Onboard & Profile
Capture the vendor, services, access, processing and enterprise dependencies.
AIRRP maintains third parties as persistent enterprise objects across services, risk tier, assessments, findings, treatment, monitoring, renewal, change and offboarding.
Vendor risk becomes more useful when it is connected to the services, applications, data and business processes that depend on the vendor. AIRRP brings that context into the third-party lifecycle.
Capture the vendor, services, access, processing and enterprise dependencies.
Determine inherent criticality and the right assessment depth.
Run risk-based third-party assessments with governed evidence.
Track remediation, exceptions, owners and due dates.
Review changes, cadence, expiring evidence and reassessment needs.
Connect third-party issues into the enterprise risk portfolio.
Assessment scope can be based on services, data access, criticality, technology dependency and other governed factors.
Existing controls, evidence, application context and prior assessment history can inform the next vendor cycle when still valid and in scope.
A vendor finding has different significance when it supports a critical business service, processes sensitive data or creates concentration risk.
See third-party risk as part of enterprise risk, not a separate questionnaire repository.