Third parties and supply chain

TPRM

Third-party risk management

Manage vendor risk with confidence.

The whole vendor lifecycle for a regulated entity. Onboard through a staged maker-checker workflow, issue the questionnaire your regulator and your risk appetite call for, let assessors or the vendor answer with evidence, compute inherent, residual and privacy risk server-side, track findings to closure, keep cadence obligations on a clock, and produce audit reports that survive inspection.

  • Maker-checkerStaged vendor onboarding
  • Server-sideInherent, residual and privacy risk
  • PassiveExternal posture, vendor never touched

How it runs.

  1. 01OnboardA maker raises the case; a checker screens, classifies criticality and runs privacy screening.
  2. 02AssessThe right questionnaire goes to the assessor or to the vendor's portal, with evidence per answer.
  3. 03ScoreInherent, residual, privacy and overall risk are computed on the server and explained inside the product.
  4. 04RemediateFindings, incidents and risk acceptances move to closure with owners and dates.
  5. 05ContractContract review, DPA sign-off, renewal decisions and offboarding checklists.
  6. 06WatchReassessment triggers, compliance clocks and passive posture monitoring run on cadence.

What TPRM does.

  • Staged onboarding
    From draft to active with maker-checker control and a readiness panel that says what each case is waiting for.
  • Questionnaires with evidence
    Templates for SEBI CSCRF, RBI outsourcing, DPDP, cyber, cloud and software risk, tailored to your requirements, with evidence per answer.
  • Vendor portal
    An expiring link lets a vendor submit answers and evidence without an account.
  • Compliance clocks
    Your regulator's cadence obligations with due dates and reminders, plus reassessment triggers such as a breach or a hosting change.
  • External posture
    A score and grade from passive sources only, fed by BreachGuard, certificate logs and DNS records; the vendor is never touched.
  • Reports that hold up
    Board-ready dashboards by financial year, branded PDF packs and per-assessment Word audit reports.

Deploy on your terms.

  • On-premises
    Inside your environment on Docker or Kubernetes, with your identity provider and your storage.
  • Air-gapped
    Containerised for networks with no internet; updates and content arrive as bundles you carry in.
  • Cloud
    Hosted by Cybervahak or in your cloud, with the same operating model and no feature trade-offs.

Integrations and standards.

Regimes, including
  • SEBI CSCRF
  • RBI Outsourcing
  • DPDP Act
Posture sources
  • BreachGuard
  • Certificate transparency logs
  • DNS, SPF and DMARC
Also referenced
  • ISO/IEC 27001
  • CERT-In
  • GDPR

Where teams deploy it.

  • SEBI CSCRF third-party assessments
  • RBI outsourcing due diligence
  • DPDP processor screening
  • Vendor renewals and offboarding
  • Continuous vendor posture watch

See TPRM in your environment.

Book a 30-minute walkthrough tailored to your stack, regulators and current security posture. No generic pitch deck, just your questions answered by a senior practitioner.

TPRM - Cybervahak