Scrutineer.ai

Scrutineer · Vendor risk

Third party risk management software, end to end

A TPRM program is only as good as the system running it. Do it in email and spreadsheets and intake stalls, assessments are inconsistent, and monitoring quietly stops happening. Third party risk management software should operate the whole lifecycle in one place. Scrutineer handles intake, assessment, scoring, approval and continuous monitoring for every third party.

A new third party enters through a structured intake, gets assessed and scored, routes to the right approver, and then stays under continuous monitoring with renewals tracked automatically. Leadership sees portfolio risk; owners see their queue; auditors see a clean trail. Scrutineer gives your TPRM program one operating system, while your team keeps ownership of every risk decision.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Interactive walkthrough on a sample company, not a scan of your systems.

Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with TPRM software

Whole lifecycle in one place

Intake, assessment, scoring, approval and monitoring run on one platform, so third-party risk stops leaking through the gaps between email and spreadsheets.

Structured intake

Every new third party enters the same way, so nothing skips assessment and your program starts with consistent, comparable data.

Audit-ready trail

Every assessment, score, approval and monitoring event is recorded, so you can show leadership and auditors that the program actually operates.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Runs structured third-party intake
  • Standardizes assessment and scoring
  • Routes approvals to the right owners
  • Monitors third parties continuously after approval
  • Tracks renewals and reassessment automatically
  • Maintains an audit-ready trail of the whole program
TPRM software readiness_report
Readiness 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Every finding links to the evidence behind it

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Third-party obligation reference

Which third-party rules actually bind you today, and which are still only proposed

Most TPRM comparisons grid vendors against features. That is not what decides the size of your program. What decides it is which regulator is looking at your third parties, what that regulator actually demands, and whether the requirement you are budgeting for is in force or still a proposal. One row below is being widely reported as a 2026 deadline and is not one.

The rule Who it binds What it demands about your third parties Status as of August 2026
Interagency Guidance on Third-Party Relationships Banks, savings associations and their holding companies, supervised by the OCC, the Federal Reserve and the FDIC Risk management across the whole relationship life cycle: planning, due diligence and selection, contract negotiation, ongoing monitoring and termination, scaled to the risk of the relationship In force since June 6, 2023. It replaced each agency's prior guidance, including the 2013 OCC bulletin most bank programs were originally built on. There is no separate lighter standard for community banks, only illustrative examples.
NYDFS Part 500, section 500.11 Entities licensed by the New York Department of Financial Services A written third-party service provider policy covering due diligence, access controls, encryption in transit and at rest, and notification when an incident touches your data In force. The Second Amendment was adopted November 1, 2023 and its phased requirements finished landing on November 1, 2025.
GLBA Safeguards Rule, service provider oversight Non-bank financial institutions under FTC jurisdiction, a much broader set than most firms assume it covers Select service providers capable of safeguarding customer information, require those safeguards by contract, and periodically assess whether they are still being delivered In force. This is the obligation most often discovered late, because firms that never thought of themselves as financial institutions are inside the definition.
HIPAA Security Rule as it stands today Covered entities and their business associates A signed business associate agreement, and a security risk analysis covering the electronic protected health information a business associate handles In force, and unchanged on this point. There is no current requirement to independently verify that a business associate's controls exist.
The HIPAA Security Rule proposal published January 6, 2025 The same entities, if it is ever finalized in its proposed form Annual written verification, prepared by a subject matter expert, that a business associate actually has the required safeguards in place. A signed agreement would stop being sufficient on its own. Still PROPOSED. HHS moved it, RIN 0945-AA22, onto its Long-Term Actions agenda with July 2027 named as the anticipated date for final action. Despite a large number of articles announcing 2026 HIPAA deadlines, there is no compliance date to prepare for yet.
FedRAMP, GovRAMP, TX-RAMP and CMMC supply chain terms Cloud and defense suppliers selling to US federal, state and defense buyers Flow-down. The controls you commit to have to hold across your own subcontractors and interconnected services, because they sit inside your authorization boundary In force and tightening. GovRAMP will only grant Provisionally Authorized status when an interconnected technology that is not itself authorized holds a current Security Snapshot.

Regulatory status changes and proposed rules move. Dates here reflect what the agencies published as of August 2026 and should be confirmed against the current rule text before you plan a program around them. Scrutineer prepares evidence and does not provide legal advice.

Good questions

Questions about TPRM software

Third party risk management software runs the full life cycle of every external relationship your organization depends on: intake, tiering, due diligence, scoring, approval, ongoing monitoring, reassessment and offboarding. It differs from a questionnaire tool in that the questionnaire is one step inside it. The point of the software is that a third party stays under management after onboarding, which is where most spreadsheet programs quietly stop.
Vendor risk management covers suppliers you pay. Third party risk management is wider and covers every external relationship that can hurt you, including ones you do not pay: resellers, agents, joint ventures, affiliates, open source dependencies and cloud services procured on a credit card. In practice most teams use the terms interchangeably, and the distinction only matters when a regulator asks whether your inventory covers relationships that never generated an invoice.
For US organizations the main ones are the Interagency Guidance on Third-Party Relationships for banks, in force since June 6, 2023; NYDFS Part 500 section 500.11 for New York licensed financial entities; the GLBA Safeguards Rule service provider provisions for FTC-regulated financial institutions; the HIPAA Security Rule for covered entities and business associates; and the flow-down terms in FedRAMP, GovRAMP, TX-RAMP and CMMC for government suppliers.
A complete inventory of third parties, a tiering rule that decides how much diligence each one earns, standard due diligence for each tier, a scoring and approval step with a named owner, continuous monitoring after approval, a reassessment cadence tied to tier, contract terms covering security and incident notification, and an offboarding step that revokes access. The step teams skip most often is offboarding, and it is the one that leaves live credentials behind.
Intake, tiering, due diligence, risk scoring, approval, contracting, monitoring, reassessment and offboarding. The order matters more than the tooling: tiering before diligence is what keeps a program affordable, because it stops a low-risk vendor consuming the same effort as one holding your customer data. Programs that assess everything at the same depth run out of budget before they run out of vendors.
No, for two reasons. A SOC 2 report covers only the systems and criteria named in its scope section, and it describes a historical window that closed before you received it. It is strong evidence within its scope and silent outside it. Read the scope, the exceptions and the complementary user entity controls, which list the things the auditor assumed you would do, before treating the report as an approval.
Published pricing in this category is thin because most platforms quote on request. The variables that drive a quote are the number of third parties under management, how many require deep assessment rather than a light review, the number of internal users and approval workflows, and whether continuous monitoring feeds are bundled or billed per vendor. Ask for pricing scoped to your actual tier distribution rather than to your total vendor count.
Fourth party risk is the risk carried by your vendors' vendors. It matters because concentration hides there: several of your suppliers commonly depend on the same cloud region, identity provider or payment processor, so a single outage or breach reaches you through multiple independent-looking relationships. You usually cannot assess a fourth party directly, so the practical control is a contract term requiring your vendor to disclose material subprocessors and notify you of changes.
No. Scrutineer is software, not an assessment firm, an auditor or a risk advisor. It runs the program: it holds the inventory, applies your tiering rules, collects and stores the evidence, tracks scores and renewals, and produces the trail an examiner asks for. Your team makes every risk decision and every approval, and an accredited auditor still issues any attestation.
A questionnaire tool sends and collects forms. Scrutineer operates the whole TPRM lifecycle: intake, assessment, scoring, approval and continuous monitoring, so a third party stays under management long after the questionnaire comes back, not just at onboarding.
Yes. Assessments route to the right approvers based on tier and risk, with owners and due dates tracked. The full trail of who assessed, scored and approved each third party is recorded for audit.

Keep reading

Guides that go deeper on third-party risk

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification