Third-Party Risk Management
Vendor security reports read, judged against your requirements, and followed up.
- Cadence
- Ongoing, by vendor tier
- Pricing
- Scoped to your environment after the assessment.
- Family
- Governance and risk
The problem
Vendor SOC 2 reports and questionnaires arrive as long PDFs nobody reads. Exceptions and the controls you are expected to run go unnoticed until an auditor asks.
What you get
- An inventory of vendors, ranked by the data they hold
- A review of each vendor's SOC 2 report or questionnaire
- Exceptions, and the complementary controls you must run
- Follow-up requests drafted for your approval
How it works
Step 1: Share your vendor list
From your contracts, or from the apps in your identity provider.
Step 2: Agents read the reports
SOC 2 reports and questionnaires summarized against your requirements.
Step 3: An expert judges the risk
Exceptions weighed, follow-ups recommended.
Step 4: You approve any change
Requests to vendors go out only with your approval. Every approval is logged.
Access we need
- Vendor reports and questionnaires you already hold
- Read-only access to the app list in your identity provider, if you want it included
What we never do
- We never contact a vendor without your approval.
- We never keep copies of vendor reports.
The full access model is on the security and trust page.
Related services
- Identity Assurance
Access reviews that finish, every quarter.
- Audit and Questionnaire Support
Evidence organized, answers drafted for your approval.
Questions about Third-Party Risk Management?
Tell us what you run and what you need, and we will reply with next steps.