Platform · Reporting

Reports composed from live data.

Board packs, audit outputs, regulator-aligned reports — generated by VANCE from the same evidence the agents are working with, not assembled in a deck the night before. The work is judgement, not formatting.

What does third-party risk reporting need to produce?

Third-party risk reporting has three distinct audiences, and confusing them is the usual reason reporting takes so long and satisfies so few.

Boards and executives need concentration and trend: which dependencies could materially hurt the organisation, whether exposure is improving, and what decisions are being asked for. They do not need a findings list. Auditors need evidence that the programme operated as described — that vendors were tiered, assessed on schedule, that findings were tracked to closure, and that the record is complete and attributable. Regulators need specified artefacts in specified formats: a DORA Article 28 register of information, an APRA CPS 230 material service provider register, an incident notification inside a statutory window.

What they share is a requirement that is easy to state and hard to meet: the output must be traceable to underlying evidence and current as of when it is read. A report assembled by hand from exports is stale on delivery and expensive to reproduce, which is why the same questions get asked and re-answered every cycle. Composing reports from live data rather than from a snapshot is what makes "produce it again as at today" a trivial request rather than another quarter of work.

The numbers your team already knows.

Reporting is the most senior, most expensive, and most repeatable work in TPRM. Every quarter the same charts, the same vendor lists, the same regulator-shaped framings — rebuilt by hand, slightly differently, by someone whose time should be worth more.

40+ hours
Average time per quarter assembling a board-grade TPRM pack
Industry estimate
~3 weeks
Lead time for an audit-ready evidence bundle, manually
Industry estimate
Live
How often a VANCE-composed report reflects the underlying data

VANCE composes. ARIA evidences. TARA frames it against the framework.

Reporting is the layer everyone else feeds. ARIA's evidence sits underneath, TARA's compliance posture frames it, and VANCE composes the actual document the audience needs to read.

VANCE avatar
VANCE
Vendor Analysis & Compliance

Reports written by the agent that has all the data. VANCE composes board packs, audit outputs and regulator-aligned reports straight from the working evidence — DORA, NIS2, GDPR, FCA and ADHICS framings included.

What you get
  • Regulatory Reporting against DORA, NIS2, GDPR, FCA, ADHICS
  • Audit Insights surfaces control gaps for board / internal audit
  • Issue Insights highlights systemic and portfolio-level risks
ARIA avatar
ARIA
Assessment & Risk Intelligence

Every claim in the report links to the source. The questionnaire answer, the SOC 2 page, the trust-centre control — ARIA keeps evidence structured against the 157 Universal Controls so VANCE doesn't have to re-derive the trail.

What you get
  • Evidence stored per control for fast retrieval
  • Trust-portal data already mapped to the RX framework
  • Questionnaire answers cross-validated against external scans
TARA avatar
TARA
Tiering & Remediation

The framework view, kept current automatically. TARA runs continuous regulatory compliance assessment and DORA gap analysis — so VANCE's reports show today's posture, not last quarter's.

What you get
  • Continuous compliance assessment against frameworks in scope
  • DORA gap analysis across the five DORA pillars
  • Smart tiering keeps reports weighted by inherent risk

From quarterly scramble to standing capability.

Reporting stops being a project and starts being something that's already true the moment someone needs it.

Board packs assemble themselves

VANCE composes the deck from the same evidence the agents are working with — your team reviews and judges, not formats.

Audit evidence is already structured

When auditors arrive, the trail exists, linked back to source. No archaeology before the review starts.

Regulator-aligned out of the box

DORA, NIS2, GDPR, FCA and ADHICS framings ship as report templates. The mapping has already been done.

Cross-portfolio patterns surface

Issue Insights spots when the same control gap is showing up across multiple vendors — instead of waiting for a human to notice.

The board pack used to take a week. VANCE produces it from live data, my team reviews it, and we ship the same day the request lands.

EW
Director of Risk Reporting
European wholesale bank

What teams ask about reporting.

Board packs, audit evidence and regulator-specified formats.

What should a board-level third-party risk report contain?
Enough to support a decision and no more. In practice: exposure concentrated by criticality rather than a count of vendors, the small number of dependencies whose failure would be material, direction of travel since last period, anything breached or materially deteriorating, the state of remediation against agreed deadlines, and explicit asks — budget, risk acceptance, or a decision on a vendor. The most common failure is presenting volume as insight: four hundred open findings is not a board fact, whereas "three of our eleven critical vendors run on the same provider" is.
What makes reporting audit-ready?
Traceability and completeness. Every assertion should resolve to the evidence behind it — the document, the scan, the questionnaire response, with a date and a source — and the record should show what was known when, not just the current state. An auditor is testing whether the process operated, so the questions are typically: how were these vendors tiered and by whom, were assessments performed on the schedule the policy requires, were findings tracked to closure or formally accepted, and can you produce that history without reconstructing it.
What is a DORA Article 28 register of information?
A structured record of every contractual arrangement for ICT services, maintained at entity, sub-consolidated and consolidated level and provided to the competent authority on request. It captures the provider and its identifiers, the function supported and whether that function is critical or important, contract dates and governing law, data locations, subcontracting arrangements supporting critical functions, and exit and substitutability assessment. The demanding part is not any single field — it is keeping it complete and current across a whole group, since the register is a standing obligation rather than an annual submission.
How do we avoid rebuilding the same report every quarter?
Stop treating the report as the artefact and treat the underlying record as the artefact. If tiering, assessment outcomes, findings, evidence and remediation state are held as live structured data, each report is a view over it and regenerating as at any date is trivial. If they live in spreadsheets and email, every report is a fresh reconciliation. Most of the quarterly effort teams describe is not analysis — it is reassembling a record that was never held in one place.

See it on your vendors.

Book a 30-minute call and we'll have NOVA, ARIA and REX produce a complete posture report on one of your live vendors inside 24 hours.