OneTrust centralizes third-party profiles—but a vendor record is not a service-dependency map
OneTrust describes a centralized third-party inventory connected to onboarding, assessments, monitoring, and reporting. A legal-entity profile can organize work while the buyer still has to identify the products, services, integrations, locations, data, and downstream parties that create the actual dependency.
Third Party Current editorial graphic. Source material: OneTrust Third-Party Risk Management; analysis and presentation by Third Party Current.
The inventory should begin with the relationship, not end with the company name
OneTrust presents third-party risk management as a lifecycle that can begin with onboarding and a centralized inventory, continue through assessments and monitoring, and trigger later reassessment. Its page says teams can aggregate details into a single editable profile and use the inventory to prioritize relationships. That can give risk, procurement, security, privacy, compliance, and business owners a common place to coordinate evidence and action.
The useful operating object is often narrower than the legal vendor. One company may supply several products, host different environments, process distinct data sets, use different subcontractors, serve multiple business units, and support both critical and noncritical processes. Conversely, one business service may depend on several contracting entities and technical components. If the inventory holds only a company-level profile, a current assessment can appear to cover a dependency that was never actually reviewed.
A dependency record needs scope, ownership, and lineage
For each relationship, teams should connect the contracting entity to the specific service or product, accountable business owner, supported process, information and system access, integration, hosting and operating locations, user population, data classes, recovery requirement, fourth parties, contract, assessment scope, exceptions, and monitoring rules. Those links let a reviewer understand why one relationship is material and which evidence applies when the vendor profile contains several offerings.
The model should also preserve change. A new module, data category, integration, jurisdiction, subcontractor, processing location, renewal term, or business owner can alter the risk object without changing the vendor's name. Reassessment triggers should point to the changed dependency and the affected decisions. Overwriting the profile with today's description can erase the earlier scope and make it impossible to reconstruct why approval, conditions, or remediation were reasonable at the time.
Test one vendor with two materially different services
A representative evaluation should onboard one company that provides both a low-risk administrative service and a critical service with privileged access and downstream hosting. The team should assign different owners, evidence requirements, review cadences, contract conditions, recovery expectations, and monitoring signals. It should then change one integration and add a fourth party. Users should see which risk conclusion expires, which controls remain reusable, and which records require a new decision.
OneTrust's official page supports the described inventory, assessment, monitoring, and workflow positioning, but no configured profile model, control mapping, data source, reassessment rule, integration, implementation, or customer outcome was independently tested here. Buyers retain responsibility for defining the governed relationship, evidence scope, decision authority, residual-risk conditions, and review history. A centralized record can coordinate that work; it does not determine the dependency or accept its risk.
What we will watch next
Third Party Current will watch for later primary-source evidence that changes the maintained company, capability, or standards record. The next useful evidence may include implementation documentation, release details, regulator findings, corrected methods, product packaging, customer-observable workflow, or a subsequent company statement. Until then, the dated source and its stated boundary remain attached to this analysis.