Vendor Risk Assessments

Software Tour

Standardize Inherent and Residual Risk Assessments

OCC, FDIC, and FFIEC third-party risk guidance all require financial institutions to assess vendor risk before and during the relationship. VendorRisk lets you build structured risk assessment questionnaires, automatically score responses, track both inherent and residual risk, and tie risk levels to review frequencies — so your program is consistent, documented, and defensible.

Determine Risk Through Custom Questionnaires

Use structured surveys to calculate vendor risk levels based on their responses.

Support for Inherent and Residual Risk Fields

Track both base-level and post-control risk by enabling dual risk field support.

Trigger Risk Scores with Specific Answers

Automatically assign a risk level when certain high-risk answers are selected.

Tie Risk Levels to Review Frequencies

Adjust diligence and performance review cadence based on vendor risk level.

Assess Risk by Vendor, Service, or Software

Apply assessments broadly or drill down to specific assets and offerings.

Create Unlimited Risk Assessment Templates

Design as many templates as needed—tailored by risk category, department, or vendor tier.

Choose From Three Risk Assessment Types

Select Q&A, scoring matrix, or manual override to evaluate risk your way.

Custom Risk Levels and Thresholds

Define risk categories like Low, Medium, High—and assign point values that align with your program.

Launch Remediation From Risk Questions

Convert flagged responses into follow-up tasks to resolve or mitigate risk.

Risk Assessments Automatically Update Risk Fields

Use completed assessments to keep your risk fields current—no manual data entry needed.



Build a Risk Tiering Program Regulators Trust

Assess inherent and residual risk, score responses automatically, and ensure your oversight cadence matches each vendor's risk level.

Schedule demo →