CapGRC
CapGRC
All modules
Third-party Risks

Manage the risks in your supply chain

Assess your vendors, track third-party risks and ensure your ecosystem's compliance in a centralized platform.

Before / After CapGRC

What you do today

  • Vendor assessments via Word/Excel questionnaires
  • No consolidated view of third-party risks
  • No post-contractual vendor follow-up
  • Regulatory compliance hard to prove

With CapGRC

  • Standardized and automated assessment questionnaires
  • Consolidated third-party risk dashboard
  • Ongoing tracking with deadline alerts
  • Complete traceability for auditors

Key features

01

Third-party inventory

Catalogue all your vendors and partners with criticality classification.

02

Assessment questionnaires

Send standardized security questionnaires and collect responses automatically.

03

Risk scoring

Calculate an automatic risk score based on responses and defined criteria.

04

Due diligence

Structure your security due diligence process with approval workflow.

05

Ongoing monitoring

Schedule periodic reassessments and receive alerts on at-risk vendors.

06

Consolidated reports

Generate third-party risk reports for your management committee and auditors.

Use cases

Procurement Manager

Cloud vendor onboarding

The procurement team assesses a new SaaS vendor via a standardized security questionnaire.

CISO

Annual review

The CISO launches the reassessment campaign for all critical vendors.

Privacy Officer

Law 25 subcontracting compliance

The Privacy Officer verifies that subcontractors comply with Law 25 requirements on personal information.

Managing our critical vendors was a nightmare. CapGRC gives us a clear view of third-party risks and automates periodic assessments.
I

Isabelle R.

Compliance Manager, University hospital center

Complementary modules

Combine Third-party Risks with these modules for a complete GRC program.

Ready to modernize your GRC program?

Request a free demo and discover how CapGRC can transform your approach to governance, risk and compliance.