THIRD PARTYCURRENT
Original dataset · 2026

What 45 TPRM companies document about capability coverage

Assessment and reporting language appears most broadly in the maintained sample. Fourth-party visibility and offboarding are documented less often. The counts describe reviewed official pages—not independently tested functionality.

THIRD PARTY CURRENTProvider capability coverage2026 data note
Executive summary

Documentation is broadest around core assessment and reporting work

The public record becomes less consistent as the capability moves toward downstream relationship visibility and formal lifecycle closure. That difference can reflect product scope, source-page emphasis, or the maturity of the category—not necessarily absent functionality.

Key findings

The maintained sample contains 45 companies across 7 primary operating models. Every company has at least one approved official product source and a normalized capability record. No product was independently tested for this report.

Reporting appears in 45 company records, the highest documented frequency in the sample. Offboarding appears in 12, the lowest. The difference is best read as a map of public positioning and buyer-research surfaces.

Figure 1. Number of company records with official positioning relevant to each normalized capability. Population: 45; sources verified July 19, 2026. A count is not a product-quality score.

Interpretation

Core assessment and reporting language is easier to find because those functions sit near the historical center of third-party risk programs. They are also broad labels. A provider can document “assessment” while differing materially in evidence reuse, reviewer workflow, control testing, or disposition.

Lower-frequency areas deserve careful interpretation. Offboarding may be performed through workflow configuration without occupying a dedicated product page. Fourth-party visibility may depend on an external dataset or specialized module. The current method therefore preserves “not established” rather than asserting that a feature is absent.

The market's category convergence is visible in the capability spread. Workflow, cyber-intelligence, GRC, supplier-risk, assessment-exchange, managed-service, and multi-domain intelligence companies share many terms while beginning from different evidence and ownership models. Buyers should use the count to identify who to investigate, then test the operating chain behind the language.

Methodology

  1. Define ten capability areas before reviewing the company sources.
  2. Select companies with official evidence of a direct third-party risk use case.
  3. Register at least one official product or documentation source for each company.
  4. Record a capability only when the approved source supports relevant positioning.
  5. Keep missing evidence as “not established,” not “feature absent.”
  6. Count company records by capability and preserve the source and verification date.

Limitations

  • Official pages can omit capabilities available in a product tier, service, or configuration.
  • Official positioning can overstate operational depth or availability.
  • The sample is substantial but not presented as the complete global market.
  • No product was independently tested for this report.
  • Counts can change when official evidence, products, or the normalized taxonomy changes.

Reproducibility and corrections

Every company count resolves to a company dossier and a registered source. Providers and readers may submit a source-backed correction without payment. Material changes should preserve the prior value, evidence, and date rather than silently rewriting the dataset.

Dataset record

Population: 45 companies. Capabilities: 10. Registered primary sources: 58. Fact records: 515. Verification date: July 19, 2026. Maintained by Third Party Current.