Build a capability-based research list
Select the capabilities your operating model requires. Results show companies whose reviewed official source documents every selected area. This is a research starting point—not a recommendation.
Use the related capability explainers to define the workflow and evidence before treating a checkbox as a requirement.
45 companies
OneTrust
Organizations evaluating a TPRM workflow within a broader privacy, security, and governance platform.
PProcessUnity
Organizations seeking a purpose-built third-party risk workflow and monitoring platform.
AAravo
Enterprises coordinating multiple third-party risk domains across complex supplier populations.
Bitsight
Security-led programs prioritizing externally observed cyber-risk intelligence.
SSecurityScorecard
Programs evaluating security ratings and portfolio-level cyber-risk monitoring.
UpGuard
Cyber-focused teams combining vendor questionnaires with external monitoring.
MPMitratech Prevalent
Organizations seeking lifecycle workflow, assessments, monitoring, and remediation in one TPRM product.
PPanorays
Security teams evaluating automated cyber assessments and monitoring.
Whistic
Teams prioritizing security-assessment exchange and evidence reuse.
MMetricStream
Large organizations evaluating TPRM within an integrated GRC program.
LogicGate
Teams seeking configurable TPRM workflows within a broader risk platform.
AArcher
Mature regulated programs needing configurable enterprise risk workflows.
Black Kite
Cyber-risk programs prioritizing extended supply-chain visibility and explainable external intelligence.
ServiceNow
Existing ServiceNow customers connecting third-party risk to enterprise workflows.
SAP Ariba Supplier Risk
Procurement-led programs embedding supplier risk in source-to-pay decisions.
VVenminder
Organizations combining TPRM software with optional outsourced assessment support.
RResolver
Risk teams seeking configurable vendor onboarding, assessment, and issue workflows.
RRiskonnect
Organizations connecting third-party risk to wider operational and enterprise risk programs.
Diligent
Governance and compliance teams evaluating automated third-party due diligence and monitoring.
PProtecht
Organizations seeking vendor risk workflows connected to enterprise and operational risk.
Certa
Organizations seeking configurable, cross-domain third-party lifecycle orchestration rather than a cyber-only monitoring product.
EExiger
Large enterprises and public-sector organizations that need third-party due diligence together with multi-tier supplier, trade, geopolitical, and compliance intelligence.
RLRisk Ledger
Security-led programs seeking reusable supplier evidence, shared assessments, network visualization, and visibility beyond direct third parties.
S&P Global KY3P
Regulated enterprises, particularly financial institutions and procurement organizations, seeking standardized assessments, reusable due-diligence data, monitoring, and managed support.
BlueVoyant
Cybersecurity teams that want external risk monitoring tied to active remediation and expert program support rather than ratings alone.
SWSupply Wisdom
Risk, procurement, and resilience teams that need real-time financial, cyber, compliance, sustainability, operational, location, and nth-party monitoring.
IInteros
Enterprises that need multi-tier supply-chain mapping, dynamic risk scoring, watchlists, and disruption intelligence across several risk domains.
Optro
Audit, risk, compliance, and information-security teams that want third-party risk connected to a broader GRC record and control environment.
NAVEX
Compliance-led organizations that want third-party screening and lifecycle oversight connected to enterprise ethics, compliance, operational, and IT risk activities.
Vanta
Security and compliance teams that want vendor security reviews and monitoring connected to wider compliance, risk-register, and trust workflows.
NNcontracts
Banks, credit unions, mortgage companies, fintechs, and other financial-services organizations seeking TPRM workflows aligned to sector-specific regulatory expectations.
CyberVadis
Organizations seeking expert-validated supplier cybersecurity assessments and shared evidence rather than relying only on self-attestation or outside-in ratings.
RiskRecon by Mastercard
Cyber TPRM teams seeking outside-in security ratings that can be tuned to risk policy and used to prioritize vendor engagement and remediation.
RRapidRatings
Procurement, supply-chain, finance, and third-party risk teams that need comparable financial-health evidence for private as well as public vendors.
Dun & Bradstreet
Compliance and risk teams that need identity-anchored business data for KYC or KYB, beneficial ownership, sanctions, anti-bribery, due diligence, and ongoing monitoring.
Coupa
Procurement-led organizations that want supplier risk records connected to a wider source-to-pay and supplier-management environment.
Gatekeeper
Vendor-management teams seeking contract, supplier, assessment, renewal, and risk workflows in one operating environment.
CORL Technologies
Healthcare providers, payers, and suppliers seeking sector-specific assessments, monitoring, and expert-led third-party risk support.
Censinet
Healthcare organizations that want collaborative risk assessments, benchmarking, and supplier evidence within a sector-specific network.
Mirato
Programs seeking to unify evidence from existing enterprise systems and automate parts of assessment review without replacing their current control framework.
Ethixbase360
Compliance-led programs combining anti-bribery, sanctions, ESG, modern-slavery, and broader third-party due diligence requirements.
Sayari
Compliance, trade, procurement, and investigative teams that need corporate ownership, trade-flow, sanctions, forced-labor, and sub-tier relationship intelligence.
EcoVadis IQ Plus
Procurement and sustainability teams that need supplier screening, risk prioritization, and evidence across environmental, social, ethical, and supply-chain due diligence domains.
IntegrityNext
Procurement and sustainability teams coordinating supplier self-assessments, compliance evidence, monitoring, and due-diligence reporting across a broad supplier base.
osapiens
Enterprises managing supplier risk, traceability, sustainability, and regulatory due diligence across complex international value chains.
No current record documents every selected area.
Remove a filter or examine adjacent company categories and implementation models.
Interpretation limit
A match means an approved official source supported relevant positioning at the verification date. It does not establish depth, product tier, data dependencies, implementation fit, or performance. Read the dataset method.