Scrutineer · Vendor risk
Third party risk management that runs on continuous evidence
Third party risk management is where a lot of breaches actually start: a supplier, a contractor or a sub-processor with weak controls and access to your data. A real TPRM program has to assess every third party, score the risk and keep watching, not file a questionnaire and move on. Scrutineer does exactly that across your full third-party population.
Each third party gets an evidence-backed risk score covering its security posture, the data and systems it can reach, and its certifications, refreshed continuously as conditions change. Critical third parties get deeper scrutiny and tighter monitoring. When something degrades, you hear about it early. Your team owns the decisions; Scrutineer gives the program the structure and the evidence to back them.
Control-mapped findings · linked evidence · you decide what to remediate
Interactive walkthrough on a sample company, not a scan of your systems.
›
Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with third-party risk
The two authorities on TPRM disagree about where a program starts
The Interagency Guidance on Third-Party Relationships that the Federal Reserve, FDIC and OCC issued on June 6, 2023 opens with Planning as a distinct stage: identify the activity, decide whether it is critical, set the risk appetite, and consider whether to outsource at all. The NYDFS industry letter of October 21, 2025 runs four stages instead and folds planning into identification and due diligence. The disagreement matters because most programs skip the stage entirely. Assessment starts when procurement forwards a signed order form, by which point the questions that would have changed the outcome, whether to outsource this at all and what a failure would cost, are no longer live. A program that begins at due diligence is a compliance exercise. One that begins at planning is a risk program.
Budgets are front-loaded. The guidance is not.
Look at where a typical third-party risk program spends its effort and almost all of it sits in due diligence and contracting: questionnaires, review cycles, redlines. Then read how much space the same two documents give to ongoing monitoring and to termination. Both treat the back half of the life cycle as carrying equal weight, and termination is where the least tooling exists in the entire category. The guidance is specific about what it expects at exit: transition of the activity, return or destruction of data, and the ability to end the arrangement without unreasonable penalty. Ask most teams to produce evidence that a departed vendor destroyed their data and you get an email thread, if that. It is the cheapest finding an examiner will ever write.
Criticality is your call, and the guidance says so explicitly
A recurring request in vendor risk software demos is for the tool to decide which third parties are critical. No product can, and the interagency guidance is unusually direct about it: it is up to each banking organization to identify its critical activities and the third-party relationships that support them, and an activity that is critical at one organization may not be at another. Some organizations assign a criticality or risk level to every relationship; others identify critical activities first and work outward. Both are acceptable. What is not acceptable is a tier that came out of a black box. Scrutineer holds the tiering rule you chose, the evidence behind each classification, and the date it was last reviewed, so the answer to how you decided is a record rather than a recollection.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Assesses suppliers, contractors and sub-processors against one standard, so no part of the third-party population sits outside the program
- Tiers third parties by the criticality rule your organization actually chose, and keeps the rule, the evidence and the review date on the record
- Scores each relationship on real exposure: the data it reaches, the systems it touches, the certifications behind it
- Tracks the contract terms that give you rights, including subcontractor notice, audit access, incident notification and exit provisions
- Continuously monitors posture and certifications, so a lapse surfaces between reviews rather than at the next annual cycle
- Carries termination and offboarding as a tracked stage, with data return or destruction evidence attached to the relationship record
- Produces the documentation and reporting an examiner asks for, out of evidence the program collected anyway
- Runs on the same control library as your SOC 2, ISO 27001 and HIPAA work, so third-party risk is not a separate system of record
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
TPRM life-cycle reference
What each stage of a third-party risk program actually has to produce
Most published life-cycle diagrams stop at naming the stages. The useful version names the artifact that proves the stage happened, because that is what an examiner asks for and the one thing a program cannot assemble after the fact. The two authorities below are the ones US teams are measured against, and they do not describe the same number of stages.
| Life-cycle stage | What the 2023 interagency guidance expects | What the NYDFS October 2025 letter expects | The artifact that proves it happened | Where programs break |
|---|---|---|---|---|
| Planning | A distinct first stage: identify the activity, decide whether it is critical, set risk appetite, and consider whether to outsource at all | Folded into identification and due diligence rather than named separately | A dated record of the criticality decision and who made it, created before a supplier was selected | Skipped. Assessment starts when a signed order form arrives and the outsourcing decision is already made |
| Due diligence and selection | Assess the third party's controls, financial condition, insurance, reliance on subcontractors and geographic footprint, in proportion to risk | The same, plus explicit evaluation of the service provider's own diligence over its providers | The completed assessment, the evidence behind it, and the reason the depth matched the tier | Every vendor gets the same questionnaire regardless of tier, so critical vendors get shallow review and trivial ones get expensive review |
| Contract negotiation | Specific provisions: subcontractor notice and consent, audit rights, incident notification, liability, monitoring costs, termination without unreasonable penalty | Baseline clauses on access control, encryption, event notification, subcontractor requirements, data location and exit obligations | The executed contract, mapped clause by clause to the rights the program relies on | Security reviews the vendor and never reads the contract, so the program assumes rights it does not hold |
| Ongoing monitoring | Monitor performance, control effectiveness, reliance on subcontractors, incidents and changes at the third party throughout the relationship | Continuous oversight proportionate to risk, documented well enough for an examiner to inspect | A dated trail of reassessments, certification renewals, incident notices and posture changes between annual reviews | Annual reassessment only. Everything that changed in month three is discovered in month twelve, if at all |
| Termination and offboarding | Transition the activity, return or destroy data, and retain the ability to terminate without unreasonable penalty | Named as one of the four stages, carrying the same weight as due diligence | Written confirmation of data return or destruction, access revocation records, and the transition plan that was actually executed | The stage with the least tooling in the whole category. Most teams can produce an email thread and nothing else |
| Independent review and reporting | Periodic independent review of the risk management process itself, plus documentation and reporting to the board | Documentation of governance and oversight that examiners may request | Internal audit reports on the program itself, and the board reporting pack showing what was escalated | The program is reviewed by the people who run it, which is not an independent review |
Expectations summarized from the Interagency Guidance on Third-Party Relationships: Risk Management issued June 6, 2023 by the Federal Reserve, FDIC and OCC, and the NYDFS industry letter on managing risks related to third-party service providers dated October 21, 2025. Both are supervisory guidance rather than prescriptive rules, and NYDFS states its letter imposes no new requirements. Apply them against your own regulator and risk profile. Scrutineer organizes readiness evidence and does not issue attestations.
Good questions
Questions about third-party risk
Keep reading
Guides that go deeper on this framework
Best third-party risk management software
The categories of TPRM tooling compared on what each actually produces, and the question that decides which one you need.
Read the guideVendor tiering that holds up in an audit
How to set a criticality rule you can defend, so diligence depth matches exposure instead of contract value.
Read the guideFourth-party risk explained
What sits behind your third parties, why it surfaces late, and where the practical limits of tracing the chain are.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification