Vendors under control, without Excel chaos
Questionnaires, scoring and follow-ups in one process. From onboarding to reassessment, CapTRISK makes diligence truly operable.

Before / After CapGRC
What you do today
- Word/Excel questionnaires returned by email, multiple versions
- No comparable risk score from one vendor to the next
- Post-contract follow-up forgotten after signature
- Diligence evidence missing when audit day arrives
With CapGRC
- Third-party inventory with criticality
- Questionnaires and scoring by category (security, data, continuity…)
- Due-diligence mandates with assessment reports
- Scheduled follow-ups during and after the contract
Key features
Third-party inventory
Centralize vendors and partners, with criticality classification and assessment history.
Diligence questionnaires
Distribute structured questionnaires (sections, questions, depth) and collect answers in the platform.
Category scoring
Get a clear, comparable reading of third-party risk across your categories (security, data, continuity, and more).
Mandates and due-diligence reports
Formalize each diligence in a mandate, with maturity assessment, evidence and a shareable report.
Contractual and post-contract follow-ups
Schedule follow-ups throughout the vendor relationship, not only at onboarding.
Audit traceability
Build a documented trail: who was assessed, when, on what basis, with what result.
Use cases
SaaS vendor onboarding
Procurement opens a diligence mandate, sends the questionnaire and gets a score before signature.
Reassessment campaign
The CISO reopens critical vendors on a scheduled follow-up calendar.
Subcontracting and personal data
The privacy officer verifies the posture of subcontractors processing personal information.
“Managing our critical vendors was a nightmare. CapGRC gives us a clear view of third-party risks and automates periodic assessments.”
Isabelle R.
Compliance Manager, University hospital center
Complementary modules
Combine CapTRISK with these modules for a complete GRC program.
CapRISK
Identify, assess and treat risks in a living register, with a clear methodology and executive visibility.
CapCOM
Drive multi-framework compliance: assessments, evidence and posture, without starting over for every framework.
CapAUDIT
Digitize internal audits: planning, evidence, findings and recommendation follow-up through to closure.
Ready to modernize your GRC program?
Request a free demo and discover how CapGRC can transform your approach to governance, risk and compliance.
