Third-party risk (TPRM)
Assess and monitor the vendors you depend on.
The module answers one question in a way a regulator can follow: how much risk does this vendor carry, and what is that judgement based on?
| Where | What it holds |
|---|---|
| Vendors | The register — who you depend on, tiered. |
| Assessments | The questionnaire-driven assessment chain. |
| Findings | Gaps found, and their remediation. |
| Dashboard | Portfolio view — ratings, overdue reviews, open findings. |
| Reports | Vendor risk register, findings ageing, assessment history. |
The one idea to take away
Scores are derived, never typed. A vendor's answers do not count until an assessor has validated them, and residual risk is computed from those validated answers. That is what separates an assessment from an opinion, and it is why the workflow has a validation step you cannot skip.