Appearance
Third-Party Risk Management
The Third-Party Risk domain (/third-party-risk) enables organizations to manage vendor relationships, assess third-party security postures, and monitor supplier compliance.
Key Capabilities
- Vendor Catalog: Maintain records of all active third parties and technology vendors.
- Risk Tiering: Classify vendors into risk tiers based on business criticality and data access levels.
- Supplier Engagements: Track individual vendor engagements with canonical business references (
ENG-YYYY-NNNN). - Security Assessments: Record questionnaire results, SOC reports, and compliance certifications.