Modern third-party risk management for ICT providers.
Replace scattered spreadsheets and mailboxes with a connected lifecycle: inventory, criticality, assessments, evidence, risks, remediation and continuous review.
ICT Providers
142 providers · 18 critical
| Provider | ICT Service | Criticality | Country | Risk |
|---|---|---|---|---|
| Amazon Web Services | Cloud Infrastructure | Critical | Ireland | High |
| Microsoft Ireland | Cloud & Productivity | Critical | Ireland | Medium |
| Stripe Payments Europe | Payment Processing | Critical | Ireland | High |
| Snowflake Netherlands | Data Platform | Important | Netherlands | Medium |
| Cloudflare Germany | Network & Security | Important | Germany | Low |
| Temenos | Core Banking | Critical | Switzerland | Medium |
Lifecycle
Seven stages, one record.
Inventory
Every ICT provider and the services they deliver.
Criticality
Weighted classification with documented rationale.
Assessments
Structured questionnaires with a vendor portal.
Evidence
Certifications and reports with expiry tracking.
Risks
Findings become owned, scored risks.
Remediation
Mitigation plans with due dates and progress.
Continuous review
Reassessment cycles triggered by criticality and change.
Reporting
Board and audit reporting from the same data.
Assessments
Assessments that produce decisions, not PDFs.
- Section-level progress across every vendor
- Evidence requested inside the questionnaire
- Reviewer decisions recorded per response
- Findings convert to risks in one click
ASM-2041 · AWS Annual ICT Assessment
Under Review117 questions · 12 sections · vendor submitted 4 August 2026
Section progress
- Governance & Oversight100%
- Information Security92%
- Business Continuity64%
- Incident Management88%
- Subcontracting45%
Q 4.3 · Business Continuity
Describe the frequency and scope of your disaster recovery testing.
“DR testing is performed periodically across production regions.”
AI Finding
Confidence 94%Disaster recovery testing evidence is missing.
The response describes testing but no test report was attached for the current period. Requires human review before any compliance decision.
Reviewed by Sarah Martin · AI suggestions never change compliance status automatically.
Evidence
Documentation that never silently expires.
- Valid, Expiring, Expired and Missing statuses
- Automated requests to vendor contacts
- Coverage by provider and criticality
- Documents linked to the risks they support
Evidence Library
418 documents · 23 missing · 11 expiring within 60 days
- Expires 30 Nov 2026Valid
SOC 2 Type II
Amazon Web Services
- Expires 21 Mar 2027Valid
ISO 27001
Microsoft Ireland
- Expires 14 Sep 2026Expiring
Penetration Test
Stripe Payments Europe
- Expired 2 Jun 2026Expired
Business Continuity Plan
Snowflake Netherlands
- Requested 4 Aug 2026Missing
Disaster Recovery Test
Amazon Web Services
Remediation
One register for outstanding third-party risk.
- Severity scoring against your risk appetite
- Named owner and due date on every risk
- Acceptance with documented rationale
- Full history for audit
Risk Register
7 high risks · 18 open · linked to assessments, evidence and contracts
| ID | Risk | Provider | Severity | Status | Owner |
|---|---|---|---|---|---|
| RSK-311 | DR testing evidence not provided | AWS | High | Mitigation Planned | S. Martin |
| RSK-318 | Exit strategy absent from contract | Microsoft | High | Open | T. Weber |
| RSK-324 | Subcontractor countries incomplete | Stripe | Medium | In Review | L. Dubois |
| RSK-327 | Pen test older than 12 months | Snowflake | Medium | Open | S. Martin |
| RSK-330 | No documented incident SLA | Temenos | Low | Accepted | M. Rossi |
Workflow
The continuous review loop.
Get your ICT third-party risk under control.
See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.