Vendor risk management software that watches third party risk continuously
Vendor risk management software keeps the register of every third party that touches your data or your operations: it tiers them by the damage they could do, runs due diligence before you sign, holds the evidence each one gives you (the SOC 2 report, the BAA, the DPA, the insurance certificate), and re-checks them on a schedule instead of once at onboarding. Complianceofficer adds the trigger everyone else misses: when a rule changes or a vendor's posture moves, the affected rows in your register flag themselves.
Scan your third party obligations now
Pick your industry and framework below. The scan returns the obligation register, including the supplier and outsourcing lines, with the last 12 months of movement. No signup, nothing stored.
§ Live · Compliance scan
No signup. Nothing you pick is stored.
Sample register · fintech, US · what a scan returns
- § 01 Written AML program with a named officer
- § 02 KYC and customer due diligence
- § 03 Sanctions screening lists Changed
- § 04 PCI DSS v4.0 validation
The vendor register: what gets watched for you
- § 01 Vendor inventory Every third party, tiered
- § 02 Due diligence and questionnaires Before you sign
- § 03 Assurance evidence and bridge letters SOC 2 reports expire
- § 04 Contract clauses that must exist BAA, DPA, security addendum
- § 05 Fourth party and concentration risk Subprocessors change quietly
- § 06 Reassessment schedule By tier, not annually for all
- § 07 Offboarding and access removal Access outlives the contract
- § 08 Regulatory expectations Interagency guidance, 2023
The rows that flag are the ones that rot silently. A SOC 2 Type II report covers a stated window and then it is out of date. A subprocessor gets added to a vendor's list and nobody on your side reads the notification email. A contractor leaves and their SSO account lives on for a year. A register only helps if something is re-reading it, which is what the watching loop does.
Tier the vendors, or drown in questionnaires
The most common failure in third party risk is treating all vendors alike. Sending the same 300 question assessment to your core banking provider and to the company that prints your business cards guarantees the review becomes a formality nobody reads. Tier first, then let the tier decide the depth and the frequency.
| Tier | Typical vendor | Diligence | Reassess |
|---|---|---|---|
| Critical | Holds regulated data, or you cannot operate without them | Full review, SOC 2 Type II or ISO cert, pen test summary, continuity plan | Annually, plus on any change |
| High | Touches customer data but is replaceable | Security questionnaire, assurance report, contract clauses checked | Every 12 to 18 months |
| Moderate | Internal tooling, limited data access | Short questionnaire, confirm no regulated data in scope | Every 24 months |
| Low | No data, no operational dependency | Record the relationship and move on | On renewal |
US banks and their fintech partners should read this against the Interagency Guidance on Third-Party Relationships issued by the Federal Reserve, FDIC and OCC in June 2023, which sets the supervisory expectation across the full life cycle: planning, due diligence, contracting, ongoing monitoring and termination. If you run AML transaction monitoring through a vendor, that vendor is squarely in scope.
A third party risk management program, stage by stage
If you are building the program rather than shopping for the tool, start from the supervisory text rather than from a vendor's feature list. The Interagency Guidance on Third-Party Relationships: Risk Management, issued by the Federal Reserve, FDIC and OCC on 6 June 2023 and published at 88 FR 37920, sets out five life cycle stages. It is written for banking organizations, but it has become the de facto reference structure well outside banking because nothing else in US supervision is this explicit.
| Stage | What has to happen | Where programs fail |
|---|---|---|
| Planning | Decide whether the activity should be outsourced at all, and what risk it carries before a vendor is in the room | Skipped entirely. The first document in most files is a signed order form |
| Due diligence and selection | Assess the candidate against the risk the activity carries, not against a fixed questionnaire | Same 300 questions for every vendor, so nobody reads the answers |
| Contract negotiation | Get the obligations into the agreement: audit rights, incident notification, subcontracting limits, data return on exit | The only stage where you have leverage, and the one compliance is invited to last |
| Ongoing monitoring | Re-check posture, evidence and performance through the life of the relationship | An annual questionnaire treated as monitoring. It is not, it is a periodic reassessment |
| Termination | Get the data back or destroyed, remove access, transition the activity | Access outlives the contract. This is the most common finding of the five |
Two things are worth pulling out. First, the guidance repeats that practices should be proportionate to the risk, complexity and size of the organization, which is the written basis for tiering rather than treating every supplier alike. Second, contract negotiation is a named stage with its own expectations, and it is the stage where an obligation is cheap to add and expensive to add later. If your program cannot show what it asked for and what it settled for at that stage, it has a gap the tooling will not close.
Vendor risk, supplier risk and supply chain risk are not the same purchase
These three phrases return each other in every search result and they name products bought by different departments for different reasons. Getting this wrong is the most common way a shortlist wastes a quarter, so it is worth thirty seconds before you book demos.
| Phrase | The risk it manages | Who owns the budget |
|---|---|---|
| Vendor or third party risk management | Security, privacy, regulatory and continuity exposure created by anyone you give data or dependency to | Compliance, risk, security |
| Supplier risk management | Used both ways. In procurement it usually means financial health, delivery performance and dependency on a supplier | Procurement, sourcing |
| Supply chain risk management | Physical and geopolitical disruption: logistics, sanctions exposure, single-source components, tier-two suppliers | Supply chain, operations |
Complianceofficer sits in the first row. We do not model logistics disruption or score supplier financial health, and a tool that does those things well is usually weak at the regulatory half. The one question that separates a demo in minutes: ask whether the platform tracks the rules that govern the relationship, or only the counterparty. If the answer is only the counterparty, it is a monitoring product and you will still need regulatory change management beside it.
What third party risk management platforms cost
Third party risk is rarely sold standalone. It is normally a module inside a larger GRC or privacy suite, which means the price you pay depends on what else you buy and on how the vendor counts. OneTrust states on its own pricing page that Third-Party Risk Management is priced on admin users plus third-party inventory, checked 1 September 2026. That second half is the lever: your bill grows with the number of vendors you record, so an honest, complete register costs more than a partial one.
Recorded buyer data for the suites that carry a TPRM module, re-verified 30 August 2026, puts median annual contracts roughly between $12,000 and $54,000, with individual contracts running from about $1,600 to over $150,000 depending on module count. Implementation is quoted separately and commonly adds 30 to 100 percent of first year license. None of the major vendors publishes a dollar figure on its own pricing page. The full breakdown by vendor is on compliance software pricing, and the entity-counting problem that drives multi-company quotes is worked through on multi-entity compliance software pricing.
One line item is newly worth asking about. Vendors are switching AI features on inside products you already bought, which puts them in your third party register and in your AI inventory at the same time. If you are being asked about both, the overlap is covered on AI governance software.
Vendor risk management questions, answered
What is the difference between vendor risk management and third party risk management?
In everyday use they mean the same thing. Where people do separate them, vendor risk management covers suppliers you pay under a contract, and third party risk management is the wider set that also includes partners, agents, resellers and affiliates who create exposure without invoicing you. Regulators generally use the broader term, so if you are writing a policy, write it for third parties.
What is a vendor risk assessment?
It is the structured review you run before signing and then repeat on a schedule: what data the vendor touches, what happens to you if they are breached or go offline, what security evidence they can actually produce, and what the contract obliges them to do about it. The output is a documented risk tier and a decision. The documentation is the part auditors ask for.
What is fourth party risk?
Fourth party risk is the risk sitting inside your vendors' vendors: their subprocessors, cloud hosts and subcontractors. You have no contract with them and usually no visibility, but their outage still becomes your outage. The version regulators care about is concentration risk, where a large share of your critical suppliers quietly depend on the same underlying provider.
How often should vendors be reassessed?
Let the tier decide. Critical vendors get a full review at least annually and again on any material change, such as a new subprocessor, an acquisition, a breach, or an expired assurance report. Lower tiers can run on a longer cycle. A blanket annual review of every vendor sounds rigorous and in practice just produces a queue nobody finishes.
Do I need a BAA or a DPA with my vendors?
It depends on the data. If a vendor creates, receives, maintains or transmits protected health information on your behalf, HIPAA requires a Business Associate Agreement, as covered on our HIPAA compliance software page. If they process personal data of people in the EU or UK on your instructions, GDPR Article 28 requires a data processing agreement, which is covered under GDPR compliance software. Many vendors need both.
What are the five stages of third party risk management?
Planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination. Those are the life cycle stages named in the Interagency Guidance on Third-Party Relationships: Risk Management issued by the Federal Reserve, FDIC and OCC on 6 June 2023 and published at 88 FR 37920. The guidance is addressed to banking organizations, but it is now the reference structure most US programs are written against regardless of sector.
How much does third party risk management software cost?
TPRM is usually a module inside a GRC or privacy suite rather than a standalone purchase, so the price depends on what else you license. Median annual contracts for those suites run roughly $12,000 to $54,000, with implementation quoted separately and commonly adding 30 to 100 percent of first year license. OneTrust states that its Third-Party Risk Management module is priced on admin users plus third-party inventory, so your bill grows as your register gets more complete.
What is the best third party risk management software?
There is no single answer because the shortlists split by what you already own. If you run a privacy program, the TPRM module in that suite usually wins on data reuse alone. If you run SOC 2 automation, your existing platform probably already holds vendor records. If your real problem is that nobody knows which rules govern the relationship, that is a different product. Decide which of those three you are, then compare inside that group rather than across all of them.
Last updated September 2026. Contract and pricing figures checked 1 September 2026. General regulatory information, not legal advice.
Run the compliance scanVendor risk, third party risk and supplier risk management software are the same category
Three names, one purchase, and the name you use is mostly a function of which department you sit in. It is worth saying out loud because buyers routinely run parallel evaluations under two of these labels and conclude they need two systems. In almost every case they do not, and the requirements document written by procurement and the one written by security are describing the same platform.
| Term | Who usually says it | What it emphasizes |
|---|---|---|
| Vendor risk management software | Security, IT and compliance teams | Security posture, assurance reports, access and data handling |
| Third party risk management software | Banks, regulated firms and their examiners | The full relationship lifecycle, including parties who are not suppliers at all |
| Supplier risk management software | Procurement and operations | Continuity, delivery, financial health and concentration |
One genuine distinction is worth keeping. Third party is the broadest of the three, because a third party is anyone you have a business arrangement with, not only someone you pay. A referral partner, a joint marketing arrangement or a data recipient is a third party without ever being a vendor or a supplier, and in banking supervision that breadth is the point. If your program was scoped from a procurement list, the relationships most likely to be missing from your register are exactly the ones that never generated a purchase order.
Whichever name your organization uses, the register underneath is the same, and it has to survive both the vendor changing and the rule changing. For the institution-level view see bank compliance software, and for the discipline of catching a supervisory expectation before your next exam does, see regulatory change management.
Related registers
- Continuous Compliance Monitoring
- Compliance Monitoring Software
- Compliance Software Cost
- Enterprise Compliance Software for CCOs and CISOs
- GRC Software and Governance Risk Compliance Software
- GDPR Compliance Software
- Compliance Automation Software
- AML Transaction Monitoring Plus Regulatory Watch
- SOC 2 Compliance Software Beyond Audit Readiness
- Policy Compliance Software and Policy Compliance Tracking
- Policy Attestation Software and Acknowledgement Tracking
- Regulatory Change Management Software, Tools and Platform
- HIPAA Compliance Software with Security Risk Analysis
- ISO 27001 Software for ISMS Compliance and Audit Evidence
- PCI Compliance Software Tied to PCI DSS 4.0.1
- Audit Management Software for Continuous Readiness
- SOX Compliance
- Segregation of Duties Software
- Financial Services Compliance Software for RIAs and BDs
- 21 CFR Part 11 Compliant Software, GxP Compliance Software
- ITGC Controls Software for SOX IT General Controls Audits
- Compliance Reporting Software and Compliance Dashboards
- SOX Compliance Software for SOX 404 Controls
- Best Compliance Software in 2026, Compared
- CMMC Compliance Software for DoD Contractors
- Enterprise Risk Management Software
- Compliance Software Pricing Comparison
- Healthcare Compliance Software for OIG Compliance Programs
- Bank Compliance Software for Financial Institutions, BSA/AML
- AI Compliance Software
- AML Compliance Software with KYC and Sanctions Screening
- Regulatory Compliance Software with Compliance Tracking
- CCPA Compliance Software, Data Privacy Management Software
- Enterprise Risk Assessment Software, Risk Assessment Tools
- AI Governance Tool, Platform and Software for US Teams
- Business Continuity Plan Software, BCM and Disaster Recovery
- SOX 404(b) Compliance Software, Requirements and Threshold
- Integrated Risk Management Software, IRM Platform and Tools
- Vanta Alternative for Regulatory Change Monitoring
- Drata Alternative Focused on Regulatory Change
- Secureframe Alternative for Regulatory Change
- Sprinto Alternative for Regulatory Change
- AuditBoard Alternative (Now Optro) for Regulatory Change
- OneTrust Competitors
- Workiva Competitors and Alternatives
§ 99 · Final entry
Get on the early-access list
Leave your work email, confirm the 6-digit code, and we will email you when your spot opens. Nothing is charged before launch.