Skip to content
Manage external risk

Third-Party Risk Management

Continuously understand and manage third-party risk. Auto-tier vendors, run due diligence, track contracts and SLAs, and give vendors a self-service portal so questionnaires don't disappear in inboxes.

Add-on module — attaches to GRC Professional or Enterprise Governance

Third-Party Risk Management module dashboard

Vendor Inventory & Tiering

Centralize every vendor with auto-tiering by risk, spend, and data sensitivity. Inherent → residual scoring per tier.

Self-Service Vendor Portal

Vendors complete questionnaires in their browser, upload SOC 2s and pen-test reports, and answer follow-ups without a single email thread.

Due Diligence Workflows

Pre-onboarding assessments, recurring re-assessments, and offboarding workflows with full audit trail.

Obligations

Track contractual security commitments — encryption, breach notification windows, audit rights — and alert when they're at risk.

SLA Monitoring

Define vendor SLAs, monitor against them, and surface breaches before they hit your customers.

Fourth-Party Visibility

See your vendors' vendors. Know which sub-processors handle your data and where the chain of custody breaks.

Deep dive

Vendors do the work, you keep the receipts

Send a questionnaire, the vendor completes it in their portal, you get a notification when they're done. No Excel sheets, no chasing, no version drift. Every answer becomes evidence in your compliance program automatically.

Vendors do the work, you keep the receipts

See Third-Party Risk Management in action.

Start a 7-day trial and run it on your own program — then buy online in-app when you're ready.

No credit card required.