THIRD PARTYCURRENT
Newsroom

Latest third-party risk news

Reporting and analysis on the standards, companies, products, incidents, and research changing third-party risk decisions.

Operating Models

Censinet managed TPRM needs activity-level accountability

Censinet offers self-directed, hybrid-support, and fully managed operating models for healthcare third-party risk. Buyers still need an activity-by-activity record of who performs the work, who supplies evidence, who decides, and who remains accountable when a finding moves into remediation.

Official TPRM product analysis

LogicGate agent findings need reviewer disposition evidence

LogicGate says its third-party-risk agents can triage vendor requests, evaluate questionnaires against a control framework, and create linked findings ready for remediation while practitioners stay involved in approvals. Buyers still need source evidence, agent and policy versions, reviewer judgment, overrides, disposition authority, and downstream action receipts.

Official TPRM platform analysis

MetricStream KPI scores need service-level evidence

MetricStream says third-party profiles can combine contracts, issues, assessments, risk ratings, and business relationships, while KPI scores cover cost, delivery, service, and quality. Those scores can focus attention, but buyers still need the source measures, population, formula, thresholds, missing-data state, service scope, and exception decisions behind each result.

Official TPRM network analysis

Risk Ledger community intelligence needs source, scope, and reuse boundaries

Risk Ledger describes a collaborative supplier network in which organizations can share intelligence and respond to emerging threats. Reuse can shorten discovery time, but a community observation still needs attributable origin, scoped applicability, sharing permission, correction history, and a buyer-owned disposition before it becomes relationship evidence.

Official TPRM intelligence analysis

A Black Kite financial-impact estimate needs its scenario basis

Black Kite presents third-party cyber intelligence that includes transparent ratings, ransomware susceptibility, continuous monitoring, and the financial impact of cyber risk. A monetary estimate can focus review, but it is defensible only when the modeled event, affected service, exposure assumptions, evidence cutoff, uncertainty, and decision use remain visible.

Official TPRM workflow analysis

An UpGuard vendor tier needs a dated relationship rubric

UpGuard describes vendor tiers as classifications of inherent risk that can determine assessment depth and can be assigned manually or through rules based on relationship-questionnaire responses. A tier can organize diligence, but it remains defensible only when the relationship facts, rubric version, evidence, reviewer, effective period, and prior classification stay reconstructable.

Official TPRM platform analysis

An Aravo integrated risk finding needs source-level reconciliation

Aravo describes a TPRM platform that can integrate findings from many risk-intelligence providers into a third party's evaluation and score. Consolidation can accelerate review, but it does not make conflicting entity matches, observation dates, methods, or source conclusions equivalent.

Official TPRM platform analysis

A ServiceNow remediation task closure is not third-party risk acceptance

ServiceNow positions third-party risk inside an enterprise workflow that can connect monitoring, issues, remediation, reporting, and offboarding. Closing a remediation task can prove that assigned work reached a configured state, but it does not by itself establish that the underlying finding was corrected, independently verified, or accepted by an authorized risk owner.

Official TPRM platform analysis

A Protecht vendor response needs artifact-level provenance

Protecht documents a secure vendor workspace for documents, tasks, and questionnaires, alongside automated evidence collection and AI-assisted assessment. A completed response can move diligence forward, but it should not become validated assurance until every artifact retains its source, scope, version, attestor, validity period, and review history.

Official TPRM platform analysis

Ncontracts needs separate clocks for contract renewal and risk review

Ncontracts presents vendor management for financial institutions with onboarding, due diligence, risk assessments, contract management, ongoing monitoring, and exit support. A renewal date can organize commercial work, but it should not reset, extend, or stand in for the evidence and authority behind a third-party risk decision.

Official TPRM platform analysis

A ProcessUnity monitoring alert needs a reassessment record

ProcessUnity describes continuous vendor monitoring, external intelligence connectors, alerts, issue management, and role-specific reporting. Those capabilities can surface a changed condition quickly, but an alert becomes decision evidence only when the affected relationship, source state, review, authority, and resulting action remain linked.

Official TPRM platform analysis

For Certa's automated TPRM decisions, rule provenance is the control

Certa describes an automated decision engine based on preset risk factors, paired with workflow routing, escalation, and detailed audit trails. That architecture can make routine decisions faster, but a defensible result still needs the exact rule version, inputs, exception path, and authority that produced it.

Official platform analysis

Mitratech Prevalent spans onboarding to offboarding—but offboarding completion is not access-revocation proof

Mitratech presents Prevalent as a third-party risk management environment spanning vendor intake, contracts, assessment, monitoring, remediation, and offboarding. Closing that workflow can document the end of a relationship, but it does not by itself prove that accounts, tokens, integrations, facilities access, retained data, and downstream dependencies were actually terminated.

Official cyber-intelligence analysis

Bitsight monitors external cyber posture—but a rating is a triage signal, not control evidence

Bitsight describes daily security ratings, continuous third- and fourth-party monitoring, assessments, and evidence workflows. An outside-in signal can prioritize review, but it cannot by itself establish which internal control exists, how it is configured, whether it operated, or whether the buyer should accept the risk.

Official platform analysis

OneTrust centralizes third-party profiles—but a vendor record is not a service-dependency map

OneTrust describes a centralized third-party inventory connected to onboarding, assessments, monitoring, and reporting. A legal-entity profile can organize work while the buyer still has to identify the products, services, integrations, locations, data, and downstream parties that create the actual dependency.

Primary-source analysis

NYDFS makes third-party policy a recurring control record

Section 500.11 connects third-party identification, minimum practices, due diligence, periodic reassessment, and contract guidance instead of treating a questionnaire as the whole control.

Primary-source analysis

Federal Reserve guide makes information gaps a risk decision

The community-bank guide says unavailable due-diligence evidence should lead to alternative information, controls, or monitoring—not an unexplained pass or a silent stop in the review.

Primary-source analysis

DORA makes ICT concentration a pre-contract decision

Article 29 puts substitutability, repeated reliance on the same or connected providers, alternative solutions, and subcontracting risk into the assessment before critical ICT services are contracted.

Primary-source analysis

PRA SS2/21 makes outsourcing exit plans testable

For material outsourcing, the current supervisory statement treats exit as a planned, owned, costed, and risk-based test—not a clause that can wait for supplier failure.

Primary-source analysis

NIS2 makes supplier security part of the entity's controls

Article 21 puts supply-chain security inside the risk measures for essential and important entities. A supplier score cannot replace the entity's own relationship-specific controls.

Primary-source analysis

Interagency guidance makes relationship structure a risk fact

Federal banking agencies apply third-party risk principles across relationship types and structures. The operating record must explain how each arrangement works.

Primary-source analysis

NIST SP 800-161 makes supplier criticality a lifecycle decision

NIST's cyber supply-chain guidance does not reduce third-party risk to an onboarding questionnaire. It connects products, services, suppliers, system context, and risk response across the life of the relationship.

Standards Watch

ISO supplier-security standard enters systematic review

ISO/IEC 27036-1 remains the published supplier-relationship standard while its 2026 review determines whether the current edition should be confirmed, revised, or withdrawn.

Regulatory Analysis

CPS 230 puts service-provider resilience into force in Australia

APRA's operational-risk standard now requires regulated entities to connect material service-provider oversight with critical operations, formal agreements, monitoring, and continuity planning.

Analysis

NIST pulls supply-chain risk into the system planning record

SP 800-18 Revision 2 treats cybersecurity supply-chain risk planning as part of the broader system risk record, raising the importance of traceable ownership and evidence.

Product Analysis

ProcessUnity launches a controls-driven risk index

The new rating approach reflects a market shift toward combining external signals with evidence from the organization's own assessment and control process.

Research Review

Censinet opens a healthcare cyber and AI governance benchmark

The 2026 study brings healthcare organizations, industry groups, and several control frameworks into one benchmarking program, creating useful peer context with important participation limits.

Partnership Analysis

CORL brings RiskRecon monitoring into its healthcare TPRM service

The partnership combines outside-in cyber signals with healthcare-specific assessment and advisory work, illustrating how managed TPRM providers are packaging intelligence into response workflows.