Risk & operationsThird-Party Risk

Third-Party Risk

Vendor register and TPRM dashboard — criticality, assessment status, evidence, and vendor risks.

Where it lives

Sidebar → Third-Party Risk

  • Dashboard (/tprm)
  • Vendors (/tprm/vendors)

In-page / sidebar tabs

KPI cards plus criticality and status breakdowns. Critical vendors that are not Reviewed are highlighted.

Vendor fields

FieldValues
CategoryCloud, SaaS, Payments, Security, HR, Legal, Marketing, Analytics, Communication, Other
CriticalityCritical, High, Medium, Low
StatusReviewed, Due, Never Assessed

Add vendors

Capture name, owner, category, and criticality. Critical + Never Assessed should not sit idle.

Assess and attach evidence

SOC reports, DPAs, questionnaires. Move status to Reviewed when current.

Log risks

Vendor risks flow to the Risks page so they sit next to control gaps.

Admins create, edit, and archive. Viewers can open the register and dashboard.