Start with the business relationship
The risk changes with the way you rely on the supplier
Imagine two teams using the same technology supplier. One relies on it to hold customer data and keep a critical service running. The other uses a separate product for an occasional internal task. The supplier is the same. What the business stands to lose is not.
That is why a third-party risk assessment should begin with the business use, the data handled and the importance of the service. From there, privacy, commercial, contractual, resilience, cyber security and compliance specialists can focus on what matters. Their findings stay connected to the relationship instead of disappearing into separate reports.
- Privacy and data
- Commercial and financial
- Contractual and legal
- Operational resilience
- Cyber security
- Compliance and conduct
Keep the decision alive
The questions change as the relationship moves
Vendor due diligence is one moment in the relationship. Before signing, you need to know what you are buying and what could go wrong. Once the supplier is in place, third-party monitoring needs to pick up changes in service, ownership, data use, incidents and performance. At renewal, the original decision should still make sense in light of what has happened.
Before engagement
What are we relying on?
Describe the service in plain language, identify its owner, note the data and systems involved, and consider what would happen if it stopped.
During review
Who needs to look?
Bring in the specialists whose concerns are relevant to this use of the supplier. Not every relationship needs the same review.
When deciding
What will we accept?
Record the decision, any conditions, the controls you expect and the people responsible for unresolved work.
While working together
Has anything changed?
Watch service performance, incidents, attestations and material changes. Reopen the decision when new facts alter the risk.
At renewal or exit
Do we continue?
Use the history of the relationship to decide whether to renew, renegotiate, move the service or leave.
Turn review into a workable decision
One decision, with the reasoning still attached
A privacy review may limit how data is used. Legal may ask for a contract change. Operations may want evidence that recovery arrangements will work. These are not competing answers. They are different parts of the same decision.
Parapet connects the specialist assessments and evidence with the business context shown earlier on the page. The agreed response then has somewhere to go: contract terms, supplier work, internal remediation, escalation or reporting. Anyone returning later can see what was decided, what informed it and what is still open.
Used this way, vendor risk management software supports everyday supplier risk management. Owners can see their commitments, overdue work and reasons for escalation. At renewal, the team can pick up from the last decision instead of starting again.
- Specialist assessments
- Evidence and findings
- Business dependency context
- Contract terms
- Joint remediation
- Escalation and reporting
Questions answered
Frequently asked questions
What does third party risk management include?
It starts with the business need and continues through review, approval, monitoring, issue management, renewal and exit. Depending on the relationship, the risks may involve privacy, commercial terms, contracts, resilience, cyber security, compliance, concentration or reputation.
Why is a supplier questionnaire not enough?
A questionnaire tells you what the supplier said at a particular time. It does not tell you which business service depends on the supplier, why a finding matters, what conditions were accepted or who is responsible for the next action.
Can specialist teams assess the same relationship separately?
Yes. Privacy, legal, commercial, resilience, security and compliance teams can use their own criteria and evidence while their findings remain connected to the same relationship and business use.
What if one supplier supports several business services?
Keep the context for each use of the supplier, including the service, owner, data, obligations and risks. Those relationships can still contribute to a combined supplier view without pretending that every use creates the same risk.
Is supplier risk management charged as a separate module?
No. All Parapet capabilities are available from day one. SaaS pricing follows active items rather than separate modules or users.