to PDF and editable PowerPoint.

  • Generated from live data, not a copy of last quarter
  • Present in-app, export to PDF, or export editable PowerPoint
  • Consistent structure, so directors know where to look
DeckWho it is forWhat it answers
Monthly VRM Board ReportBoard and board risk committeePortfolio at a glance, critical vendors, residual risk trend, overdue items and decisions needed.
Executive Risk BriefingCRO, CEO and executive committeeTop vendor risks, material changes, incidents and the actions under way.
Audit Committee / Examiner ReadinessAudit committee and internal auditProgram coverage, assessment timeliness, sign-off evidence and open issues against policy.
Regulator / Examiner MeetingSupervisors and examiners, with complianceProgram structure, inventory, critical relationships, testing and remediation status.
Concentration Risk BriefingRisk committee and operational resilience leadsProvider, fourth-party and regional concentration, and blast radius for key providers.
Vendor Incident / Breach BriefingCISO, incident response and executivesWhat happened, which vendors and data are affected, notification decisions and next steps.
Vendor KPI & Performance ReviewBusiness owners, vendor managers and procurementService performance, SLA adherence, open findings and relationship health by vendor.
Vendor Approval PipelineProcurement, business line heads and TPRMVendors in intake, due diligence and assessment, with blockers and expected decisions.
Annual TPRM Program ReviewBoard, for annual program approvalThe year in review: program scope, outcomes, trends, policy changes and next year’s priorities.
Formats and delivery

In the format the meeting needs, on the day it needs it

Committee secretaries want PDF. CROs want to edit the slides. Analysts want the data. Everyone wants it on time.

Present in the platform

Walk the committee through a deck live, straight from the platform, with no file versions to reconcile.

PDF

Board-paper-ready PDF, including vendor risk assessment reports and sign-off certificates.

Editable PowerPoint

Native PowerPoint, not images of slides, so commentary can be added before distribution.

Excel

Registers, findings, performance and questionnaire data for analysis, reconciliation and audit sampling.

Scheduled delivery

Recurring reports to named recipients on your committee calendar.

Exam readiness

Every figure traceable. Every exam request answered from the record.

The number on slide three should lead back to the vendors behind it, and the vendor should lead back to the evidence, the finding and the person who signed. That chain is what examiners and internal audit test.

Traceable figures

Board and dashboard figures are calculated from vendor records, so any number can be broken down to the vendors, assessments and findings that produce it.

Examiner package

Assessments, evidence, findings, remediation, risk acceptances, sign-off certificates and audit trail for a vendor or the whole program, assembled on request.

Complete audit trail

Who changed what, who reviewed each item and who approved each stage, with timestamps, exportable for examiners.

Audit Committee / Examiner Readiness

A standing view of whether the program would stand up to an exam today: coverage, timeliness, sign-off evidence and open issues.

Regulator / Examiner Meeting

The opening deck for a supervisory meeting: how the program is structured, what it covers and how critical relationships are overseen.

Who it serves

One source of truth, many audiences

Boards and risk committees

Oversight of third-party risk against appetite, with the decisions they are asked to make.

CROs and CISOs

Top exposures, incidents and concentration, with the detail to answer follow-up questions.

Heads of TPRM

Program health and pipeline, and a board pack that no longer takes a week to assemble.

Internal audit and examiners

Coverage, timeliness and evidence, traceable from summary to source.

Figures shown in product screens are illustrative.

FAQ

Frequently asked questions

What should a third-party risk board report include?

Directors need a short answer to six questions: where are we exposed, what changed, are we following our policy, where are we concentrated, what risk have we accepted and what decisions do you need from us. The Monthly VRM Board Report is structured around those questions, with detail available behind every figure.

Which decks are included?

Nine ready-made decks: Monthly VRM Board Report, Vendor KPI & Performance Review, Executive Risk Briefing, Audit Committee / Examiner Readiness, Vendor Approval Pipeline, Vendor Incident / Breach Briefing, Concentration Risk Briefing, Annual TPRM Program Review and Regulator / Examiner Meeting.

Can we edit the decks before the meeting?

Yes. Every deck can be presented in the platform, exported to PDF for committee papers, or exported as an editable PowerPoint file so the CRO or head of TPRM can add commentary and context.

Where do the numbers come from?

From the same vendor records analysts work in: assessments, findings, risk acceptances, monitoring signals and fourth-party data. There is no separate reporting spreadsheet, so each figure can be traced back to the vendors behind it.

Can reports be delivered automatically?

Yes. Reports can be scheduled to named recipients on a recurring cadence, such as monthly for the board risk committee or quarterly for the audit committee.

What is in the examiner package?

The examiner package assembles assessments, evidence, findings, remediation, risk acceptances, sign-off certificates and the audit trail for a vendor or for the program, so an exam or internal audit request is answered from the record rather than rebuilt by hand.

Get started

See VendRisk360 on your own vendors

A tailored walkthrough with a third-party risk specialist, built around your program, your regulators and your vendors.