THIRD PARTYCURRENT
Interactive research tool

Build a capability-based research list

Select the capabilities your operating model requires. Results show companies whose reviewed official source documents every selected area. This is a research starting point—not a recommendation.

Capabilities

Use the related capability explainers to define the workflow and evidence before treating a checkbox as a requirement.

45 companies

OneTrust logo

OneTrust

Organizations evaluating a TPRM workflow within a broader privacy, security, and governance platform.

Review →
ProcessUnity icon

ProcessUnity

Organizations seeking a purpose-built third-party risk workflow and monitoring platform.

Review →
Aravo icon

Aravo

Enterprises coordinating multiple third-party risk domains across complex supplier populations.

Review →
Bitsight logo

Bitsight

Security-led programs prioritizing externally observed cyber-risk intelligence.

Review →
SecurityScorecard logo

SecurityScorecard

Programs evaluating security ratings and portfolio-level cyber-risk monitoring.

Review →
UpGuard logo

UpGuard

Cyber-focused teams combining vendor questionnaires with external monitoring.

Review →
Mitratech Prevalent icon

Mitratech Prevalent

Organizations seeking lifecycle workflow, assessments, monitoring, and remediation in one TPRM product.

Review →
Panorays icon

Panorays

Security teams evaluating automated cyber assessments and monitoring.

Review →
Whistic logo

Whistic

Teams prioritizing security-assessment exchange and evidence reuse.

Review →
MetricStream logo

MetricStream

Large organizations evaluating TPRM within an integrated GRC program.

Review →
LogicGate icon

LogicGate

Teams seeking configurable TPRM workflows within a broader risk platform.

Review →
Archer icon

Archer

Mature regulated programs needing configurable enterprise risk workflows.

Review →
Black Kite icon

Black Kite

Cyber-risk programs prioritizing extended supply-chain visibility and explainable external intelligence.

Review →
ServiceNow logo

ServiceNow

Existing ServiceNow customers connecting third-party risk to enterprise workflows.

Review →
SAP logo for SAP Ariba Supplier Risk

SAP Ariba Supplier Risk

Procurement-led programs embedding supplier risk in source-to-pay decisions.

Review →
Venminder logo

Venminder

Organizations combining TPRM software with optional outsourced assessment support.

Review →
Resolver icon

Resolver

Risk teams seeking configurable vendor onboarding, assessment, and issue workflows.

Review →
Riskonnect icon

Riskonnect

Organizations connecting third-party risk to wider operational and enterprise risk programs.

Review →
Diligent logo

Diligent

Governance and compliance teams evaluating automated third-party due diligence and monitoring.

Review →
Protecht logo

Protecht

Organizations seeking vendor risk workflows connected to enterprise and operational risk.

Review →
Certa logo

Certa

Organizations seeking configurable, cross-domain third-party lifecycle orchestration rather than a cyber-only monitoring product.

Review →
Exiger logo

Exiger

Large enterprises and public-sector organizations that need third-party due diligence together with multi-tier supplier, trade, geopolitical, and compliance intelligence.

Review →
Risk Ledger icon

Risk Ledger

Security-led programs seeking reusable supplier evidence, shared assessments, network visualization, and visibility beyond direct third parties.

Review →
S&P Global KY3P neutral text identifier

S&P Global KY3P

Regulated enterprises, particularly financial institutions and procurement organizations, seeking standardized assessments, reusable due-diligence data, monitoring, and managed support.

Review →
BlueVoyant neutral text identifier

BlueVoyant

Cybersecurity teams that want external risk monitoring tied to active remediation and expert program support rather than ratings alone.

Review →
Supply Wisdom logo

Supply Wisdom

Risk, procurement, and resilience teams that need real-time financial, cyber, compliance, sustainability, operational, location, and nth-party monitoring.

Review →
Interos logo

Interos

Enterprises that need multi-tier supply-chain mapping, dynamic risk scoring, watchlists, and disruption intelligence across several risk domains.

Review →
Optro icon

Optro

Audit, risk, compliance, and information-security teams that want third-party risk connected to a broader GRC record and control environment.

Review →
NAVEX logo

NAVEX

Compliance-led organizations that want third-party screening and lifecycle oversight connected to enterprise ethics, compliance, operational, and IT risk activities.

Review →
Vanta logo

Vanta

Security and compliance teams that want vendor security reviews and monitoring connected to wider compliance, risk-register, and trust workflows.

Review →
Ncontracts logo

Ncontracts

Banks, credit unions, mortgage companies, fintechs, and other financial-services organizations seeking TPRM workflows aligned to sector-specific regulatory expectations.

Review →
CyberVadis logo

CyberVadis

Organizations seeking expert-validated supplier cybersecurity assessments and shared evidence rather than relying only on self-attestation or outside-in ratings.

Review →
RiskRecon logo

RiskRecon by Mastercard

Cyber TPRM teams seeking outside-in security ratings that can be tuned to risk policy and used to prioritize vendor engagement and remediation.

Review →
RapidRatings logo

RapidRatings

Procurement, supply-chain, finance, and third-party risk teams that need comparable financial-health evidence for private as well as public vendors.

Review →
Dun & Bradstreet logo

Dun & Bradstreet

Compliance and risk teams that need identity-anchored business data for KYC or KYB, beneficial ownership, sanctions, anti-bribery, due diligence, and ongoing monitoring.

Review →
Coupa company identifier

Coupa

Procurement-led organizations that want supplier risk records connected to a wider source-to-pay and supplier-management environment.

Review →
Gatekeeper company identifier

Gatekeeper

Vendor-management teams seeking contract, supplier, assessment, renewal, and risk workflows in one operating environment.

Review →
CORL Technologies company identifier

CORL Technologies

Healthcare providers, payers, and suppliers seeking sector-specific assessments, monitoring, and expert-led third-party risk support.

Review →
Censinet company identifier

Censinet

Healthcare organizations that want collaborative risk assessments, benchmarking, and supplier evidence within a sector-specific network.

Review →
Mirato company identifier

Mirato

Programs seeking to unify evidence from existing enterprise systems and automate parts of assessment review without replacing their current control framework.

Review →
Ethixbase360 company identifier

Ethixbase360

Compliance-led programs combining anti-bribery, sanctions, ESG, modern-slavery, and broader third-party due diligence requirements.

Review →
Sayari company identifier

Sayari

Compliance, trade, procurement, and investigative teams that need corporate ownership, trade-flow, sanctions, forced-labor, and sub-tier relationship intelligence.

Review →
EcoVadis IQ Plus company identifier

EcoVadis IQ Plus

Procurement and sustainability teams that need supplier screening, risk prioritization, and evidence across environmental, social, ethical, and supply-chain due diligence domains.

Review →
IntegrityNext company identifier

IntegrityNext

Procurement and sustainability teams coordinating supplier self-assessments, compliance evidence, monitoring, and due-diligence reporting across a broad supplier base.

Review →
osapiens company identifier

osapiens

Enterprises managing supplier risk, traceability, sustainability, and regulatory due diligence across complex international value chains.

Review →

No current record documents every selected area.

Remove a filter or examine adjacent company categories and implementation models.

Interpretation limit

A match means an approved official source supported relevant positioning at the verification date. It does not establish depth, product tier, data dependencies, implementation fit, or performance. Read the dataset method.