TPRM glossary

Continuous monitoring, because an annual assessment is a photograph

Continuous monitoring is the ongoing observation of a vendor’s security posture between assessments, using externally observable evidence — exposed services, certificate and patch hygiene, breach and dark-web signals — so that a material change is detected when it happens rather than at the next annual questionnaire. Also called Continuous security monitoring.

The gap it closes

A point-in-time assessment describes a vendor on the day it was completed. Every day after that, the assessment is a claim about the past being used as a statement about the present. A vendor assessed in March that exposes a database in July is, on your register, still a March vendor until next March.

Continuous monitoring closes that gap with evidence that does not depend on the vendor answering anything: what their estate exposes to the internet, how quickly known vulnerabilities are patched, whether certificates and DNS are maintained, and whether their credentials or data appear in breach corpora. It is deliberately outside-in, which is both its strength — no cooperation needed, so it works on vendors who ignore you — and its limit.

What it cannot tell you

Outside-in signal sees the perimeter. It does not see access management, staff vetting, change control, encryption of data at rest, or whether a documented incident process is ever rehearsed. Those need the vendor to tell you, and to show you — which is what questionnaires and evidence collection are for.

The two are complements, and reading them together is where the useful signal is: a vendor that scores well on paper while its external estate degrades is telling you something no single source would. At RiskXchange, REX runs the outside-in side and ARIA the questionnaire and document side, and the combined read is deliberately produced by both rather than by either alone.

Common questions

How is continuous monitoring different from an annual assessment?
An assessment is a scheduled, cooperative, deep look at a vendor. Continuous monitoring is an unscheduled, non-cooperative, shallow look that never stops. Neither substitutes for the other: monitoring tells you when something changed, the assessment tells you what the vendor actually does.
Does continuous monitoring need the vendor’s permission?
No. It uses publicly observable data — DNS, certificates, exposed services, breach and dark-web sources — so it works on any vendor, including ones that never returned a questionnaire. That is why coverage is usually far higher than assessment coverage.
What counts as a material change?
A change that would alter a decision you have already made: a new critical exposure, a confirmed breach, a large sustained drop in rating, or an expired certification. Alerting on anything less produces noise that teams learn to ignore, which is worse than not alerting.

Definitions are the easy part. Evidence is not.

See what your vendors actually expose — scored, monitored and evidenced in one place.