Skip to content

Third-Party Risk Management

The Third-Party Risk domain (/third-party-risk) enables organizations to manage vendor relationships, assess third-party security postures, and monitor supplier compliance.


Key Capabilities

  • Vendor Catalog: Maintain records of all active third parties and technology vendors.
  • Risk Tiering: Classify vendors into risk tiers based on business criticality and data access levels.
  • Supplier Engagements: Track individual vendor engagements with canonical business references (ENG-YYYY-NNNN).
  • Security Assessments: Record questionnaire results, SOC reports, and compliance certifications.

OrviQ Enterprise Governance, Risk & Compliance Platform