Risk & security

Your vendors are your exposure.

A vendor register, structured assessments and risk ratings that feed the same evidence base as the rest of your compliance programme - so third-party risk stops being an annual spreadsheet exercise.

Part of the Niyam platformAuditor-ready evidenceWorks with DPDP and ISO 27001
The problem

Most breaches arrive through somebody else's door.

Every processor, sub-processor and SaaS tool you onboard extends your attack surface and your regulatory duty, and almost none of it is tracked in one place.

  • Nobody owns the vendor list. Procurement has one list, security has another, and neither matches what is actually connected to production.
  • Assessments happen once, then rot. A questionnaire completed at onboarding says nothing about the vendor's posture eighteen months later.
  • Processor duties go unmapped. Under DPDP you remain accountable for what your processors do. That needs a record, not an assumption.
  • Auditors ask and you scramble. ISO 27001 and SOC 2 both want evidence of supplier assessment. Rebuilding it from email each cycle is expensive.
Capabilities

One register, assessed and rated.

Built on the vendor risk module in the Niyam platform.

Vendor register

One authoritative list of third parties, what data each touches, and who owns the relationship internally.

Structured assessments

Send questionnaires, collect responses and keep them attached to the vendor record rather than in an inbox.

Risk rating & tiering

Score and tier vendors by the data they handle and the access they hold, so effort goes where the exposure is.

Processor obligations

Link each vendor to its DPA, its obligations and its review date, so accountability is documented.

Reassessment cycles

Due dates and owners for periodic review, so an assessment is current rather than historical.

Evidence for auditors

Vendor assessments land in the same evidence base your ISO 27001 and SOC 2 controls draw on.

How it works

From a scattered vendor list to a managed programme.

1
Step one

Build the register

Consolidate your third parties into one list, with the data each one handles and an internal owner for each.

2
Step two

Tier by exposure

Rate vendors so a payroll processor and a marketing plugin do not get the same treatment.

3
Step three

Assess and record

Issue questionnaires, capture responses and attach the DPA and obligations to the vendor record.

4
Step four

Review on a cycle

Reassessment dates and owners keep the register current, and the trail satisfies auditors without a rebuild.

Outcomes

What changes.

Third-party risk becomes a maintained register with owners and dates, rather than a document somebody refreshes before an audit.

  • One vendor register the whole organisation agrees on
  • Assessments attached to vendors, not lost in email
  • Risk effort concentrated on the vendors that matter
  • Processor accountability documented for DPDP
  • Supplier-assessment evidence ready for ISO 27001 and SOC 2
  • Reassessments that happen on schedule
Frameworks

Supplier controls, satisfied once.

Frameworks are what Niyam helps you operationalise. They are not separate products.

ISO 27001:2022SOC 2DPDP 2023GDPRRBI ITGRC 2023NIST CSF 2.0
Pricing

Quoted to your vendor count and scope.

Third-Party Risk Management is scoped with our team rather than sold self-serve, because the work depends on how many vendors you carry and how deeply each is assessed. Vendor Assessment is also available as a delivered service.

FAQ

Questions about third-party risk.

It is scoped with our team. We do not list it as an automatic tier feature, because the effort depends on your vendor count and assessment depth. Talk to sales and we will quote against your actual register.

Yes. Vendor Assessment is available as a delivered service if you would rather we chase, review and score your vendors.

No. It records the risk side of the relationship and keeps the evidence. Procurement keeps owning commercial terms.

Under DPDP you stay accountable for processors acting on your behalf. A maintained register with DPAs and obligations is how you evidence that.

Find out which vendors are actually your risk.

Talk to our team and we will scope a third-party risk programme against your real vendor list.