The purpose of the third-party risk management module is to provide comprehensive support for the evaluation of services provided by vendors (supporting multiple types of assessments), including risk ratings and risk management. The processes implemented in the system enable the resource-efficient and reportable maintenance of risk assessments for even a large number of vendor services.

During implementation, the system’s assessment configuration can also accommodate existing questionnaires and methodologies.

Registration of Vendors and Services

Registration of vendors and the services they provide (ICT services), including their types, lifecycle information and classification.

Survey and risk methodologies

The system allows for the creation of several different questionnaires and the corresponding survey types.

Questionnaire features:

  • Questions regarding data management, policies, and controls, as well as customizable questions
  • Multilingual support based on the vendor’s language of communication
  • File upload capabilities, vendor document management, with security controls
  • Management of branching paths and conditional options within the questionnaire
  • Customizable information sheet for the vendors
  • Vendor certificate management

Survey types:

  • Questionnaire version management
  • Scoring, weighting, and risk methodology settings, tailored to the survey type
  • Survey workflow settings
Third-Party Risk Assessments

We can evaluate vendors and the services they provide based on security considerations (and other factors) appropriate to the type of assessment, using sophisticated questionnaires and associated risk analysis processes.

The following are supported during third-party risk assessment and management:

  • Workflow management
  • In addition to vendor and TPRM assessor roles, a business owner review/approval workflow step can be included as needed
  • Deadline and automatic reminder management
  • Customizable email templates
  • Detailed event and email logs for each assessment
  • Comment management among stakeholders
  • Support and management of up to several hundred assessments simultaneously
  • Results overview and review support
  • Support for mitigation tasks and phases
  • Document, file, and evidence management
  • Risk value and classification reports
  • Assessment report export
  • Support for review cycle periods
  • Management and review of archived (previous cycle) surveys

Additional features for vendor-facing questionnaires:

  • Validation checks before submitting a questionnaire
  • Comment management
  • Self-service vendor export of their own submitted data
  • Temporary unique links with passcode options
  • Vendors manage their “own” temporary document repository during their work, from which they can reference files.
Managing Mitigation Phase

For deficiencies identified during assessments, a mitigation phase can be initiated by defining mitigation tasks, all the way to on-site audit support. A separate risk rating can be calculated for the mitigation phase.

Service deployment

The TPRM module is available:

  • As SeCube GRC Kürt SaaS service
  • As on-premises system

In the on-premises case, the system architecture has been secure designed, supplemented with file upload protection features and with product support for hardening configurations.

TPRM

    top