jump to content

Third-party management

Learn how to record vendor relationships in the platform, including contacts, services, DPAs, subprocessor hierarchies, and third-party risk assessments.

View as Markdown

A third party represents an external organization that provides a product or service, processes data, or otherwise contributes risk to your compliance program.

Keep the vendor record focused on the relationship, not only the company name:

  • business and security contacts;
  • services used by your organization;
  • data and operational dependencies;
  • DPA, BAA, and compliance-report status;
  • parent, child, and subprocessor relationships;
  • risk assessments and their expiry dates.

The hierarchy distinguishes a direct vendor from downstream parties. This makes it possible to review concentration and subprocessor risk without flattening every provider into one list.

An assessment belongs to a third party and records the review performed for that relationship. the platform can run asynchronous vendor vetting to gather supporting information, but the resulting material still requires human review. Publish a third-party list only after ownership and relationship data are accurate.

Third-party records are available through the web console and automation interfaces. Use access reviews for identities imported from connected applications; use third-party management for the contractual, privacy, and operational relationship with the provider itself.

Ultima actualizare: