Noru

Third-party risk software: what to look for

Why questionnaire volume is the wrong metric, and what actually tells you a vendor is a risk worth managing.

Third-party risk management software inventories your vendors, assesses the risk each one carries, and evidences that the assessment happened. The failure mode of the category is measuring effort instead of risk: sending every supplier the same long questionnaire produces a large amount of documentation and very little signal. The tools worth having tier vendors by what they can actually reach — which systems, which personal data, which privileged access — and reserve depth for the ones that matter. Under GDPR Article 28 a processor also needs contractual terms and documented due diligence, so check the tool carries the contract layer, not just the questionnaire.

What to look for

Does it tier by real access?

The question is what a vendor can reach — which systems, which categories of personal data, whether access is privileged, whether data leaves the EU. A tool that tiers by contract value or headcount will send deep assessments to low-risk suppliers and shallow ones to the vendor holding your production data.

Does it discover vendors, or only record them?

The vendors you forgot are the ones that hurt. Look for discovery from what you already run — identity provider grants, cloud accounts, expense data, code dependencies — rather than a register that is only as complete as the last person to fill it in.

Does it hold the Article 28 layer?

A processor relationship needs written terms covering the subject matter, duration, nature and purpose of processing, plus the specific obligations Article 28(3) lists. Check the tool tracks whether those terms exist and are current, not just whether a questionnaire came back.

How are subprocessors handled?

Your vendor's vendors carry your data too. Ask whether the tool tracks declared subprocessors and flags changes, because that is what actually moves your transfer exposure between assessments.

Is anything monitored between assessments?

An annual questionnaire tells you about last year. Look for signals that arrive on their own — certification expiry, breach disclosure, changes in hosting region or access scope — so a vendor's risk can change without waiting for the next cycle.

The kinds of tool on the market

Four shapes of vendor, described by category rather than by name. Which one fits depends on how fast your systems change and how much judgement you need to buy in.

Broad enterprise suites

Large, modular GRC platforms that cover most regimes through separately licensed modules, usually with a long implementation and a dedicated administrator.

Best fit: Large organisations with a compliance team big enough to own configuration, and budget that tolerates a multi-module licence.

Point tools

Focused products that do one job well — consent, DSAR intake, cookie scanning, vendor questionnaires — and integrate loosely with whatever else you run.

Best fit: Teams with one acute, well-bounded problem, who accept that the register tying everything together lives somewhere else.

Consultancies and managed services

People rather than software: an external DPO or advisory retainer that produces the documentation on your behalf, often in documents you then own.

Best fit: Organisations without in-house expertise who need judgement more than tooling, and who can accept that the output is a snapshot.

Compliance operations platforms

Systems that connect to what you already run, derive the records from live signals, and keep them current between audits rather than regenerating them before one.

Best fit: Teams whose systems change faster than documents can be maintained by hand, and who need to evidence a current state on demand.

Where Noru fits

Noru scores vendors by the access they actually have, taken from connected identity, cloud and code systems, so the depth of assessment follows real exposure rather than procurement paperwork.

Vendor records sit in the same programme as controls, evidence and the privacy data map, so a supplier processing personal data shows up in the Article 30 recipient fields and the transfer picture without a second register.

Because the same control library covers NIS2's supply chain measure and ISO 27001's supplier controls, one vendor assessment produces evidence for each framework that asks for it.

FAQ

Common questions

Talk to us

What is third-party risk management software?

Software that maintains an inventory of suppliers and processors, assesses the risk each carries, holds the contractual and due diligence record, and evidences that the assessment happened and stayed current.

How should vendors be prioritised for assessment?

By what they can reach. A vendor with production access or a large volume of personal data warrants depth; a vendor with no access to systems or data does not, regardless of what you pay them. Tiering by spend is the most common and most expensive mistake in the category.

What does GDPR Article 28 require of us?

That you only use processors providing sufficient guarantees of appropriate technical and organisational measures, and that the relationship is governed by a written contract covering the matters Article 28(3) sets out — including processing only on documented instructions, confidentiality, security, subprocessor rules, assistance with data subject rights, deletion or return, and audit rights.

Are security questionnaires worth sending?

For high-tier vendors, yes, as a structured way to ask specific questions and get an answer on the record. What they are not is evidence: responses are self-reported and describe a moment in time. Pair them with independent artefacts such as a current SOC 2 report or ISO 27001 certificate.

How does TPRM relate to NIS2?

NIS2 lists supply chain security among the Article 21 risk-management measures, including security in the relationships with direct suppliers. For entities in scope, third-party risk stops being a procurement nicety and becomes a regulated measure you have to evidence.

See Noru against your own systems

A 45-minute walkthrough against your frameworks, your integrations and your evidence.