THIRD PARTYCURRENT
Company directory

Third-party risk companies

Research the companies shaping third-party risk across lifecycle workflow, cyber intelligence, supplier risk, managed assessment, enterprise GRC, and multi-domain monitoring.

45 companies

Filter by the operating model or documented capability most relevant to your program.

OneTrust logo
TPRM Workflow Platform

OneTrust

Organizations evaluating a TPRM workflow within a broader privacy, security, and governance platform.

Market coverage5 documented capability areasTPRM Workflow Platform
Read dossier →
ProcessUnity icon
TPRM Workflow Platform

ProcessUnity

Organizations seeking a purpose-built third-party risk workflow and monitoring platform.

Market coverage5 documented capability areasTPRM Workflow Platform
Read dossier →
Aravo icon
TPRM Workflow Platform

Aravo

Enterprises coordinating multiple third-party risk domains across complex supplier populations.

Market coverage5 documented capability areasTPRM Workflow Platform
Read dossier →
Bitsight logo
Cyber Risk Intelligence And Ratings

Bitsight

Security-led programs prioritizing externally observed cyber-risk intelligence.

Market coverage4 documented capability areasCyber Risk Intelligence And Ratings
Read dossier →
SecurityScorecard logo
Cyber Risk Intelligence And Ratings

SecurityScorecard

Programs evaluating security ratings and portfolio-level cyber-risk monitoring.

Market coverage3 documented capability areasCyber Risk Intelligence And Ratings
Read dossier →
UpGuard logo
Cyber Risk Intelligence And Ratings

UpGuard

Cyber-focused teams combining vendor questionnaires with external monitoring.

Market coverage4 documented capability areasCyber Risk Intelligence And Ratings
Read dossier →
Mitratech Prevalent icon
TPRM Workflow Platform

Mitratech Prevalent

Organizations seeking lifecycle workflow, assessments, monitoring, and remediation in one TPRM product.

Market coverage7 documented capability areasTPRM Workflow Platform
Read dossier →
Panorays icon
Cyber Risk Intelligence And Ratings

Panorays

Security teams evaluating automated cyber assessments and monitoring.

Market coverage3 documented capability areasCyber Risk Intelligence And Ratings
Read dossier →
Whistic logo
Assessment Exchange

Whistic

Teams prioritizing security-assessment exchange and evidence reuse.

Market coverage3 documented capability areasAssessment Exchange
Read dossier →
MetricStream logo
Integrated GRC Platform

MetricStream

Large organizations evaluating TPRM within an integrated GRC program.

Market coverage6 documented capability areasIntegrated GRC Platform
Read dossier →
LogicGate icon
Integrated GRC Platform

LogicGate

Teams seeking configurable TPRM workflows within a broader risk platform.

Market coverage7 documented capability areasIntegrated GRC Platform
Read dossier →
Archer icon
Integrated GRC Platform

Archer

Mature regulated programs needing configurable enterprise risk workflows.

Market coverage5 documented capability areasIntegrated GRC Platform
Read dossier →
Black Kite icon
Cyber Risk Intelligence And Ratings

Black Kite

Cyber-risk programs prioritizing extended supply-chain visibility and explainable external intelligence.

Market coverage7 documented capability areasCyber Risk Intelligence And Ratings
Read dossier →
ServiceNow logo
Integrated GRC Platform

ServiceNow

Existing ServiceNow customers connecting third-party risk to enterprise workflows.

Market coverage9 documented capability areasIntegrated GRC Platform
Read dossier →
SAP logo for SAP Ariba Supplier Risk
Supplier Risk Suite

SAP Ariba Supplier Risk

Procurement-led programs embedding supplier risk in source-to-pay decisions.

Market coverage6 documented capability areasSupplier Risk Suite
Read dossier →
Venminder logo
Managed TPRM Platform

Venminder

Organizations combining TPRM software with optional outsourced assessment support.

Market coverage8 documented capability areasManaged TPRM Platform
Read dossier →
Resolver icon
Integrated GRC Platform

Resolver

Risk teams seeking configurable vendor onboarding, assessment, and issue workflows.

Market coverage5 documented capability areasIntegrated GRC Platform
Read dossier →
Riskonnect icon
Integrated GRC Platform

Riskonnect

Organizations connecting third-party risk to wider operational and enterprise risk programs.

Market coverage5 documented capability areasIntegrated GRC Platform
Read dossier →
Diligent logo
Integrated GRC Platform

Diligent

Governance and compliance teams evaluating automated third-party due diligence and monitoring.

Market coverage6 documented capability areasIntegrated GRC Platform
Read dossier →
Protecht logo
Integrated GRC Platform

Protecht

Organizations seeking vendor risk workflows connected to enterprise and operational risk.

Market coverage9 documented capability areasIntegrated GRC Platform
Read dossier →
Certa logo
TPRM Workflow Platform

Certa

Organizations seeking configurable, cross-domain third-party lifecycle orchestration rather than a cyber-only monitoring product.

Market coverage9 documented capability areasTPRM Workflow Platform
Read dossier →
Exiger logo
Multi-Domain Risk Intelligence

Exiger

Large enterprises and public-sector organizations that need third-party due diligence together with multi-tier supplier, trade, geopolitical, and compliance intelligence.

Market coverage8 documented capability areasMulti-Domain Risk Intelligence
Read dossier →
Risk Ledger icon
Assessment Exchange

Risk Ledger

Security-led programs seeking reusable supplier evidence, shared assessments, network visualization, and visibility beyond direct third parties.

Market coverage7 documented capability areasAssessment Exchange
Read dossier →
S&P Global KY3P neutral text identifier
Assessment Exchange

S&P Global KY3P

Regulated enterprises, particularly financial institutions and procurement organizations, seeking standardized assessments, reusable due-diligence data, monitoring, and managed support.

Market coverage10 documented capability areasAssessment Exchange
Read dossier →
BlueVoyant neutral text identifier
Managed TPRM Platform

BlueVoyant

Cybersecurity teams that want external risk monitoring tied to active remediation and expert program support rather than ratings alone.

Market coverage5 documented capability areasManaged TPRM Platform
Read dossier →
Supply Wisdom logo
Multi-Domain Risk Intelligence

Supply Wisdom

Risk, procurement, and resilience teams that need real-time financial, cyber, compliance, sustainability, operational, location, and nth-party monitoring.

Market coverage3 documented capability areasMulti-Domain Risk Intelligence
Read dossier →
Interos logo
Multi-Domain Risk Intelligence

Interos

Enterprises that need multi-tier supply-chain mapping, dynamic risk scoring, watchlists, and disruption intelligence across several risk domains.

Market coverage4 documented capability areasMulti-Domain Risk Intelligence
Read dossier →
Optro icon
Integrated GRC Platform

Optro

Audit, risk, compliance, and information-security teams that want third-party risk connected to a broader GRC record and control environment.

Market coverage7 documented capability areasIntegrated GRC Platform
Read dossier →
NAVEX logo
Integrated GRC Platform

NAVEX

Compliance-led organizations that want third-party screening and lifecycle oversight connected to enterprise ethics, compliance, operational, and IT risk activities.

Market coverage8 documented capability areasIntegrated GRC Platform
Read dossier →
Vanta logo
TPRM Workflow Platform

Vanta

Security and compliance teams that want vendor security reviews and monitoring connected to wider compliance, risk-register, and trust workflows.

Market coverage8 documented capability areasTPRM Workflow Platform
Read dossier →
Ncontracts logo
TPRM Workflow Platform

Ncontracts

Banks, credit unions, mortgage companies, fintechs, and other financial-services organizations seeking TPRM workflows aligned to sector-specific regulatory expectations.

Market coverage8 documented capability areasTPRM Workflow Platform
Read dossier →
CyberVadis logo
Managed TPRM Platform

CyberVadis

Organizations seeking expert-validated supplier cybersecurity assessments and shared evidence rather than relying only on self-attestation or outside-in ratings.

Market coverage6 documented capability areasManaged TPRM Platform
Read dossier →
RiskRecon logo
Cyber Risk Intelligence And Ratings

RiskRecon by Mastercard

Cyber TPRM teams seeking outside-in security ratings that can be tuned to risk policy and used to prioritize vendor engagement and remediation.

Market coverage4 documented capability areasCyber Risk Intelligence And Ratings
Read dossier →
RapidRatings logo
Multi-Domain Risk Intelligence

RapidRatings

Procurement, supply-chain, finance, and third-party risk teams that need comparable financial-health evidence for private as well as public vendors.

Market coverage4 documented capability areasMulti-Domain Risk Intelligence
Read dossier →
Dun & Bradstreet logo
Multi-Domain Risk Intelligence

Dun & Bradstreet

Compliance and risk teams that need identity-anchored business data for KYC or KYB, beneficial ownership, sanctions, anti-bribery, due diligence, and ongoing monitoring.

Market coverage5 documented capability areasMulti-Domain Risk Intelligence
Read dossier →
Coupa company identifier
Supplier Risk Suite

Coupa

Procurement-led organizations that want supplier risk records connected to a wider source-to-pay and supplier-management environment.

Market coverage9 documented capability areasSupplier Risk Suite
Read dossier →
Gatekeeper company identifier
TPRM Workflow Platform

Gatekeeper

Vendor-management teams seeking contract, supplier, assessment, renewal, and risk workflows in one operating environment.

Market coverage8 documented capability areasTPRM Workflow Platform
Read dossier →
CORL Technologies company identifier
Managed TPRM Platform

CORL Technologies

Healthcare providers, payers, and suppliers seeking sector-specific assessments, monitoring, and expert-led third-party risk support.

Market coverage8 documented capability areasManaged TPRM Platform
Read dossier →
Censinet company identifier
Assessment Exchange

Censinet

Healthcare organizations that want collaborative risk assessments, benchmarking, and supplier evidence within a sector-specific network.

Market coverage8 documented capability areasAssessment Exchange
Read dossier →
Mirato company identifier
TPRM Workflow Platform

Mirato

Programs seeking to unify evidence from existing enterprise systems and automate parts of assessment review without replacing their current control framework.

Market coverage7 documented capability areasTPRM Workflow Platform
Read dossier →
Ethixbase360 company identifier
Multi-Domain Risk Intelligence

Ethixbase360

Compliance-led programs combining anti-bribery, sanctions, ESG, modern-slavery, and broader third-party due diligence requirements.

Market coverage9 documented capability areasMulti-Domain Risk Intelligence
Read dossier →
Sayari company identifier
Multi-Domain Risk Intelligence

Sayari

Compliance, trade, procurement, and investigative teams that need corporate ownership, trade-flow, sanctions, forced-labor, and sub-tier relationship intelligence.

Market coverage9 documented capability areasMulti-Domain Risk Intelligence
Read dossier →
EcoVadis IQ Plus company identifier
Multi-Domain Risk Intelligence

EcoVadis IQ Plus

Procurement and sustainability teams that need supplier screening, risk prioritization, and evidence across environmental, social, ethical, and supply-chain due diligence domains.

Market coverage8 documented capability areasMulti-Domain Risk Intelligence
Read dossier →
IntegrityNext company identifier
Assessment Exchange

IntegrityNext

Procurement and sustainability teams coordinating supplier self-assessments, compliance evidence, monitoring, and due-diligence reporting across a broad supplier base.

Market coverage7 documented capability areasAssessment Exchange
Read dossier →
osapiens company identifier
Supplier Risk Suite

osapiens

Enterprises managing supplier risk, traceability, sustainability, and regulatory due diligence across complex international value chains.

Market coverage9 documented capability areasSupplier Risk Suite
Read dossier →

No company record matches that filter.

Try a company name, capability, or broader provider model.