Third-Party Risk Management

Vendor risk management in the same platform, not a separate tool.

Classify vendors by tier, send AI-scored assessments through a white-labeled portal, track findings to resolution and connect vendor posture to the controls their systems implement for you — without another subscription or another login.

Book a Demo Start Free
White-label vendor portalAI-scored assessmentsEvidence vault & gap analysisLinked to your risk register
G2 Summer 2026 High Performer badges — RealCISO ranked #1 vCISO platformSourceForge Leader Award, Summer 2026
4.8/5 · 223 reviews · Read reviews on SourceForge

4.8/5 across 223 reviews on SourceForge · #1 vCISO platform on G2, Summer 2026

$100
per month as an add-on · unlimited vendors
Included
on Enterprise · unlimited on Enterprise Plus and Complete
0–100
Composite vendor risk score
1
Login, data model and vendor record for compliance and vendor risk

Standalone TPRM tools run $10K–$30K+ a year. See RealCISO pricing →

The Problem

TPRM is usually a second vendor, a second login and a second invoice

Or it's a spreadsheet of questionnaires you send and never hear back on. Either way you are managing vendor risk outside the platform where it matters — disconnected from the controls vendors are supposed to help you satisfy. Meanwhile the auditor is asking: who are your critical vendors, have you assessed them, what's their risk score? And you're pulling it together from three places.

How It Works

The TPRM flow in RealCISO

1

Classify your vendors

Add vendors to the registry and assign a risk tier — Critical, High, Medium, Low — based on what they do: data access, infrastructure, authentication, development tools. Each tier sets score thresholds, review frequency and required evidence.

2

Define what you're assessing

Questionnaire templates from a built-in library or your own, with conditional sub-questions and scoping by tier, access type and held certifications. Sent assessments use a snapshot, so edits never change one in flight.

3

Send the assessment

A token-based portal link — your brand, your domain, no vendor account. Yes/No/N/A answers, comments, file uploads, auto-saved; revision requests show your notes beside their answers.

4

Cleo scores it

On submission Cleo produces a 0–100 score, category breakdowns, a plain-language summary and draft findings with severity and confidence. You accept, modify or dismiss — no black boxes.

Track to resolution

Findings move Open → In Progress → Resolved or Accepted Risk; link them to the Risk Register or the Planner. Review cycles run on each classification's cadence — monthly to every three years — so assessments don't expire unnoticed.

Your auditor sees the work

The TPRM dashboard shows vendor status, upcoming reviews at 30/60/90/120 days, risk-score distribution, findings by severity, evidence gaps and action items. Every metric drills into the vendors behind it.

Key Capabilities

Built in, not bolted on

White-label vendor portal

The portal your vendors see is yours — logo, colors, custom domain (vendor-portal.yourcompany.com, CNAME + auto SSL). Vendors never see RealCISO.

AI-powered risk scoring

Cleo analyzes responses, identifies red flags, drafts findings with severity and produces a composite score. Thresholds per classification: Passing, Marginal, Failing — recommended 75–85 for Critical vendors.

Classifications & thresholds

Define tiers once; set score thresholds, review frequency and required evidence types (SOC 2 Type II, pen test, ISO certificate, BCP). TPRM enforces the cadence.

Conditional questionnaires

Ask every vendor five base questions and only Critical vendors fifteen follow-ups. Skip what a held certification already answers.

Evidence vault & gap analysis

Vendor attachments are cataloged automatically; manual uploads sit alongside. Gap analysis compares what a classification requires with what is on file and surfaces the missing pieces on the dashboard.

Organization-level

TPRM lives at the organization level: a vendor is assessed once and visible across every environment that depends on it. Consultants deliver it as a managed service on the client licences they run.

Who It's For

Four ways teams use it

MSPs & MSSPs

A natural upsell to your compliance practice. White-label the portal and deliver vendor risk as part of the program — no integration work.

Regulated industries

Healthcare, fintech, defense — your auditors ask about vendor assessments. TPRM gives you the documented process and the findings to prove it.

SaaS companies selling to enterprise

Procurement won't sign without a vendor risk process. Trust Center shows your posture; TPRM shows you assess your own vendors. Together they close the loop.

Startups & scale-ups

Cloud, auth, dev tools, payments — TPRM tells you which vendors are actual risks and which matter to your compliance posture.

Common Questions

TPRM FAQ

Do my vendors need a RealCISO account?

No. Vendors receive a token-based link to a branded portal — your logo, your colors, optionally your own domain — where they answer, attach documents and return later to continue. Revision requests show them your notes beside their original answers.

How is the risk score calculated?

After a vendor submits, Cleo analyzes the responses in the background and produces a 0–100 score, category breakdowns, a plain-language summary and draft findings with severity and confidence. Findings are drafts until you accept, modify or dismiss them; the composite score combines responses and accepted findings, and each classification sets its own Passing / Marginal / Failing thresholds.

Can I ask different vendors different questions?

Yes. Questionnaire templates support conditional sub-questions and scoping by classification, access type, and held certifications — ask all vendors five base questions and only Critical vendors fifteen follow-ups, or skip encryption questions for a vendor that holds ISO 27001.

Is TPRM per environment or per organization?

Organization level. A vendor is assessed once and that assessment is visible across every environment that depends on the vendor. For consultants it rides on the client licences they manage, so vendor risk can be delivered as a managed service.

What does TPRM cost?

It is a $100-per-month add-on with unlimited vendors on Essentials and Professional, included on Enterprise, and unlimited on Enterprise Plus and the partner Complete client licence. Accounts that had TPRM bundled in a prior plan keep it through their next renewal.

How does it pair with the Trust Center?

TPRM handles inbound risk — you assess your vendors. Trust Center handles outbound — your prospects assess you. One platform covers both directions of third-party risk, and Trust Center is included in every paid plan.

Explore the Platform

Go deeper on any capability

Both directions of third-party risk, and where vendor findings land.

Trusted by 3,000+ Organizations

See a live TPRM dashboard

A 30-minute demo of white-label vendor assessment with AI scoring — classify vendors, send assessments, track findings, all inside your compliance platform.

Book a Demo Start Free