Buyer's guide

Choosing a vendor risk management tool

How to tell a questionnaire engine from a risk programme, what to test in a trial, and the questions that separate the two.

relynt.io/providers

ICT Providers

96 providers · 18 critical

Add ICT Provider
AllCriticalHigh RiskAssessment OverdueMissing Evidence
ProviderICT ServiceCriticalityCountryRisk
Halcyon Cloud ServicesCloud InfrastructureCriticalIrelandHigh
Northwind Cloud IrelandCloud & ProductivityCriticalIrelandMedium
Payflux Payments EuropePayment ProcessingCriticalIrelandHigh
Lumendata NetherlandsData PlatformImportantNetherlandsMedium
Edgeway GermanyNetwork & SecurityImportantGermanyLow
ValteraCore BankingCriticalSwitzerlandMedium

What to test

Six things to try in a trial.

Ask what happens after the questionnaire comes back

Collecting answers is the easy half. The question is whether a poor answer becomes an owned, dated risk with a mitigation plan, or a PDF in a folder.

Send yourself a questionnaire

Sit in the vendor's seat. Does the link work, can they save and come back, can they attach evidence against a specific answer, and can they ask you a question? Vendor-side friction is why response rates collapse.

Check the evidence expires

A SOC 2 report is valid for a year. A tool that records the document but not the date it stops counting will tell you a lapsed provider is covered.

Look for the fourth party

Your provider's providers are where concentration risk hides. If subcontractors are a free-text box, nobody will ever query them.

Test the tiering, not the template library

Every tool ships SIG and CAIQ. Few make the inherent-risk decision first, which is what stops a payroll supplier receiving 855 questions.

Decide whether you need the register

If you are an EU financial entity, third-party risk and the Register of Information are the same dataset seen twice. Buying tools that each hold half of it is how the reporting date gets unpleasant.

Fit

When this is the wrong product

A buyer's guide that cannot say who a product is wrong for is an advertisement. These are the cases where you should buy something else.

  • You are not in scope for DORA. Much of what Relynt does is shaped by a regulation that will not apply to you.
  • You want continuous security ratings or attack-surface scanning. Relynt records what providers tell you and what they prove, not an external score.
  • You manage thousands of suppliers across procurement, ESG and financial risk. This is ICT third-party risk.
  • You want the vendor's own trust centre. Different side of the transaction.
  • Send yourself a questionnaire and answer it
  • Let an evidence document expire
  • Add a subcontractor and query by country
  • Turn a bad answer into a dated risk

FAQ

Frequently asked questions

What is the difference between TPRM and vendor risk management?
In practice the terms are used interchangeably. Where a distinction is drawn, vendor risk management covers the commercial relationship as well, and third-party risk management is the risk discipline alone. DORA is narrower than both: it is about ICT third-party service providers.
How many questions should a vendor questionnaire have?
It depends on what the vendor does for you, which is the whole point of tiering. A screening set of ten to fifteen questions decides that; SIG Lite is 126 questions and SIG Core is 855. Sending the long one to everybody is the most common way a programme dies.
Do we need to assess every supplier?
Under DORA the obligation attaches to ICT third-party service providers, with the heaviest requirements where a critical or important function depends on them. The first job is deciding which of your suppliers those are, and recording why.
Can this replace spreadsheets?
For the inventory, the assessments, the evidence expiry and the Register, yes. Most teams keep a spreadsheet for something regardless, and a tool that cannot export cleanly to one is a trap rather than a solution.

Test it on your own register.

The free validator takes a package or a single template straight from your spreadsheet, needs no account, and reads the file in your browser.

Choosing a vendor risk management tool | Relynt