Vendors, suppliers, fourth parties.

Third-Party Risk Management for enterprises

Continuous, evidence-based monitoring of your vendor ecosystem across 325 million+ companies — with real-time alerts, dark web intelligence and fourth-party visibility.

  • /01Continuous monitoring across 325 million+ companies
  • /02Real-time alerts on vendor posture changes
  • /03Dark Web Intelligence — 1,000+ underground forums
  • /04Fourth-party visibility (your vendors' vendors)
  • /05AI-powered: pre-filled profiles, questionnaire analysis
◆ TPRM — VENDOR ECOSYSTEM
▲ 2 ALERTS
Your Org
AWS
Salesforce
Workday
Vendor#214
Vendor#091
Vendor#308
Vendor#412
Vendor#107
● HEALTHY
4
● WATCHING
2
● AT RISK
2
In short
Third-Party Risk Management — vendor risk monitoring — is the continuous measurement of the security risk your vendors, suppliers and service providers introduce. In its evidence-based form it measures each third party's externally observable security performance daily across a universe of 325 million+ continuously monitored companies, and raises an alert the moment a vendor's posture changes — rather than asking that vendor to describe its own controls once a year.

Nearly half of all breaches now involve a third party — 48% in Verizon's 2026 DBIR, up from 30% a year earlier. Most enterprises have no continuous visibility into supplier security at all: they have a folder of completed questionnaires, a spreadsheet of criticality ratings, and an honest belief that both were accurate on the day they were written. A vendor's defences can collapse in a week. The question is whether you find out from a monitoring alert or from the vendor's breach notification.

Third-Party Risk Management in 45 seconds: why a questionnaire can't keep pace with a vendor, and what continuous monitoring shows instead.

Watch and comment on YouTube

Why questionnaires fail

Not because vendors lie. Because the instrument has three structural defects that no amount of diligence corrects:

  1. It is self-reported. The vendor assesses itself, and the assessment is rarely verified against anything observable.
  2. It is point-in-time. It records a belief held on the day the form was completed, and nothing updates it afterwards.
  3. It is rarely re-read. Completed questionnaires are filed as evidence of process, not consulted as sources of risk information.

Continuous external monitoring inverts all three: independently observed, recalculated daily, and pushed to you as an alert instead of waiting to be looked up. Our guide on third-party risk management for banks and insurers works through what a tiered programme looks like in practice.

What TPRM does, job by job

Onboard a vendor without waiting for a questionnaire

Continuous monitoring covers 325 million+ companies, so most of your vendor portfolio is already rated on the day you start. A rating answers the first diligence question before a questionnaire is sent; where a contract still requires one, AI-assisted assessment pre-fills the vendor profile and analyses the answers, and the questionnaire can concentrate on the controls a rating cannot see.

Monitor continuously, and hear about movement

The signal that matters is not a vendor's absolute score but its movement — a supplier sliding forty points in a month is telling you something a static rating never will. Alerts arrive when posture changes, alongside dark and deep web intelligence across 1,000+ underground forums for credentials and data associated with your suppliers. The same question, pointed at your own estate, is what the credential exposure check works through.

Re-tier vendors on evidence

A vendor's tier should move when its risk does. Ratings give the tiering model below a measured input that changes daily, rather than a criticality score set at onboarding and never revisited.

See fourth parties

Your vendors' vendors, and the concentration risk you inherited without contracting for it.

Report the portfolio to the board

One view a board can read: how many critical vendors sit below their tier's threshold, which moved this quarter, and what was done about each. It is dated and independently calculated, which makes it evidence rather than assertion.

Tiering: the part that determines whether it works

Monitoring two hundred vendors equally produces two hundred alerts and no action. Programmes that work tier the portfolio first, set a different threshold and a different response per tier, and assign a named owner to each. Axis Max Life Insurance — whose Bitsight rating of 810 is among the highest in Indian financial services — adopted an ABCD tiered framework in which critical vendors must hold a B or better, and replaced 100% of manual vendor questionnaires with continuous monitoring.

TierTypical criteriaResponse on deterioration
CriticalHolds regulated data, or an outage stops the businessNamed owner, contractual minimum rating, escalation within days
ImportantMaterial operational dependency, limited data accessReviewed at the monthly vendor forum
StandardReplaceable, no sensitive dataMonitored; acted on only at threshold breach
A workable starting shape. The thresholds matter less than the fact that each tier has a different, pre-agreed response.

What regulators expect

Regulators have moved decisively — the SEC and NYDFS in the US, DORA in the EU, and India's RBI, SEBI and IRDAI — toward requiring boards to evidence oversight of outsourcing and supply-chain risk rather than assert it. In India, every current instrument carries a third-party chapter — the RBI Directions of 31 July 2026 and the separate outsourcing Directions they preserve, SEBI's CSCRF, and IRDAI's 2026 Guidelines, which require third parties to be classified and overseen by risk tier. Which instrument binds you sets out the full picture.

India: the RBI outsourcing Directions, one per entity class

The RBI rewrote outsourcing as nine Directions, all dated 28 November 2025, one for each regulated class. For commercial banks they repeal the 2023 Master Direction on Outsourcing of IT Services, so a bank's vendor programme still mapped to the 2023 text is mapped to a repealed instrument. Regional Rural Banks are the only RBI class with no member of this family.

InstrumentReferenceWho it binds
RBI outsourcing Directions, 2025RBI/DOR/2025-26/171Scheduled commercial banks — banking companies other than Small Finance Banks, Local Area Banks, Payments Banks and Regional Rural Banks — with the corresponding new banks and SBI. Immediate effect, with existing IT outsourcing agreements to comply by 10 April 2026. Repeals the 2023 Master Direction on Outsourcing of IT Services for the banks covered.
RBI NBFC outsourcing Directions, 2025RBI/DOR/2025-26/363NBFCs across the scale-based layers, together with HFCs, Core Investment Companies, standalone primary dealers and the account aggregator and P2P categories; NOFHCs excluded. Base Layer takes the general provisions only. Existing IT outsourcing agreements to comply by 10 April 2026.
RBI SFB outsourcing Directions, 2025RBI/DOR/2025-26/202Small Finance Banks. Covers outsourcing of financial services and of IT services. Immediate effect, with existing IT outsourcing agreements to comply at renewal or by 10 April 2026, whichever is earlier.
RBI Payments Bank outsourcing Directions, 2025RBI/DOR/2025-26/220Payments Banks. Covers outsourcing of financial services and of IT services. Immediate effect, with existing IT outsourcing agreements to comply at renewal or by 10 April 2026, whichever is earlier.
RBI LAB outsourcing Directions, 2025RBI/DOR/2025-26/245Local Area Banks, for material outsourcing of IT services only — the instrument has no financial-services chapter. Immediate effect, with existing IT outsourcing agreements to comply at renewal or by 10 April 2026, whichever is earlier.
RBI UCB outsourcing Directions, 2025RBI/DOR/2025-26/293All Urban Co-operative Banks for outsourcing of financial services; the IT outsourcing chapter and the IT-specific board provisions apply only to Tier 3 and Tier 4 UCBs. Immediate effect, with existing IT outsourcing agreements to comply at renewal or by 10 April 2026, whichever is earlier.
RBI RCB outsourcing Directions, 2025RBI/DOR/2025-26/318Rural Co-operative Banks — State and Central Co-operative Banks as defined in the NABARD Act, 1981 — for outsourcing of financial services only. No IT outsourcing chapter and no transition proviso: in force with immediate effect.
RBI AIFI outsourcing Directions, 2025RBI/DOR/2025-26/337EXIM Bank, NABARD, NaBFID, NHB and SIDBI, for material outsourcing of IT services only. Immediate effect, with existing IT outsourcing agreements to comply at renewal or by 10 April 2026, whichever is earlier.
RBI Credit Information Company outsourcing Directions, 2025RBI/DoR/2025-26/379Credit Information Companies under section 2(e) of the Credit Information Companies (Regulation) Act, 2005, for material outsourcing of IT services only. Not the Core Investment Companies the NBFC instrument calls CICs. Existing IT outsourcing agreements to comply at renewal or by 10 April 2026, whichever is earlier.
The RBI Managing Risks in Outsourcing Directions, 2025. Each reference and scope line read from the RBI's own notification.

Continuous monitoring produces that evidence as a by-product of operating: a dated, independently calculated record of each critical vendor's security performance over time, a documented tiering model, and an auditable alert-and-response trail. That is a materially stronger position at examination than a folder of self-assessments.

Ratings, questionnaires or VAPT?

Each answers a different question, and a vendor programme usually needs more than one. The difference is who produces the evidence, when, and whether the vendor has to agree to it.

Security ratingQuestionnaireVAPT report
Who produces itAn independent rating providerThe vendor, about itselfA tester the vendor engages
How currentRecalculated dailyThe day it was completedThe test window
Vendor consent neededNo — externally observable signals onlyYesYes, and usually a scope agreement
What it seesThe internet-facing estateWhatever the vendor chooses to describeThe systems in scope, inside and out
Best used forScreening every vendor and watching for changeControls a rating cannot seeDepth on the few critical vendors
Three kinds of vendor security evidence, compared.

The longer argument is in security questionnaires vs security ratings.

Packages and vendor bands

TPRM comes in two packages, each banded by the number of vendors monitored (1–50 vendors, 51–100 vendors, 101–500 vendors, unlimited).

Continuous Monitoring

Continuous, evidence-based visibility across your vendor portfolio.

  • Continuous visibility with real-time scoring
  • Correlated risk vectors
  • Unified attack surface management
  • Vendor communication
  • Dark and deep web intelligence
  • Predictive vulnerability detection
  • Framework intelligence
  • Nth and fourth-party visibility
  • Board reporting
  • Workflow integrations and REST API
  • Rule-based alerts

Continuous Monitoring + Vendor Risk Management — most commonly chosen

Adds the workflow layer — intake, assessment and remediation — on top of monitoring.

  • Vendor intake workflows
  • Risk assessment
  • Vendor network access
  • Portfolio-level management
  • Vendor lifecycle management
  • Vendor collaboration
  • Remediation tracking
  • Governance reporting

The practical difference is whether you need the workflow layer. Continuous Monitoring gives you visibility and alerts; adding Vendor Risk Management gives you intake, assessment, remediation tracking and governance reporting — the machinery that turns an alert into a closed action. Pricing is quoted in INR against scope; see the pricing page for what moves a quote.

Where to start

Point the instrument at yourself first. The complimentary Cyber Risk Rating Report shows you exactly what your vendors will see when you start rating them — which is both a useful calibration and, in our experience, a considerably more persuasive internal business case than a slide about supply-chain risk. If your own estate is the priority, Security Posture Management applies the same continuous measurement inward. Both run on the same Bitsight platform and the same rating.

Questions people actually ask about TPRM.

/01

What is Third-Party Risk Management?

Third-Party Risk Management is the practice of identifying, assessing and continuously monitoring the security risk that vendors, suppliers and service providers introduce into an organisation. In its evidence-based form it measures each third party's externally observable security performance daily, rather than asking the vendor to describe its own controls once a year.

/02

Why do vendor security questionnaires fail?

A questionnaire is self-reported, point-in-time and unverified. It records what a vendor believed about itself on the day someone filled the form in, it is rarely re-read after filing, and it cannot detect the posture collapse that happens three months later. Continuous external monitoring inverts all three properties: it is independently observed, updated daily, and it raises an alert at the moment a vendor's posture changes.

/03

Do our vendors need to agree to be monitored?

No. Ratings are calculated entirely from external, attacker-visible signals, so a vendor can be monitored without its participation, its cooperation, or any contractual change. In practice most organisations tell their critical vendors anyway, because the conversation is more productive when both sides can see the same evidence.

/04

What is fourth-party risk, and why does it matter?

Fourth parties are your vendors' vendors — the concentration you inherit without contracting for it. When a single cloud host, payment processor or managed service provider sits behind thirty of your suppliers, an incident there is a correlated failure across your portfolio rather than an isolated vendor problem. Fourth-party visibility surfaces that concentration before it becomes an outage.

/05

How does TPRM help with RBI, SEBI, IRDAI and IFSCA expectations?

Indian regulators now expect boards to evidence oversight of outsourcing and supply-chain risk rather than assert it. Every one of the current instruments carries a third-party chapter — the RBI Directions of 31 July 2026, the separate RBI outsourcing Directions of 2025, SEBI's CSCRF, and IRDAI's 2026 Guidelines, which require third parties to be classified and overseen by risk tier. For a GIFT City entity the IFSCA Guidelines go further still, setting an express six-monthly review of third parties supporting core operations — the clearest cadence obligation in the Indian set. Continuous monitoring produces exactly that evidence: a dated, independently calculated record of each critical vendor's security performance over time, plus a documented tiering model and an auditable alert-and-response trail.

Start with the number, not the contract.

Your organisation already has a rating, calculated from signals anyone can see. Request the complimentary Cyber Risk Rating Report and find out what it says — as little as 45 minutes for publicly listed entities, up to 48 hours for all others. No agent, no system access, no questionnaire.

Request my rating →See packaging