Skip to content
complianceofficer

Vendor risk management software that watches third party risk continuously

Vendor risk management software keeps the register of every third party that touches your data or your operations: it tiers them by the damage they could do, runs due diligence before you sign, holds the evidence each one gives you (the SOC 2 report, the BAA, the DPA, the insurance certificate), and re-checks them on a schedule instead of once at onboarding. Complianceofficer adds the trigger everyone else misses: when a rule changes or a vendor's posture moves, the affected rows in your register flag themselves.

Scan your third party obligations now

Pick your industry and framework below. The scan returns the obligation register, including the supplier and outsourcing lines, with the last 12 months of movement. No signup, nothing stored.

§ Live · Compliance scan

No signup. Nothing you pick is stored.

Frameworks you answer to

Sample register · fintech, US · what a scan returns

  • § 01 Written AML program with a named officer
  • § 02 KYC and customer due diligence
  • § 03 Sanctions screening lists Changed
  • § 04 PCI DSS v4.0 validation

The vendor register: what gets watched for you

  • § 01 Vendor inventory Every third party, tiered
  • § 02 Due diligence and questionnaires Before you sign
  • § 03 Assurance evidence and bridge letters SOC 2 reports expire
  • § 04 Contract clauses that must exist BAA, DPA, security addendum
  • § 05 Fourth party and concentration risk Subprocessors change quietly
  • § 06 Reassessment schedule By tier, not annually for all
  • § 07 Offboarding and access removal Access outlives the contract
  • § 08 Regulatory expectations Interagency guidance, 2023

The rows that flag are the ones that rot silently. A SOC 2 Type II report covers a stated window and then it is out of date. A subprocessor gets added to a vendor's list and nobody on your side reads the notification email. A contractor leaves and their SSO account lives on for a year. A register only helps if something is re-reading it, which is what the watching loop does.

§ 13 Tiering

Tier the vendors, or drown in questionnaires

The most common failure in third party risk is treating all vendors alike. Sending the same 300 question assessment to your core banking provider and to the company that prints your business cards guarantees the review becomes a formality nobody reads. Tier first, then let the tier decide the depth and the frequency.

Tier Typical vendor Diligence Reassess
Critical Holds regulated data, or you cannot operate without them Full review, SOC 2 Type II or ISO cert, pen test summary, continuity plan Annually, plus on any change
High Touches customer data but is replaceable Security questionnaire, assurance report, contract clauses checked Every 12 to 18 months
Moderate Internal tooling, limited data access Short questionnaire, confirm no regulated data in scope Every 24 months
Low No data, no operational dependency Record the relationship and move on On renewal

US banks and their fintech partners should read this against the Interagency Guidance on Third-Party Relationships issued by the Federal Reserve, FDIC and OCC in June 2023, which sets the supervisory expectation across the full life cycle: planning, due diligence, contracting, ongoing monitoring and termination. If you run AML transaction monitoring through a vendor, that vendor is squarely in scope.

§ 163 The program

A third party risk management program, stage by stage

If you are building the program rather than shopping for the tool, start from the supervisory text rather than from a vendor's feature list. The Interagency Guidance on Third-Party Relationships: Risk Management, issued by the Federal Reserve, FDIC and OCC on 6 June 2023 and published at 88 FR 37920, sets out five life cycle stages. It is written for banking organizations, but it has become the de facto reference structure well outside banking because nothing else in US supervision is this explicit.

The five third party risk life cycle stages in the 2023 Interagency Guidance
Stage What has to happen Where programs fail
Planning Decide whether the activity should be outsourced at all, and what risk it carries before a vendor is in the room Skipped entirely. The first document in most files is a signed order form
Due diligence and selection Assess the candidate against the risk the activity carries, not against a fixed questionnaire Same 300 questions for every vendor, so nobody reads the answers
Contract negotiation Get the obligations into the agreement: audit rights, incident notification, subcontracting limits, data return on exit The only stage where you have leverage, and the one compliance is invited to last
Ongoing monitoring Re-check posture, evidence and performance through the life of the relationship An annual questionnaire treated as monitoring. It is not, it is a periodic reassessment
Termination Get the data back or destroyed, remove access, transition the activity Access outlives the contract. This is the most common finding of the five

Two things are worth pulling out. First, the guidance repeats that practices should be proportionate to the risk, complexity and size of the organization, which is the written basis for tiering rather than treating every supplier alike. Second, contract negotiation is a named stage with its own expectations, and it is the stage where an obligation is cheap to add and expensive to add later. If your program cannot show what it asked for and what it settled for at that stage, it has a gap the tooling will not close.

§ 164 Three products

Vendor risk, supplier risk and supply chain risk are not the same purchase

These three phrases return each other in every search result and they name products bought by different departments for different reasons. Getting this wrong is the most common way a shortlist wastes a quarter, so it is worth thirty seconds before you book demos.

Vendor risk, supplier risk and supply chain risk software compared
Phrase The risk it manages Who owns the budget
Vendor or third party risk management Security, privacy, regulatory and continuity exposure created by anyone you give data or dependency to Compliance, risk, security
Supplier risk management Used both ways. In procurement it usually means financial health, delivery performance and dependency on a supplier Procurement, sourcing
Supply chain risk management Physical and geopolitical disruption: logistics, sanctions exposure, single-source components, tier-two suppliers Supply chain, operations

Complianceofficer sits in the first row. We do not model logistics disruption or score supplier financial health, and a tool that does those things well is usually weak at the regulatory half. The one question that separates a demo in minutes: ask whether the platform tracks the rules that govern the relationship, or only the counterparty. If the answer is only the counterparty, it is a monitoring product and you will still need regulatory change management beside it.

§ 165 The number

What third party risk management platforms cost

Third party risk is rarely sold standalone. It is normally a module inside a larger GRC or privacy suite, which means the price you pay depends on what else you buy and on how the vendor counts. OneTrust states on its own pricing page that Third-Party Risk Management is priced on admin users plus third-party inventory, checked 1 September 2026. That second half is the lever: your bill grows with the number of vendors you record, so an honest, complete register costs more than a partial one.

Recorded buyer data for the suites that carry a TPRM module, re-verified 30 August 2026, puts median annual contracts roughly between $12,000 and $54,000, with individual contracts running from about $1,600 to over $150,000 depending on module count. Implementation is quoted separately and commonly adds 30 to 100 percent of first year license. None of the major vendors publishes a dollar figure on its own pricing page. The full breakdown by vendor is on compliance software pricing, and the entity-counting problem that drives multi-company quotes is worked through on multi-entity compliance software pricing.

One line item is newly worth asking about. Vendors are switching AI features on inside products you already bought, which puts them in your third party register and in your AI inventory at the same time. If you are being asked about both, the overlap is covered on AI governance software.

§ 14 Questions buyers ask

Vendor risk management questions, answered

What is the difference between vendor risk management and third party risk management?

In everyday use they mean the same thing. Where people do separate them, vendor risk management covers suppliers you pay under a contract, and third party risk management is the wider set that also includes partners, agents, resellers and affiliates who create exposure without invoicing you. Regulators generally use the broader term, so if you are writing a policy, write it for third parties.

What is a vendor risk assessment?

It is the structured review you run before signing and then repeat on a schedule: what data the vendor touches, what happens to you if they are breached or go offline, what security evidence they can actually produce, and what the contract obliges them to do about it. The output is a documented risk tier and a decision. The documentation is the part auditors ask for.

What is fourth party risk?

Fourth party risk is the risk sitting inside your vendors' vendors: their subprocessors, cloud hosts and subcontractors. You have no contract with them and usually no visibility, but their outage still becomes your outage. The version regulators care about is concentration risk, where a large share of your critical suppliers quietly depend on the same underlying provider.

How often should vendors be reassessed?

Let the tier decide. Critical vendors get a full review at least annually and again on any material change, such as a new subprocessor, an acquisition, a breach, or an expired assurance report. Lower tiers can run on a longer cycle. A blanket annual review of every vendor sounds rigorous and in practice just produces a queue nobody finishes.

Do I need a BAA or a DPA with my vendors?

It depends on the data. If a vendor creates, receives, maintains or transmits protected health information on your behalf, HIPAA requires a Business Associate Agreement, as covered on our HIPAA compliance software page. If they process personal data of people in the EU or UK on your instructions, GDPR Article 28 requires a data processing agreement, which is covered under GDPR compliance software. Many vendors need both.

What are the five stages of third party risk management?

Planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination. Those are the life cycle stages named in the Interagency Guidance on Third-Party Relationships: Risk Management issued by the Federal Reserve, FDIC and OCC on 6 June 2023 and published at 88 FR 37920. The guidance is addressed to banking organizations, but it is now the reference structure most US programs are written against regardless of sector.

How much does third party risk management software cost?

TPRM is usually a module inside a GRC or privacy suite rather than a standalone purchase, so the price depends on what else you license. Median annual contracts for those suites run roughly $12,000 to $54,000, with implementation quoted separately and commonly adding 30 to 100 percent of first year license. OneTrust states that its Third-Party Risk Management module is priced on admin users plus third-party inventory, so your bill grows as your register gets more complete.

What is the best third party risk management software?

There is no single answer because the shortlists split by what you already own. If you run a privacy program, the TPRM module in that suite usually wins on data reuse alone. If you run SOC 2 automation, your existing platform probably already holds vendor records. If your real problem is that nobody knows which rules govern the relationship, that is a different product. Decide which of those three you are, then compare inside that group rather than across all of them.

Last updated September 2026. Contract and pricing figures checked 1 September 2026. General regulatory information, not legal advice.

Run the compliance scan
§ 66 Naming

Vendor risk, third party risk and supplier risk management software are the same category

Three names, one purchase, and the name you use is mostly a function of which department you sit in. It is worth saying out loud because buyers routinely run parallel evaluations under two of these labels and conclude they need two systems. In almost every case they do not, and the requirements document written by procurement and the one written by security are describing the same platform.

Term Who usually says it What it emphasizes
Vendor risk management software Security, IT and compliance teams Security posture, assurance reports, access and data handling
Third party risk management software Banks, regulated firms and their examiners The full relationship lifecycle, including parties who are not suppliers at all
Supplier risk management software Procurement and operations Continuity, delivery, financial health and concentration

One genuine distinction is worth keeping. Third party is the broadest of the three, because a third party is anyone you have a business arrangement with, not only someone you pay. A referral partner, a joint marketing arrangement or a data recipient is a third party without ever being a vendor or a supplier, and in banking supervision that breadth is the point. If your program was scoped from a procurement list, the relationships most likely to be missing from your register are exactly the ones that never generated a purchase order.

Whichever name your organization uses, the register underneath is the same, and it has to survive both the vendor changing and the rule changing. For the institution-level view see bank compliance software, and for the discipline of catching a supervisory expectation before your next exam does, see regulatory change management.

§ 67

Related registers

§ 99 · Final entry

Get on the early-access list

Leave your work email, confirm the 6-digit code, and we will email you when your spot opens. Nothing is charged before launch.