THIRD PARTYCURRENT
Author and research team

Third Party Current Research Desk

The desk maintains the company database, reviews primary sources, separates provider statements from editorial conclusions, and writes market analysis for third-party risk leaders.

Editorial remit

The Research Desk covers regulatory and standards changes, company moves, product releases, incidents, and original market data. Every article identifies the underlying source class and explains which statements are verified facts, company-reported claims, or Third Party Current analysis.

Provider profiles and comparisons use a shared taxonomy so readers can move from a news event to the affected company and capability record. A product announcement may create a dated change record without changing the comparative dataset until supporting evidence is reviewed.

Recent work

Official managed-TPRM service analysis

Censinet managed TPRM needs activity-level accountability

Censinet offers self-directed, hybrid-support, and fully managed operating models for healthcare third-party risk. Buyers still need an activity-by-activity record of who performs the work, who supplies evidence, who decides, and who remains accountable when a finding moves into remediation.

Official TPRM product analysis

LogicGate agent findings need reviewer disposition evidence

LogicGate says its third-party-risk agents can triage vendor requests, evaluate questionnaires against a control framework, and create linked findings ready for remediation while practitioners stay involved in approvals. Buyers still need source evidence, agent and policy versions, reviewer judgment, overrides, disposition authority, and downstream action receipts.

Official TPRM platform analysis

MetricStream KPI scores need service-level evidence

MetricStream says third-party profiles can combine contracts, issues, assessments, risk ratings, and business relationships, while KPI scores cover cost, delivery, service, and quality. Those scores can focus attention, but buyers still need the source measures, population, formula, thresholds, missing-data state, service scope, and exception decisions behind each result.

Official TPRM network analysis

Risk Ledger community intelligence needs source, scope, and reuse boundaries

Risk Ledger describes a collaborative supplier network in which organizations can share intelligence and respond to emerging threats. Reuse can shorten discovery time, but a community observation still needs attributable origin, scoped applicability, sharing permission, correction history, and a buyer-owned disposition before it becomes relationship evidence.

Official TPRM intelligence analysis

A Black Kite financial-impact estimate needs its scenario basis

Black Kite presents third-party cyber intelligence that includes transparent ratings, ransomware susceptibility, continuous monitoring, and the financial impact of cyber risk. A monetary estimate can focus review, but it is defensible only when the modeled event, affected service, exposure assumptions, evidence cutoff, uncertainty, and decision use remain visible.

Official TPRM workflow analysis

An UpGuard vendor tier needs a dated relationship rubric

UpGuard describes vendor tiers as classifications of inherent risk that can determine assessment depth and can be assigned manually or through rules based on relationship-questionnaire responses. A tier can organize diligence, but it remains defensible only when the relationship facts, rubric version, evidence, reviewer, effective period, and prior classification stay reconstructable.

Official TPRM platform analysis

An Aravo integrated risk finding needs source-level reconciliation

Aravo describes a TPRM platform that can integrate findings from many risk-intelligence providers into a third party's evaluation and score. Consolidation can accelerate review, but it does not make conflicting entity matches, observation dates, methods, or source conclusions equivalent.

Official TPRM platform analysis

A ServiceNow remediation task closure is not third-party risk acceptance

ServiceNow positions third-party risk inside an enterprise workflow that can connect monitoring, issues, remediation, reporting, and offboarding. Closing a remediation task can prove that assigned work reached a configured state, but it does not by itself establish that the underlying finding was corrected, independently verified, or accepted by an authorized risk owner.

Official TPRM platform analysis

A Protecht vendor response needs artifact-level provenance

Protecht documents a secure vendor workspace for documents, tasks, and questionnaires, alongside automated evidence collection and AI-assisted assessment. A completed response can move diligence forward, but it should not become validated assurance until every artifact retains its source, scope, version, attestor, validity period, and review history.

Official TPRM platform analysis

Ncontracts needs separate clocks for contract renewal and risk review

Ncontracts presents vendor management for financial institutions with onboarding, due diligence, risk assessments, contract management, ongoing monitoring, and exit support. A renewal date can organize commercial work, but it should not reset, extend, or stand in for the evidence and authority behind a third-party risk decision.

Official TPRM platform analysis

A ProcessUnity monitoring alert needs a reassessment record

ProcessUnity describes continuous vendor monitoring, external intelligence connectors, alerts, issue management, and role-specific reporting. Those capabilities can surface a changed condition quickly, but an alert becomes decision evidence only when the affected relationship, source state, review, authority, and resulting action remain linked.

Official TPRM platform analysis

For Certa's automated TPRM decisions, rule provenance is the control

Certa describes an automated decision engine based on preset risk factors, paired with workflow routing, escalation, and detailed audit trails. That architecture can make routine decisions faster, but a defensible result still needs the exact rule version, inputs, exception path, and authority that produced it.

Official platform analysis

Mitratech Prevalent spans onboarding to offboarding—but offboarding completion is not access-revocation proof

Mitratech presents Prevalent as a third-party risk management environment spanning vendor intake, contracts, assessment, monitoring, remediation, and offboarding. Closing that workflow can document the end of a relationship, but it does not by itself prove that accounts, tokens, integrations, facilities access, retained data, and downstream dependencies were actually terminated.

Primary-source analysis

DORA makes ICT concentration a pre-contract decision

Article 29 puts substitutability, repeated reliance on the same or connected providers, alternative solutions, and subcontracting risk into the assessment before critical ICT services are contracted.

Primary-source analysis

PRA SS2/21 makes outsourcing exit plans testable

For material outsourcing, the current supervisory statement treats exit as a planned, owned, costed, and risk-based test—not a clause that can wait for supplier failure.