Every vendor, from intake to exit, in one record
Scope each relationship at intake, set its depth of due diligence by criticality, contract with conditions, monitor between reviews, reassess on cadence and exit with evidence. One governed workflow, one audit trail, for every vendor, supplier and outsourcing arrangement.
Most TPRM failures happen between the assessments
Examiners rarely criticize a single assessment. They criticize the inventory that missed a vendor, the review that lapsed, and the exit nobody can evidence.
The same vendor, five times
One questionnaire for everyone
Reviews that quietly lapse
Exits with no evidence
A lifecycle you can walk an examiner through
Each stage has an owner, required evidence and an exit condition. Nothing moves forward until it is met, and every decision is recorded.
Reassessment cadence by tier: an example policy
Cadence is set by your policy and enforced by the platform. Confirmed monitoring signals, new services or new data types can bring any date forward.
- 01
Intake
Business ownerThe request captures the business case, the services, the business units that will rely on them and the data types in scope. Business case plus data types decide control applicability, so the assessment asks only what matters for this relationship. A new engagement with an existing vendor joins that vendor’s record instead of creating a second one. - 02
Due diligence
TPRM teamInherent risk and criticality set the tier. Sanctions screening and public-source checks run first. The vendor is invited to the vendor portal with a request list sized to its tier, from a short attestation for Low-risk vendors to SOC reports, penetration tests, BCP and DR test results and financials for Critical ones. - 03
Assessment
Analyst and reviewerA point-in-time, inside-out review of the vendor’s controls across 30+ control domains, based on the artifacts it provided. Your analysts review the evidence, record ratings, findings and notes, and sign off. SOC reports are reviewed for exceptions, carve-outs, subservice organizations and CUECs. With Comprehensive Vendor Risk Assessment Services, VendRisk360 assessors perform the assessment for you. - 04
Contracting
Procurement and legalFindings that must close before signature become pre-contract conditions. Residual risk goes through the risk acceptance workflow where needed, and multi-stage sign-off with segregation of duties issues a sign-off certificate. Contract and renewal dates are recorded on the vendor record and drive the next review. - 05
Monitoring
OngoingContinuous, outside-in monitoring across the vendor’s external attack surface, shadow infrastructure, indicators of compromise, breaches and security incidents, adverse news and litigation, regulatory and enforcement actions and sanctions. Alerts fire only after a signal is confirmed, and each lands on the vendor record for the owner to act on. - 06
Reassessment
Cadence or triggerEach tier follows the reassessment cadence set in your policy, for example annual for Critical vendors, and the platform tracks every due date. A confirmed high-severity signal, a new service or a new data type can bring the date forward. Recertification asks owners to confirm the relationship, its services and its tier, and reconciles the answers against the register. - 07
Offboarding
ExitAn offboarding case tracks termination steps: access revocation, return or destruction of data with certificates, transition of services, and final invoices or obligations. Exit evidence is stored on the record, and the history remains for audit and examination.
Ask the right questions, of the right vendor
Two intake answers do most of the work: why the business needs the vendor, and what data it will touch. From those, VendRisk360 derives which control domains apply and how deep the review goes.
- Business case, services and relying business units captured up front
- Data types in scope: personal data, cardholder data, PHI, confidential and regulated data
- Control applicability derived automatically, then adjustable by the analyst with a reason
- One record per vendor: new engagements join the existing record
Business case
Outsourced card payment processing
Data types
Control domains in scope
- Access management
- Encryption and key management
- Business continuity and DR
- Incident response and notification
- Subcontractor oversight
- Privacy and data retention
Illustrative example
Recertify what you have. Exit what you no longer need.
An inventory is only as good as its last reconciliation. Exits are only as good as their evidence.
Recertification and reconciliation
On a set cadence, relationship owners confirm each vendor is still in use, which services it provides, which data it handles and whether the tier still fits. VendRisk360 reconciles the answers against the register and flags drift: a Low-risk vendor now handling customer data, or an owner who has left.
- Owner attestations with a recorded response
- Tier and data-type changes routed for review
- Orphaned relationships reassigned, not lost
Offboarding with exit evidence
DORA, the EBA outsourcing guidelines and APRA CPS 230 all expect documented exit strategies for critical services. When a relationship ends, an offboarding case tracks each step and stores the proof.
- Access revocation confirmed
- Data return or destruction certificates stored
- Service transition and final obligations closed
- History retained for auditors and examiners
Vendors work their stage in the vendor portal
Due diligence requests, questionnaires, evidence and remediation all go through one portal with one-time-code access. Your team tracks progress from the lifecycle board instead of an inbox.
Whatever your regulator calls it
The discipline has a different name in every market. The platform structures the same lifecycle to the vocabulary and records each regime expects.
| Market or sector | What it is called | Key references |
|---|---|---|
| United States | Third-party relationships | Interagency Guidance (Fed, FDIC, OCC), NCUA for credit unions and CUSOs, FFIEC |
| European Union | ICT third-party arrangements, outsourcing | DORA register of information, critical or important functions, EBA Guidelines on outsourcing |
| United Kingdom | Outsourcing and third-party risk | PRA SS2/21, material outsourcing, operational resilience |
| Australia | Material service providers | APRA CPS 230 and CPG 230, material arrangements |
| Singapore | Material outsourcing | MAS Guidelines on Outsourcing |
| India | Outsourcing of IT services | RBI Master Direction on outsourcing of IT services, material outsourcing |
| Healthcare | Business associates | HIPAA business associate agreements and safeguards |
| SaaS and data processors | Sub-processors | GDPR Article 28 processor and sub-processor obligations |
VendRisk360 is aligned to these frameworks. Each organization remains responsible for its own compliance.
See global regulatory coverageWorks with the rest of the platform
Vendor Lifecycle Management Platform
Manage vendors, request evidence, review, record and sign off
Learn moreNth-Party Intelligence
Fourth parties, concentration and systemic risk, CUECs
Learn moreBoard & Executive Reporting
Board packs, executive briefings and examiner-ready exports
Learn moreComprehensive Vendor Risk Assessment
You onboard the vendor; our certified assessors do the rest
Learn moreContinuous Monitoring
Outside-in monitoring: attack surface, shadow infrastructure, compromise
Learn moreReport-Specific Reviews
SOC report, information security and business continuity reviews
Learn moreFrequently asked questions
What is vendor lifecycle management?
Vendor lifecycle management is governing each third-party relationship from the first request through due diligence, contracting, ongoing monitoring, periodic reassessment and termination. Regulators in the US, EU, UK, Australia, Singapore and India all describe this lifecycle, and expect the depth of oversight to match the criticality of the service.
How does intake decide which controls apply?
The requester states the business case and the data types the vendor will access or process, such as customer personal data, cardholder data or protected health information. VendRisk360 uses both answers to determine which control domains apply, so the questionnaire and evidence list fit the relationship.
How often are vendors reassessed?
Cadence follows the tier, and your own TPRM policy sets it. A common pattern is annual reassessment for Critical vendors, a longer interval for Material vendors and review at contract renewal for Low-risk vendors. The platform enforces whatever cadence you configure. Confirmed monitoring signals, new services or new data types can trigger an earlier reassessment.
Can the vendor record serve as our DORA register of information or outsourcing register?
The vendor record holds the relationships, services, criticality, contract dates, locations and subcontractors that registers such as the DORA register of information, the EBA outsourcing register and APRA CPS 230 material arrangements draw on, and the data exports to Excel. Your compliance team remains responsible for the final regulatory submission and its format.
What does offboarding record?
An offboarding case tracks each exit step and stores the evidence: access revocation, data return or destruction certificates, service transition and closure of obligations. The vendor record and its history remain available to auditors after the relationship ends.
What is recertification?
Recertification periodically asks each relationship owner to confirm the vendor is still in use, which services it provides, which data it handles and whether the tier is still right. The answers are reconciled against the register so stale or misclassified relationships are corrected.
See VendRisk360 on your own vendors
A tailored walkthrough with a third-party risk specialist, built around your program, your regulators and your vendors.