Companies whose customers, regulators, or auditors are asking about their vendors.
Third-party risk shows up in every framework you already answer to: SOC 2 CC9.2, ISO 27001 A.5.19–A.5.23, NIST CSF 2.0 GV.SC, CMMC's flow-down obligations, HIPAA business-associate requirements, and the FFIEC's third-party guidance for financial institutions. Yet in most mid-sized organizations vendor assessments are a spreadsheet, a stale questionnaire, and a SOC 2 report nobody read. We build the program — and the AI-vendor extension of it — so the answer to "how do you manage third-party risk" is a process, not a person.
What you getFrom onboarding to offboarding, governed.
- Program design — policy, inherent-risk tiering model, assessment depth by tier, roles across procurement, legal, security, and the business, and KPIs the steering committee will read.
- Vendor inventory and tiering — a complete register of third parties with data access, criticality, and regulatory exposure scored, so effort goes where the risk is.
- Due-diligence toolkit — questionnaires aligned to SIG / CAIQ, a SOC 2 report review checklist, and an AI-specific module covering training on customer data, retention, subprocessors, and model-change notification.
- Contract security requirements — standard clause set for security, privacy, breach notification, audit rights, and AI terms, plus a review process for redlines.
- Ongoing monitoring — reassessment cadence by tier, triggers for change, and integration with your GRC platform (Optro, ServiceNow, Archer) or a lightweight register if you do not have one.
Right-sized rigor, by tier.
Inventory and tier
Pull vendors from AP, procurement, and SSO logs; score inherent risk; agree the tiers. A 200-vendor company typically has 10–20 that deserve deep review.
Assess and contract
Deep assessments for Tier 1, attestation review for Tier 2, self-attestation for Tier 3 — and contract terms that match the tier.
Monitor and report
Reassessment triggers, SOC 2 bridge-letter tracking, and a quarterly TPRM dashboard for the risk committee.
Know which of your vendors could take you down.
Start with a 20-minute call and a look at your current vendor list.