PlatformModulesVendor Risk
Vendor RiskThird-party governance

Know every vendor that touches your data

A living vendor inventory, risk tiers, assessments and subprocessors, security and privacy findings, and remediation tracked to closure — the third-party layer your RoPA and DPA reviews depend on.

128 vendors
Under governance
4 risk tiers
Continuously scored
Subprocessor
Chains mapped
PrivacyPointVendor risk

Vendor & Third-Party Risk

Workspace · Vendor risk

Active vendors128 +7 this quarter
Tier 1 (critical)19 all assessed
Open findings27 8 high
Assessments due9 next 30 days

Vendor inventory

128 vendors · tiered by data riskOpen inventory
VendorTierAssessmentFindingsRemediationNext review
Northwind CloudTier 1Current3 open66%Sep 2
Helios AnalyticsTier 2Due Aug 195 open40%Aug 19
Cedar HR SuiteTier 1Current0 open100%Nov 8
Atlas MessagingTier 3Not started0%Aug 30
Quartz EmailTier 2Current2 open80%Oct 1

Portfolio by tier

128 vendors
  • Tier 1 · Critical19
  • Tier 2 · High34
  • Tier 3 · Moderate41
  • Tier 4 · Low34

Data residency & flows

Where vendors process your data
11
countries
UKLondonUSVirginia
Active transfer routeUK → US · SCC Module Two

Security & privacy findings

8 high-severity open
FindingVendorSeverityStatus
No encryption at restHeliosHighIn progress
Subprocessor undisclosedAtlasHighOpen
SOC 2 expiredQuartzMediumIn progress
No breach-notice SLANorthwindMediumRemediated
What it does

Vendor & Third-Party Risk capabilities

Vendor Risk keeps a current inventory of every third party that processes personal data, tiers them by risk, and drives assessments on a cadence that matches the tier. Findings from security and privacy reviews become remediation items tracked to closure, and subprocessor chains stay mapped so nothing hides one layer down.

Vendor inventory

A single register of every third party that processes personal data, linked to the contracts, systems and activities that rely on them.

Risk tiering

Vendors are scored and tiered by data sensitivity and access, setting assessment cadence and approval requirements automatically.

Assessments

Send, collect and score security and privacy questionnaires on a schedule that matches each vendor's tier.

Subprocessor mapping

Trace the subprocessor chain behind each vendor so onward processing never hides a layer below the surface.

Security & privacy findings

Turn assessment answers and evidence review into structured findings, ranked by severity and linked to the vendor record.

Remediation tracking

Every finding carries an owner, due date and status, tracked to closure with a full remediation history.

Why it matters

Outcomes teams feel

Vendor & Third-Party Risk is one module of a connected platform — the value compounds as its records link to the rest of your privacy operations.

  • No blind spots downstreamSubprocessor mapping and a live inventory mean you can answer where your data goes — including the vendors your vendors use.
  • Effort where risk isTiering focuses assessments on critical vendors and lightens the load on low-risk ones, instead of one cadence for all.
  • Findings that closeRemediation tracking turns a list of issues into resolved work, with evidence that each was actually fixed.
In the platform

Connected, not siloed

Records created here flow into adjacent modules automatically — a vendor here becomes a counterparty in DPA Review and an entry in your RoPA.

Vendor Risk

See Vendor & Third-Party Risk on your own data

Book a walkthrough and we will show Vendor & Third-Party Risk running against a workflow your team actually owns — connected to the rest of PrivacyPoint.