Scrutineer.ai

Scrutineer · Vendor risk

Third party risk management that runs on continuous evidence

Third party risk management is where a lot of breaches actually start: a supplier, a contractor or a sub-processor with weak controls and access to your data. A real TPRM program has to assess every third party, score the risk and keep watching, not file a questionnaire and move on. Scrutineer does exactly that across your full third-party population.

Each third party gets an evidence-backed risk score covering its security posture, the data and systems it can reach, and its certifications, refreshed continuously as conditions change. Critical third parties get deeper scrutiny and tighter monitoring. When something degrades, you hear about it early. Your team owns the decisions; Scrutineer gives the program the structure and the evidence to back them.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Interactive walkthrough on a sample company, not a scan of your systems.

Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with third-party risk

The two authorities on TPRM disagree about where a program starts

The Interagency Guidance on Third-Party Relationships that the Federal Reserve, FDIC and OCC issued on June 6, 2023 opens with Planning as a distinct stage: identify the activity, decide whether it is critical, set the risk appetite, and consider whether to outsource at all. The NYDFS industry letter of October 21, 2025 runs four stages instead and folds planning into identification and due diligence. The disagreement matters because most programs skip the stage entirely. Assessment starts when procurement forwards a signed order form, by which point the questions that would have changed the outcome, whether to outsource this at all and what a failure would cost, are no longer live. A program that begins at due diligence is a compliance exercise. One that begins at planning is a risk program.

Budgets are front-loaded. The guidance is not.

Look at where a typical third-party risk program spends its effort and almost all of it sits in due diligence and contracting: questionnaires, review cycles, redlines. Then read how much space the same two documents give to ongoing monitoring and to termination. Both treat the back half of the life cycle as carrying equal weight, and termination is where the least tooling exists in the entire category. The guidance is specific about what it expects at exit: transition of the activity, return or destruction of data, and the ability to end the arrangement without unreasonable penalty. Ask most teams to produce evidence that a departed vendor destroyed their data and you get an email thread, if that. It is the cheapest finding an examiner will ever write.

Criticality is your call, and the guidance says so explicitly

A recurring request in vendor risk software demos is for the tool to decide which third parties are critical. No product can, and the interagency guidance is unusually direct about it: it is up to each banking organization to identify its critical activities and the third-party relationships that support them, and an activity that is critical at one organization may not be at another. Some organizations assign a criticality or risk level to every relationship; others identify critical activities first and work outward. Both are acceptable. What is not acceptable is a tier that came out of a black box. Scrutineer holds the tiering rule you chose, the evidence behind each classification, and the date it was last reviewed, so the answer to how you decided is a record rather than a recollection.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Assesses suppliers, contractors and sub-processors against one standard, so no part of the third-party population sits outside the program
  • Tiers third parties by the criticality rule your organization actually chose, and keeps the rule, the evidence and the review date on the record
  • Scores each relationship on real exposure: the data it reaches, the systems it touches, the certifications behind it
  • Tracks the contract terms that give you rights, including subcontractor notice, audit access, incident notification and exit provisions
  • Continuously monitors posture and certifications, so a lapse surfaces between reviews rather than at the next annual cycle
  • Carries termination and offboarding as a tracked stage, with data return or destruction evidence attached to the relationship record
  • Produces the documentation and reporting an examiner asks for, out of evidence the program collected anyway
  • Runs on the same control library as your SOC 2, ISO 27001 and HIPAA work, so third-party risk is not a separate system of record
Third-party risk readiness_report
Readiness 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Every finding links to the evidence behind it

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

TPRM life-cycle reference

What each stage of a third-party risk program actually has to produce

Most published life-cycle diagrams stop at naming the stages. The useful version names the artifact that proves the stage happened, because that is what an examiner asks for and the one thing a program cannot assemble after the fact. The two authorities below are the ones US teams are measured against, and they do not describe the same number of stages.

Life-cycle stage What the 2023 interagency guidance expects What the NYDFS October 2025 letter expects The artifact that proves it happened Where programs break
Planning A distinct first stage: identify the activity, decide whether it is critical, set risk appetite, and consider whether to outsource at all Folded into identification and due diligence rather than named separately A dated record of the criticality decision and who made it, created before a supplier was selected Skipped. Assessment starts when a signed order form arrives and the outsourcing decision is already made
Due diligence and selection Assess the third party's controls, financial condition, insurance, reliance on subcontractors and geographic footprint, in proportion to risk The same, plus explicit evaluation of the service provider's own diligence over its providers The completed assessment, the evidence behind it, and the reason the depth matched the tier Every vendor gets the same questionnaire regardless of tier, so critical vendors get shallow review and trivial ones get expensive review
Contract negotiation Specific provisions: subcontractor notice and consent, audit rights, incident notification, liability, monitoring costs, termination without unreasonable penalty Baseline clauses on access control, encryption, event notification, subcontractor requirements, data location and exit obligations The executed contract, mapped clause by clause to the rights the program relies on Security reviews the vendor and never reads the contract, so the program assumes rights it does not hold
Ongoing monitoring Monitor performance, control effectiveness, reliance on subcontractors, incidents and changes at the third party throughout the relationship Continuous oversight proportionate to risk, documented well enough for an examiner to inspect A dated trail of reassessments, certification renewals, incident notices and posture changes between annual reviews Annual reassessment only. Everything that changed in month three is discovered in month twelve, if at all
Termination and offboarding Transition the activity, return or destroy data, and retain the ability to terminate without unreasonable penalty Named as one of the four stages, carrying the same weight as due diligence Written confirmation of data return or destruction, access revocation records, and the transition plan that was actually executed The stage with the least tooling in the whole category. Most teams can produce an email thread and nothing else
Independent review and reporting Periodic independent review of the risk management process itself, plus documentation and reporting to the board Documentation of governance and oversight that examiners may request Internal audit reports on the program itself, and the board reporting pack showing what was escalated The program is reviewed by the people who run it, which is not an independent review

Expectations summarized from the Interagency Guidance on Third-Party Relationships: Risk Management issued June 6, 2023 by the Federal Reserve, FDIC and OCC, and the NYDFS industry letter on managing risks related to third-party service providers dated October 21, 2025. Both are supervisory guidance rather than prescriptive rules, and NYDFS states its letter imposes no new requirements. Apply them against your own regulator and risk profile. Scrutineer organizes readiness evidence and does not issue attestations.

Good questions

Questions about third-party risk

Third party risk management is the program that identifies, assesses, contracts for, monitors and eventually exits every external relationship your organization depends on. US supervisory guidance frames it as a life cycle rather than an assessment: planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination. The assessment most people picture is one stage out of five.
The June 2023 interagency guidance names five: planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination, with oversight, documentation and independent review running across all of them. The NYDFS industry letter of October 21, 2025 uses four, folding planning into identification and due diligence. If you answer to both, run five stages and map the four-stage vocabulary onto them.
In practice they overlap heavily and most tools sell both. The useful distinction is scope. Vendor risk usually means organizations you buy from and pay. Third party risk covers every external relationship that supports an activity, which also picks up joint ventures, agents, affiliates, franchisees and channel partners that never appear in accounts payable.
For US banking organizations, yes in substance. The Federal Reserve, FDIC and OCC issued uniform guidance on June 6, 2023 setting out sound practices across the whole life cycle, and examiners assess against it. For NYDFS covered entities, 23 NYCRR Part 500 requires a written third-party service provider policy, and the October 2025 industry letter describes what examiners expect to see. Other sectors carry narrower obligations through HIPAA, GLBA and contract.
You do, and the guidance says so plainly: it is up to each organization to identify its critical activities and the relationships that support them, and an activity critical at one organization may not be at another. No software can make that call for you. What software should do is record the rule you applied, the evidence behind each classification, and the date it was last reviewed.
Tie the interval to tier, then add event triggers on top. A critical third party that processes regulated data warrants at least annual reassessment plus a review whenever something material changes: an acquisition, a new subcontractor, an incident, an expired certification, or a change in the data it handles. Reassessment on a calendar alone means the program can learn about a change up to twelve months late.
At minimum: how relationships are identified and inventoried, the criticality rule and who approves it, the diligence depth required at each tier, the contract provisions that are mandatory, monitoring frequency and triggers, escalation paths, termination and data disposal requirements, and who reports what to the board. Every one of those has a matching artifact an examiner can ask to see.
It treats them as part of the third-party relationship rather than as a separate program. Due diligence should cover the volume and type of subcontracted work, how the third party selects and oversees its subcontractors, the geographic location of those subcontractors, and dependency on a single provider for multiple activities. The rights themselves come from contract clauses on notice, consent, reporting, liability and termination.
Any external organization with access to your data, systems or operations: software vendors, infrastructure providers, contractors, agencies and sub-processors. Scrutineer assesses and scores them all on a consistent standard so your whole third-party surface is covered.
By exposure. Third parties that touch sensitive data or critical systems are tiered higher, get deeper assessment and are monitored more frequently, so your team focuses effort where a failure would hurt most.

Keep reading

Guides that go deeper on this framework

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification