Third-Party Risk
Vendor register and TPRM dashboard — criticality, assessment status, evidence, and vendor risks.
Where it lives
Sidebar → Third-Party Risk
- Dashboard (
/tprm) - Vendors (
/tprm/vendors)
In-page / sidebar tabs
KPI cards plus criticality and status breakdowns. Critical vendors that are not Reviewed are highlighted.
Searchable table. Open a vendor for the slide-over: notes, evidence, and linked risks. Add or edit from the modal. Delete archives (soft-delete) the vendor.
Vendor fields
| Field | Values |
|---|---|
| Category | Cloud, SaaS, Payments, Security, HR, Legal, Marketing, Analytics, Communication, Other |
| Criticality | Critical, High, Medium, Low |
| Status | Reviewed, Due, Never Assessed |
Add vendors
Capture name, owner, category, and criticality. Critical + Never Assessed should not sit idle.
Assess and attach evidence
SOC reports, DPAs, questionnaires. Move status to Reviewed when current.
Log risks
Vendor risks flow to the Risks page so they sit next to control gaps.
Admins create, edit, and archive. Viewers can open the register and dashboard.
Was this page helpful?