Know every vendor that touches your data
A living vendor inventory, risk tiers, assessments and subprocessors, security and privacy findings, and remediation tracked to closure — the third-party layer your RoPA and DPA reviews depend on.
Vendor & Third-Party Risk
Workspace · Vendor risk
| Vendor | Tier | Assessment | Findings | Remediation | Next review |
|---|---|---|---|---|---|
| Northwind Cloud | Tier 1 | Current | 3 open | 66% | Sep 2 |
| Helios Analytics | Tier 2 | Due Aug 19 | 5 open | 40% | Aug 19 |
| Cedar HR Suite | Tier 1 | Current | 0 open | 100% | Nov 8 |
| Atlas Messaging | Tier 3 | Not started | — | 0% | Aug 30 |
| Quartz Email | Tier 2 | Current | 2 open | 80% | Oct 1 |
Portfolio by tier
128 vendors- Tier 1 · Critical19
- Tier 2 · High34
- Tier 3 · Moderate41
- Tier 4 · Low34
Data residency & flows
Where vendors process your dataSecurity & privacy findings
8 high-severity open| Finding | Vendor | Severity | Status |
|---|---|---|---|
| No encryption at rest | Helios | High | In progress |
| Subprocessor undisclosed | Atlas | High | Open |
| SOC 2 expired | Quartz | Medium | In progress |
| No breach-notice SLA | Northwind | Medium | Remediated |
Vendor & Third-Party Risk capabilities
Vendor Risk keeps a current inventory of every third party that processes personal data, tiers them by risk, and drives assessments on a cadence that matches the tier. Findings from security and privacy reviews become remediation items tracked to closure, and subprocessor chains stay mapped so nothing hides one layer down.
Vendor inventory
A single register of every third party that processes personal data, linked to the contracts, systems and activities that rely on them.
Risk tiering
Vendors are scored and tiered by data sensitivity and access, setting assessment cadence and approval requirements automatically.
Assessments
Send, collect and score security and privacy questionnaires on a schedule that matches each vendor's tier.
Subprocessor mapping
Trace the subprocessor chain behind each vendor so onward processing never hides a layer below the surface.
Security & privacy findings
Turn assessment answers and evidence review into structured findings, ranked by severity and linked to the vendor record.
Remediation tracking
Every finding carries an owner, due date and status, tracked to closure with a full remediation history.
Outcomes teams feel
Vendor & Third-Party Risk is one module of a connected platform — the value compounds as its records link to the rest of your privacy operations.
- No blind spots downstreamSubprocessor mapping and a live inventory mean you can answer where your data goes — including the vendors your vendors use.
- Effort where risk isTiering focuses assessments on critical vendors and lightens the load on low-risk ones, instead of one cadence for all.
- Findings that closeRemediation tracking turns a list of issues into resolved work, with evidence that each was actually fixed.
Connected, not siloed
Records created here flow into adjacent modules automatically — a vendor here becomes a counterparty in DPA Review and an entry in your RoPA.
See Vendor & Third-Party Risk on your own data
Book a walkthrough and we will show Vendor & Third-Party Risk running against a workflow your team actually owns — connected to the rest of PrivacyPoint.