Skip to content
complianceofficer

Vendor risk management software that watches third party risk continuously

Vendor risk management software keeps the register of every third party that touches your data or your operations: it tiers them by the damage they could do, runs due diligence before you sign, holds the evidence each one gives you (the SOC 2 report, the BAA, the DPA, the insurance certificate), and re-checks them on a schedule instead of once at onboarding. Complianceofficer adds the trigger everyone else misses: when a rule changes or a vendor's posture moves, the affected rows in your register flag themselves.

Scan your third party obligations now

Pick your industry and framework below. The scan returns the obligation register, including the supplier and outsourcing lines, with the last 12 months of movement. No signup, nothing stored.

§ Live · Compliance scan

No signup. Nothing you pick is stored.

Frameworks you answer to

Sample register · fintech, US · what a scan returns

  • § 01 Written AML program with a named officer
  • § 02 KYC and customer due diligence
  • § 03 Sanctions screening lists Changed
  • § 04 PCI DSS v4.0 validation

The vendor register: what gets watched for you

  • § 01 Vendor inventory Every third party, tiered
  • § 02 Due diligence and questionnaires Before you sign
  • § 03 Assurance evidence and bridge letters SOC 2 reports expire
  • § 04 Contract clauses that must exist BAA, DPA, security addendum
  • § 05 Fourth party and concentration risk Subprocessors change quietly
  • § 06 Reassessment schedule By tier, not annually for all
  • § 07 Offboarding and access removal Access outlives the contract
  • § 08 Regulatory expectations Interagency guidance, 2023

The rows that flag are the ones that rot silently. A SOC 2 Type II report covers a stated window and then it is out of date. A subprocessor gets added to a vendor's list and nobody on your side reads the notification email. A contractor leaves and their SSO account lives on for a year. A register only helps if something is re-reading it, which is what the watching loop does.

§ 13 Tiering

Tier the vendors, or drown in questionnaires

The most common failure in third party risk is treating all vendors alike. Sending the same 300 question assessment to your core banking provider and to the company that prints your business cards guarantees the review becomes a formality nobody reads. Tier first, then let the tier decide the depth and the frequency.

Tier Typical vendor Diligence Reassess
Critical Holds regulated data, or you cannot operate without them Full review, SOC 2 Type II or ISO cert, pen test summary, continuity plan Annually, plus on any change
High Touches customer data but is replaceable Security questionnaire, assurance report, contract clauses checked Every 12 to 18 months
Moderate Internal tooling, limited data access Short questionnaire, confirm no regulated data in scope Every 24 months
Low No data, no operational dependency Record the relationship and move on On renewal

US banks and their fintech partners should read this against the Interagency Guidance on Third-Party Relationships issued by the Federal Reserve, FDIC and OCC in June 2023, which sets the supervisory expectation across the full life cycle: planning, due diligence, contracting, ongoing monitoring and termination. If you run AML transaction monitoring through a vendor, that vendor is squarely in scope.

§ 14 Questions buyers ask

Vendor risk management questions, answered

What is the difference between vendor risk management and third party risk management?

In everyday use they mean the same thing. Where people do separate them, vendor risk management covers suppliers you pay under a contract, and third party risk management is the wider set that also includes partners, agents, resellers and affiliates who create exposure without invoicing you. Regulators generally use the broader term, so if you are writing a policy, write it for third parties.

What is a vendor risk assessment?

It is the structured review you run before signing and then repeat on a schedule: what data the vendor touches, what happens to you if they are breached or go offline, what security evidence they can actually produce, and what the contract obliges them to do about it. The output is a documented risk tier and a decision. The documentation is the part auditors ask for.

What is fourth party risk?

Fourth party risk is the risk sitting inside your vendors' vendors: their subprocessors, cloud hosts and subcontractors. You have no contract with them and usually no visibility, but their outage still becomes your outage. The version regulators care about is concentration risk, where a large share of your critical suppliers quietly depend on the same underlying provider.

How often should vendors be reassessed?

Let the tier decide. Critical vendors get a full review at least annually and again on any material change, such as a new subprocessor, an acquisition, a breach, or an expired assurance report. Lower tiers can run on a longer cycle. A blanket annual review of every vendor sounds rigorous and in practice just produces a queue nobody finishes.

Do I need a BAA or a DPA with my vendors?

It depends on the data. If a vendor creates, receives, maintains or transmits protected health information on your behalf, HIPAA requires a Business Associate Agreement, as covered on our HIPAA compliance software page. If they process personal data of people in the EU or UK on your instructions, GDPR Article 28 requires a data processing agreement, which is covered under GDPR compliance software. Many vendors need both.

Last updated July 2026. General regulatory information, not legal advice.

Run the compliance scan

§ 99 · Final entry

Get on the early-access list

Leave your work email, confirm the 6-digit code, and we will email you when your spot opens. Nothing is charged before launch.