Third-Party Governance
The whole supplier life, on one record
A dedicated suite covering the full supplier lifecycle, from a governed onboarding front door to offboarding, aligned with enterprise risk. Each supplier is entered once and known across data protection, cybersecurity, legal and risk.

The supplier lifecycle, end to end
Four stages that carry a supplier from first contact to offboarding, each feeding the next without re-keying.
Identify and onboard
A governed front door
Suppliers enter through an onboarding wizard, a master supplier register and procurement intake, so nothing arrives through the side door.
- Supplier onboarding wizard
- Master supplier register
- Procurement intake

Tier and classify
Know which suppliers matter
Criticality assessment and inherent-risk scoring rank the portfolio, and a DORA register captures your critical ICT service providers.
- Criticality assessment
- Inherent risk scoring
- DORA ICT register

Assess
Due diligence in one vocabulary
Campaigns of four kinds, onboarding, periodic, trigger-based and renewal, dispatch questionnaires to a supplier response portal, with structured due diligence in the same risk vocabulary as enterprise risk.
- Four campaign types
- Supplier response portal
- Structured due diligence

Treat, monitor and offboard
The full working life
Issue tracking, contract management, performance scorecards and SLA tracking through the relationship, a dependency map and concentration-risk analysis across it, and a governed offboarding workflow at the end.
- Contracts and SLA tracking
- Dependency map
- Concentration-risk analysis

Where third-party risk meets enterprise risk
Supplier governance is not a silo here. It shares the same register, the same vocabulary and the same supplier record as the rest of the platform.
Aligned with enterprise risk
Supplier exposures link directly into the enterprise risk register, scored in the same vocabulary, so third-party risk is part of the enterprise view rather than a separate spreadsheet.
One shared supplier entity
Each supplier exists once and is visible across data protection, cybersecurity, legal and risk. Update it in one place and every domain sees the change.
DORA register built in
A register for critical ICT service providers, kept alongside the assessments and contracts that support it, ready when the regulator asks.
Concentration risk, made visible
A dependency map and concentration-risk analysis surface where too much rests on one supplier, before that concentration becomes a problem.
Performance scorecards
Scorecards and SLA tracking give each relationship a running record of how it is actually performing, not just how it was scoped.
Renewal, never a surprise
Renewal pipelines and campaign scheduling mean the next review and the next contract date arrive on the calendar, not in the inbox at the last minute.
Bring every supplier onto one record
Onboard through a governed front door, assess in the same vocabulary as your risk register, and keep the whole relationship in view through to offboarding.