TPRM · Premium

Your vendors change daily.
Your due diligence should too.

Stop chasing suppliers for annual spreadsheets that are stale the day they come back. Evidence is gathered continuously from official registries, sanctions lists and live attack-surface scans, and every finding arrives graded, timestamped and audit-ready.

16
Continuous assurance feeds
15
Passive attack-surface probes
7
Honest evidence states
0
Questionnaires required
Three scores, not one

One number hides the thing you most need to know.

A single rating cannot tell you how much you actually know about a supplier. Risk says how they look on the evidence held. Confidence is the weakest-link reliability of that evidence. Coverage is how much of the required diligence actually ran — so a gap shows as a gap, never as a clean pass.

  • Risk, Confidence and Coverage scored separately, so “low risk” and “low risk, but we could not check much” never look the same.
  • NATO Admiralty grading on every row — source reliability A–F against information credibility 1–6.
  • The company behind the company. A nightly-rebuilt corporate ownership graph resolves the real parent and ultimate beneficial owners behind every third party — not just the name on the invoice — with Companies House identity resolution and Cyber Essentials verified against the official certification registry.
  • Hard stops, not footnotes. Sanctions and PEP screening, credit checks, insolvency monitoring and Modern Slavery / ESG registry checks per company — a confirmed insolvency notice or sanctions hit blocks the vendor and raises an urgent alert within hours.
  • Passive by design. Fifteen probes observe a vendor's public attack surface — DNS, TLS, email posture, security headers, exposed technologies, subdomains, open ports — each in its own evidence panel with a full AI-written analysis per scan. Nothing intrusive is ever run.
  • A response portal without the password reset. Send an assessment by magic link; the third party answers without an account and the responses flow straight into the dossier.
  • An append-only, hash-chained register, so you can show the record exactly as it stood on any past date.
  • Your judgement stays private. The evidence corpus is shared infrastructure; your approvals, assessments and business context are not.
See it live
+GR
GGRCxAI

Northwind Logistics Ltd

CRN 12345678 · monitored continuously

OverviewRegisterOwnership
Risk
81
high
Confidence
77
weakest link C3
Coverage
85%
19 of 22 checks
Due-diligence register1 hard stop
GradeCheckOutcome
A1Companies House — status & officersConfirmed
A1Gazette — insolvency notice, CRN matchedHard stop
C3Press report — uncorroboratedPossible
Credit check — awaiting credentialsNot checked
02:14 — Gazette insolvency notice, vendor blockedUrgent
03:00 — Ownership graph refreshed (nightly walk)Done
Inside the module

The thirteen pages

From first request through to a board-ready dossier.

TPRM Dashboard

Portfolio-wide risk, confidence and coverage across every monitored third party.

Third Parties

The vendor pool, with org-defined tags and named relationship owners.

Third-Party Requests

Anyone proposes, admins approve — approval registers the vendor and queues its first scan.

Monitored Third Parties

Continuous monitoring, with 16 assurance feeds refreshing behind each dossier.

Review Queue

Triage the findings that need a human decision, with the evidence attached.

Fix Queue

Route registry corrections for admin review so records get fixed at source.

Attack Surface

Fifteen passive probes per domain — DNS, TLS, headers, email posture, subdomains and more.

Monitoring

Scan health and freshness, so you know what has actually been checked and when.

Supply Chain Map

Concentration and blast radius across your third parties, with shared ownership visible.

Manual Third Parties

Vendors you track by hand, alongside the monitored pool.

Reconcile Manual

Merge manually-tracked vendors into monitored records without losing history.

Third Party Assessments

Native questionnaires launched straight from a monitored vendor.

Credit Checks

Financial and credit signals, with insolvency treated as a hard stop.

Works with

Every module shares one system of record, so evidence gathered in one place counts everywhere it is needed.

vCISO

The same corpus, turned on your own estate.

Learn more

Risk Management

Vendor findings raised straight into the register.

Learn more

Pricing

£2,000/month as an add-on, or standalone — vCISO included.

Learn more

Find out about the insolvency in hours,
not at next year's renewal.

See a live dossier on a supplier of your choosing.