Onboard, assess and manage every vendor
Centralise your vendor register, criticality levels, questionnaires and regulatory information in one place.
Overview
A complete vendor ecosystem view
Track supplier details, NIS2-related data, CPV codes and custom fields tailored to your compliance requirements, alongside criticality levels, data tiers, certifications and reviews.
Manage third-party information alongside compliance, risk and inventory data, creating a centralised view of your vendor ecosystem.
Challenge and solution
Supplier details, contracts, questionnaire answers and security ratings sit in different tools, so nobody can say which critical vendors are assessed, which processors are in scope, or which contracts are missing a DPA.
Integrates with the ResilientX TPRM platform to send questionnaires to suppliers and continuously monitor their cyber posture, collecting data in a single place next to contracts, sub-processors and customers.
Features
What the Third Parties module includes
Suppliers
Inventory, criticality, data tiers, certifications, reviews and risk scoring for every vendor.
Sub-processor register
Article 28 register with CSV export, shared with the Privacy module.
Customers
The organisations you provide services to, with their requirements and contracts.
Contracts
Central register of agreements: DPAs, MSAs and SLAs, linked to the parties they bind.
TPRM integration
Send questionnaires and continuously monitor cyber posture through ResilientX TPRM.
NIS2 vendor data
NIS2-related fields, CPV codes and custom attributes tailored to your compliance requirements.
See ResilientX GRC in action
Third Parties module FAQ
How does it work with ResilientX TPRM?
The module integrates with the ResilientX TPRM platform: questionnaires are sent to suppliers from there and their cyber posture is monitored continuously, with results stored on the vendor record in GRC.
Can we export the sub-processor register?
Yes. The Article 28 sub-processor register can be exported as CSV whenever a customer or authority asks for it.
Does it track contracts?
Yes. DPAs, MSAs, SLAs and other agreements live in a central contract register linked to the suppliers and customers they bind.