Skip to content
AI-ASSISTEDThird-party risk platform and expert services

Complete
Vendor Risk Intelligence

Manage the vendor lifecycle. Assess comprehensive risk. Monitor continuously. Stay ahead of emerging threats with 360° coverage: evidence-based review from the inside, continuous monitoring from the outside.

  • Built for regulated industries
  • SSO and mandatory MFA
  • Tenant-isolated data

Aligned to regulators and standards worldwide

Interagency TPRM GuidanceOCC 2023-17FFIECNCUADORAEBA OutsourcingGDPRNIS2PRA SS2/21APRA CPS 230RBIMASSAMAHIPAANIST CSF 2.0NIST AI RMFISO/IEC 27001ISO/IEC 27701SOC 2PCI DSS v4.0Interagency TPRM GuidanceOCC 2023-17FFIECNCUADORAEBA OutsourcingGDPRNIS2PRA SS2/21APRA CPS 230RBIMASSAMAHIPAANIST CSF 2.0NIST AI RMFISO/IEC 27001ISO/IEC 27701SOC 2PCI DSS v4.0
The 360 in VendRisk360

Inside‑out and outside‑in. Every vendor, all year.

A point-in-time assessment tells you how a vendor looked on the day it was reviewed. VendRisk360 pairs evidence-based review of the vendor's controls with continuous monitoring of what the outside world can see, so risk that changes between assessments does not go unnoticed.

Inside-out

Point‑in‑time, evidence‑based review

  • Controls reviewed against your policySecurity, resilience, privacy and AI use, scoped by business case, data and tier.
  • Evidence complete and currentSOC reports, penetration tests, continuity tests, insurance and financials, checked for completeness, expiry and scope.
  • Findings and remediationGaps raised with the vendor and tracked to closure.
  • Expert sign-offRated and signed off by certified assessors or your own reviewers.

Outside-in

Continuous, independent monitoring

  • External attack surfaceExposed services, TLS and configuration posture across vendor domains.
  • Shadow infrastructureUnknown or unmanaged internet-facing assets that belong to the vendor.
  • Indicators of compromiseSigns of compromise, breaches and security incidents linked to the vendor.
  • Adverse news and regulatory actionLitigation, enforcement, sanctions and financial distress.
AssessmentContinuous monitoring between assessmentsReassessmentSignal can trigger early review
Why teams switch

Third-party risk, without the spreadsheets

Most programs still run on questionnaires, inboxes and a review that is out of date the day it is signed. Here is what changes, line by line.

  • Vendor inventory

    Spreadsheets, inboxes and shared drives, each with a different version of the truth

    One record per vendor, product and relationship, with owner, tier and full history

  • Depth of review

    The same long questionnaire for every vendor, whatever the risk

    Criticality tiering decides the depth, so critical vendors get full due diligence and low-risk ones do not

  • Evidence

    Self-attested answers accepted at face value; expired reports go unnoticed

    Answers checked against evidence, with SOC reports and certificates tracked for scope and expiry

  • Between assessments

    A point-in-time snapshot that is out of date the day after sign-off

    Continuous outside-in monitoring of attack surface, breaches, adverse news and regulatory actions

  • Fourth parties

    Invisible until one of them causes an incident

    Nth-party intelligence maps who your vendors depend on and where concentration risk sits

  • Vendor experience

    Email chains, attachments and repeated chasing

    A secure vendor portal for questionnaires, documents and remediation, with reminders built in

  • Decisions and audit

    Approvals and risk acceptances scattered across email; audits mean weeks of reconstruction

    Policy-based sign-off, risk acceptance with owners and expiry dates, and a complete audit trail

  • Reporting

    Board packs assembled by hand each quarter

    Board and executive reporting generated from live data, ready for examiners

  • AI

    Either no automation, or black-box scores nobody can explain

    Optional AI that drafts and extracts, while your people review and make every decision

Platform and services

Everything third-party risk needs, in one place

From intake to offboarding, every vendor, supplier and outsourcing arrangement gets one record, one risk rating and one audit trail, with assessments, monitoring and reporting working from the same data.

Platform

Vendor Lifecycle Management Platform

Your team manages every vendor, sends due diligence requests, reviews, records and signs off, with every step tracked.

  • Intake scoped by business case and data types
  • Criticality tiering and reassessment cadence
  • Contracts, SLAs and performance reviews
  • Exit plans and offboarding evidence
Learn more
Service

Comprehensive Vendor Risk Assessment

You onboard the vendor. Our certified assessors collect the evidence, assess the risk and follow up on findings.

CriticalMaterialLow risk
  • Depth scaled to Critical, Material and Low-risk vendors
  • Evidence collected, checked and followed up for you
  • Expert assessment with second-expert review
Learn more
Service

Continuous Monitoring

Outside-in coverage between assessments, with signals confirmed before they reach your team.

  • External attack surface and exposed services
  • Shadow infrastructure
  • Indicators of compromise, breaches and incidents
  • Adverse news and regulatory action
Learn more
Add-on serviceReport-Specific ReviewsTargeted expert reviews with a written report for each vendor. Order on their own or with the platform and services.SOC Report ReviewInformation Security Program ReviewBusiness Continuity Program ReviewExplore
Vendor lifecycle management

One vendor record, from intake to exit

Onboarding, due diligence, monitoring, reassessment and offboarding share one record, so nothing is re-keyed and every decision has its evidence behind it. Step through the stages.

Stage 1 of 6

Every new vendor starts with the right questions

The business owner requests a vendor in a guided intake. Answers about data, access and criticality set the tier, so the depth of review is decided before anyone sends a questionnaire.

  • Guided intake for business owners, no spreadsheet templates
  • Criticality tier set from data sensitivity, access and business impact
  • Duplicate check against vendors you already have
See the full lifecycle

Payments processor

Example vendor record

Intake submitted
Tier 1: CriticalHandles customer data
Business owner
Payments team
Review depth
Full due diligence
Next step
Evidence request
Confirm tier and start review

Review depth by tier

Critical
Full assessment, for example yearly, plus continuous monitoring
Material
Focused assessment, for example every two years
Low risk
Streamlined review, for example at contract renewal

Tiers, evidence, sign-off and cadence follow your own policy. How tiers work

Two ways to run your program

Your team on our platform, or our team end to end

Run third-party risk yourself on the Vendor Lifecycle Management Platform, or engage Comprehensive Vendor Risk Assessment Services: you onboard the vendor and our certified assessors do the rest.

Self-managedVendor Lifecycle Management Platform

Your team manages vendors, requests evidence, performs and records the review, and signs off. Every step is tracked.

Most comprehensive
Delivered by VendRisk360Comprehensive Vendor Risk Assessment Services

You onboard the vendor. VendRisk360 experts do the rest, with near real-time progress for every vendor.

Vendor onboarding and tiering
Platform: Your team
Managed: You onboard the vendor; we confirm scope and tier
Due diligence and evidence requests
Platform: Your team sends requests through the vendor portal
Managed: VendRisk360 requests evidence and follows up with the vendor
Evidence completeness and key dates
Platform: Your team
Managed: Our assessors, with optional AI-assisted checks
SOC report review
Platform: Your team, or add a SOC Report Review
Managed: Included, with CUECs mapped to your controls
Risk assessment and rating
Platform: Your analysts review and record
Managed: Certified assessors, with second-expert quality review
Findings and remediation
Platform: Your team tracks to closure
Managed: VendRisk360 raises and follows up with the vendor
Continuous monitoring
Platform: Signals on the platform
Managed: Signals triaged by VendRisk360
Sign-off and accountability
Platform: Your reviewers
Managed: Your reviewers keep final approval
Progress and audit trail
Platform: Tracked on the platform
Managed: Near real-time progress for every vendor
Add-on service

Report-Specific Reviews

Need one report reviewed, not a full assessment? Our assessors deliver a targeted review and a written report for each vendor.

  • SOC Report Review: SOC 1 and SOC 2, including CUECs and carve-outs
  • Information Security Program Review
  • Business Continuity Program Review
  • Expert review, with optional AI assistance you can switch on or off
Explore report-specific reviews

Assessments and reviews by certified, experienced assessors

CISSPCISACISMCRISCISO/IEC 27001 Lead AuditorISO/IEC 27001 Lead ImplementerPCI DSS implementation
Board & executive reporting

The view your board and executives actually ask for

Directors want to know where the organization is exposed, what changed since the last meeting and what they are being asked to decide. VendRisk360 answers from live data, in the format a board reads, and every number traces back to the vendor record behind it.

Board and committee packs

Nine ready-made decks, from the monthly board report to exam readiness.

Executive command view

Residual risk trend, heat map, concentration and decisions needed.

PDF and editable PowerPoint

One click, in a consistent professional format.

Traceable to the record

Every figure links to the vendor, evidence and approval behind it.

See board and executive reporting
Where AI is used

Optional AI, clearly scoped. People make every decision.

AI is a choice, not a dependency. If you opt in, it assists in two places only. Every review, rating and sign-off is done by an expert assessor or by your own reviewers.

ActivityAI involvement
Vendor lifecycle workflow on the platformNo AI required
Evidence completeness and key datesOptional AI assistance
SOC report reviewOptional AI-assisted first pass
Information security and business continuity reviewsExpert assessors
Risk ratings, findings and sign-offAlways people
Continuous monitoringAutomated scanning, confirmed before alerting

Example: optional AI-assisted completeness check and key-date extraction, verified by an assessor.

See it in action

What changes when your program runs on VendRisk360

Three moments that used to take weeks of email and spreadsheets, and now take minutes.

Continuous monitoring

Stop learning about vendor risk at the annual review

Between assessments, VendRisk360 watches each vendor from the outside. When something changes, you see what changed, which vendor and service it affects, who owns the relationship and what to do next.

  • Attack surface, breaches, adverse news, sanctions and regulatory actions, confirmed before they alert
  • Every signal tied to the right vendor and service, and routed to its owner
  • Detection, reassessment and decision closed in one record, with the reasons kept for audit
Continuous Monitoring
Global regulatory coverage

One platform for every regulator you answer to

Whether you call it third-party risk, outsourcing, ICT third-party risk or material service providers, the platform structures your program and evidence to the rules in your market.

North America
Interagency TPRM GuidanceOCC Bulletin 2023-17FFIECNCUANYDFS 23 NYCRR 500
Europe & UK
DORAEBA Outsourcing GuidelinesEIOPA Cloud GuidelinesNIS2GDPR
India, Asia & Middle East
RBI IT Outsourcing DirectionsSEBI CSCRFDPDP ActMAS Outsourcing GuidelinesSAMA
Australia & New Zealand
APRA CPS 230APRA CPS 234Privacy Act 1988NZ Privacy Act 2020
Security first

Built like the security products it assesses

SSO and mandatory MFA

SAML and OIDC single sign-on, with a second factor required on every password login.

Tenant isolation

Row-level security keeps each customer’s data separate at the database layer.

Encryption everywhere

TLS in transit and encryption at rest for records and uploaded evidence.

Complete audit trail

Every decision, sign-off and change is logged and exportable for examiners.

Get started

See VendRisk360 on your own vendors

A tailored walkthrough with a third-party risk specialist, built around your program, your regulators and your vendors.