Vendor Risk Management

Vendor risk, run by an AI workforce.

Three named agents collaborating across the vendor lifecycle. NOVA owns the relationship. ARIA reads the evidence. REX watches from the outside. Together they replace the spreadsheets, the chasing, and the gut-feel scoring.

What is vendor risk management?

Vendor risk management — VRM — is the practice of identifying, assessing and controlling the risk an organisation takes on through the vendors it buys from. It runs for the whole life of the relationship, from selection and onboarding through to offboarding, and it covers more than security: financial stability, concentration and resilience, regulatory and sanctions exposure, data protection, and the fourth parties your vendors depend on in turn.

The discipline exists because of a structural asymmetry. When you outsource a function you transfer the work, but you do not transfer the accountability — to your regulator, your customers, or a court. What you do transfer is control. Vendor risk management is the set of practices that tries to close the distance between those two facts.

It sits inside the wider field of third-party risk management, which covers any external dependency rather than only the parties you purchase from. In day-to-day use the two terms overlap almost completely; VRM is the procurement-facing wording and TPRM is the one regulators reach for.

Why is vendor risk management important?

Vendor risk management is important because the exposure has grown faster than anybody’s ability to see it. Four things changed.

Most of your attack surface now belongs to other people. A typical organisation runs on hundreds of SaaS products, API integrations, contractors holding standing credentials and managed providers with privileged access. The perimeter you can patch is a shrinking fraction of the perimeter that can be used against you.

Supervisory expectations moved from having a policy to showing evidence. The question is no longer whether you assess vendors, but what you knew about a specific critical vendor between reviews and when you knew it. That is answered with records or not at all.

Concentration turns one vendor’s failure into everybody’s incident. When an identity provider, a payments processor or a single cloud region fails, it does not take out one company — it takes out every company behind it at once, including the alternates you assumed were independent.

It gates your own revenue. Your customers run this process on you. A slow or unevidenced security review is a deal that closes a quarter late, which makes vendor risk a commercial function as much as a control function.

What a vendor risk management programme looks like.

A vendor risk management program is the standing operation rather than the individual assessment. The assessment is an event; the programme is what makes the next hundred of them consistent. Six things distinguish one from a queue of questionnaires:

A maintained inventory reconciled against accounts payable and SSO rather than assembled once. A tiering model that decides how much diligence each vendor gets, keyed on data, access and substitutability rather than invoice value. Evidence standards stating what counts, what it expires, and how it is validated instead of filed. Monitoring between assessments, because a point-in-time review tells you nothing about the eleven months that follow it. Named owners on every finding, with deadlines and a defined consequence for missing them. And reporting in outcomes — coverage, time to detection, time to remediation — rather than assessments completed.

The build sequence for all six, with a maturity model for grading what you already have, is set out in the third-party risk management framework guide.

Too many vendors. Too little time.

Vendor risk teams are running the largest, most regulated stage of procurement with the smallest headcount in security. The result: late questionnaires, stale scores, and material risk hiding in plain sight.

Hiring more analysts isn't the answer — there aren't enough to hire, and the regulatory load is climbing faster than your headcount could anyway. The Agency takes the work the team shouldn't be doing.

200+
Average vendors per risk team
1.5
People typically managing them
~70%
Of TPRM time spent on admin

Three agents. One vendor lifecycle.

Vendor risk needs three things at once: someone who can talk to the vendor, someone who can read what they send, and someone who can verify it from the outside. We named them.

NOVA
NOVA agent avatar
AI Vendor Relationship Manager

The only agent that talks to your vendors. Owns the relationship from intake through to offboarding, across email, WhatsApp, and in-app chat.

The team
  • Intake — captures the vendor record
  • Vendor Discovery — surfaces shadow vendors
  • Firmographics — enriches the vendor profile
  • Vendor Chaser — automated nudges across channels
  • Data Destruction — verifies offboarding evidence
What they do for vendor risk
  • Drafts the questionnaire request, sends it, chases the follow-up — without you copying and pasting
  • Detects when your vendor contact has left and reroutes onboarding automatically
  • Spots unmanaged vendors in your stack you didn't know you had
ARIA
ARIA agent avatar
Assessment & Risk Intelligence Agent

Reads your vendor's evidence so you don't have to. Documents, questionnaires, contracts, trust centres — all turned into structured posture against the 157 Universal Controls.

The team
  • Q Pre-Populator — auto-fills 70%+ from prior evidence
  • Q Analyser — scores completed responses
  • Response Validator — cross-checks claims against scan data
  • Document Classifier — routes uploads to the right control
  • Trust Centre Parser — ingests vendor trust portals
  • Contract Analyser — extracts risk-relevant clauses
  • SnapShot — on-demand one-page vendor summary
What they do for vendor risk
  • Pre-fills the next questionnaire from the SOC 2 a vendor uploaded last quarter
  • Catches vendors saying one thing in the questionnaire and another on their trust page
  • Surfaces contract clauses that cap vendor liability at 12 months' fees
REX
REX agent avatar
Risk & Breach Intelligence Agent

Watches your vendors from the outside. Continuous attack-surface mapping, breach detection, fourth-party discovery, and regulatory or financial signals — all without asking the vendor a single question.

The team
  • Digital Footprint Scanner — maps the vendor's external surface
  • Outside-In Scanner — daily security posture scoring
  • Continuous Monitoring — material-change and breach detection
  • BreachWatch — dark-web correlation against vendor identifiers
  • Fourth-Party Discovery — vendors of vendors, mapped
  • Vendor Business Risk Analyst — Companies House, sanctions, negative news
What they do for vendor risk
  • Tells you a vendor's posture dropped 40 points overnight — and why
  • Flags a credential dump on the dark web before the vendor disclosed
  • Maps the chain when your vendor's vendor has the actual breach

Five stages. One workflow.

The full vendor lifecycle, with the named agent responsible at each stage. Onboarding through reporting — no handoffs, no gaps.

01
Onboarding

Outreach, intake, evidence collection, follow-up.

NOVA
02
Assessment

Document intelligence + outside-in scan, joined.

ARIA + REX
03
Monitoring

Continuous scoring, breach detection, fourth-party.

REX
04
Remediation

Tiering, treatment plans, SLA-driven actions.

TARA
05
Reporting

DORA, NIS2, audit packs, board insights.

VANCE

"Single source of truth" is a lie.

Most TPRM platforms give you one signal — ratings or questionnaires. One half of the picture. We give you both, joined.

Most platforms

One signal. Cherry-picked.

A rating or a questionnaire. Whichever the vendor will let you see. The other half stays a story you have to take their word for.

  • Outside-in score with no internal evidence to corroborate it
  • Self-reported questionnaires with no external check on the answers
  • "Single source of truth" branding for half a picture
RiskXchange

Both signals. Joined.

ARIA reads the documents, REX scans from the outside. Their findings are reconciled into one combined view — gaps, contradictions, evidence, all in one place.

  • Outside-in scan + inside-out evidence, reconciled
  • Vendor claims cross-checked against external reality
  • One score — earned, not asserted

Vendor risk management, answered.

What is vendor risk management?
The practice of identifying, assessing and controlling the risk an organisation takes on through the vendors it buys from — across security, resilience, financial stability, regulatory exposure and data protection — for the whole life of the relationship, from selection through to offboarding.
Why is vendor risk management important?
Because accountability for a failure stays with you while control over it does not. A regulator or a customer holds you responsible for data held by a vendor. Most of a modern attack surface now sits outside the perimeter, supervisory expectations have moved from having a policy to evidencing what you knew and when, and your own customers run the same process on you — so weak assurance delays your revenue as well as raising your risk.
What is a vendor risk management program?
The standing operation rather than a one-off assessment: a maintained inventory of vendors, a tiering model that decides how much diligence each one gets, defined evidence standards, monitoring between assessments, named owners for findings, and reporting that reaches the board. A programme is what makes vendor risk repeatable when the person who built it leaves.
How do you start a vendor risk management programme?
Build the inventory first and accept it is incomplete — reconcile accounts payable, SSO logs and cloud spend. Then define scope and tiers before assessing anything, agree risk appetite with the people it will overrule, and assess the critical tier properly rather than working alphabetically through the whole estate. Turn on continuous monitoring before you finish assessing. The full sequence is set out in our TPRM framework guide.
What is the difference between vendor risk management and TPRM?
They overlap heavily. Vendor risk management usually refers to parties you buy from; third-party risk management is broader, covering any external dependency including non-purchased relationships, and is the term regulators use. See third-party risk management.
Can vendor risk management be automated?
The mechanical parts, yes — chasing questionnaires, pre-filling responses from evidence a vendor already supplied, scanning posture continuously, and drafting reports. The judgement parts stay human: what risk you accept, what is a stop, and who owns a finding. See vendor risk management software for what the tooling removes.

See it on your vendors.

Pick one of your live vendors. We'll have NOVA, ARIA and REX produce a complete posture report inside 24 hours. No procurement. No commitment.