Vendor Risk
The capabilities.
Each one runs on the shared spine: owners and checkers, evidence with validity windows, and every action in the immutable audit trail.
Questionnaire assessments from curated templates (security, data protection, financial, regulatory)
Risk scoring into a tier (low / medium / high / critical), inherent vs residual
Material vendor risks link into the ERM register
Reassessment cadence by tier; contract, renewal and attestation tracking
The frameworks it speaks to.
Curated in the shared catalog and cross-mapped, so the work you do in this module counts toward each of them.
Works with
Records here link to the same owners, evidence and audit trail these modules read from. Nothing is re-entered; nothing drifts apart.
See all twelve modulesThe sectors and seats it serves.
Compliance you can prove.
Walk into your next audit ready.
Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.
The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.