Platform
Third-Party Risk

Third-Party Risk

Onboard, assess and monitor third parties end to end

Manage the full third-party lifecycle in one place — onboarding, risk tiering, due diligence, contracting controls, and ongoing monitoring — so the exposure a firm takes on through its vendors, suppliers and partners is understood, proportionate and continuously watched. Third parties are where a firm's risk leaves its own four walls: a supplier's outage becomes your outage, a vendor's breach becomes your breach, a partner's misconduct becomes your regulatory problem. OnyxOne treats every third party as a managed relationship with a risk profile that is assessed at onboarding, sized to its criticality, and kept current for as long as the relationship lasts.

At a glance

How it works, visually

Onboarding & review flowSchematic
Item receivedOnboarding / eventRiskthreshold?Auto-clearLow risk · loggedEscalate to reviewAnalyst investigatesRecord &auditNoYes — parallel review paths

A representative path for onboarding and re-assessing a third party, with escalation where risk warrants it.

The challenge

The problems this module solves

The operational realities that make this hard for compliance and risk teams today.

No one knows how many third parties there are

Vendors are onboarded by whichever team needs them, recorded in scattered spreadsheets and purchasing systems, and never consolidated. Without a single inventory, the firm cannot answer the most basic question — who are our third parties, and what do they touch?

Every third party is assessed the same, or not at all

A cleaning contractor and a core-banking provider get the same cursory check, or the critical one slips through because no one tiered the population by risk. Effort is mis-allocated: trivial vendors are over-assessed while the ones that could take the firm down are under-assessed.

Due diligence is a one-time gate, then silence

A vendor is assessed at onboarding and never looked at again. Their financial health deteriorates, their certifications lapse, they suffer a breach — and the firm finds out only when the consequence lands, because nothing monitored the relationship after go-live.

Contractual controls aren't tracked to the risk

The audit rights, security clauses and exit provisions that should reflect a vendor's criticality are negotiated once and then buried in a contract no one revisits. When they are needed, no one knows whether they exist.

Concentration and fourth-party risk are invisible

The firm depends on one provider across many services, or on a vendor who in turn depends on a single sub-processor, and no one sees the concentration until it fails. Risk that hides in the supply chain never reaches the register.

The approach

How OnyxOne addresses it

One inventory of every third party

All third parties are held in a single register with what they provide, what they access and which part of the business relies on them. The firm can finally answer who its third parties are and what they touch, from one authoritative source.

Risk-based tiering that directs effort

Each third party is tiered by criticality and inherent risk, so due diligence and monitoring are proportionate — deep on the vendors that could hurt the firm, light on the ones that cannot. Effort follows exposure instead of treating everything alike.

Diligence that continues past onboarding

Assessment is not a one-time gate. Third parties are re-assessed on a risk-based cycle and monitored for change — lapsed certifications, adverse media, financial stress — so a relationship that deteriorates is surfaced while there is still time to act.

Contractual controls tied to the risk profile

The audit rights, security requirements, service levels and exit provisions expected for a tier are tracked against each relationship, so the firm knows which controls it holds over which vendor — and can act on them when it needs to.

Concentration and dependency made visible

The register surfaces where the firm depends heavily on a single provider and, where captured, on their critical sub-processors, so concentration and fourth-party risk reach the risk picture instead of hiding in the supply chain.

Capabilities

What's in the module

Turn on what you need and add more as your programme scales.

Third-party register

Hold every third party in one inventory with what they provide, access and support.

Risk tiering

Classify each third party by criticality and inherent risk to make diligence and monitoring proportionate.

Onboarding workflow

Take a new third party through a defined onboarding path with the right diligence for its tier.

Due-diligence assessment

Run structured assessments and evidence collection sized to the third party's risk.

Screening integration

Screen third parties and their principals against sanctions, PEP and adverse-media sources.

Contractual-control tracking

Track audit rights, security clauses, service levels and exit provisions against each relationship.

Ongoing monitoring

Watch for change — certifications, financial health, adverse media — across the live population.

Periodic re-assessment

Re-assess third parties on a risk-based cycle so their profile stays current.

Concentration & dependency view

Surface heavy reliance on single providers and, where captured, their critical sub-processors.

Immutable relationship trail

Every assessment, decision, control and review is written to an append-only record.

Dashboards

The views your team works from

Purpose-built dashboards and views, each answering a question a specific role needs to act on.

An executive viewIllustrative
ILLUSTRATIVE EXAMPLEOPEN CASES128SLA ADHERENCE96%SCREENING ALERTS1.2kOVERDUE REVIEWS14Cases by categoryAMLKYCFraudSanctionsConductOtherRisk mixby tierHighMediumLow

A representative layout of the KPI tiles and charts these dashboards present. Figures shown are illustrative examples, not real data.

Third-party portfolio

The full population by tier, status and criticality, with diligence and monitoring state against each relationship.

Due-diligence tracker

Onboarding and re-assessment progress by tier, highlighting overdue or incomplete diligence.

Monitoring alerts

Change events across the population — lapsed certifications, adverse media, financial stress — prioritised by criticality.

Concentration view

Where the firm depends heavily on single providers and their critical sub-processors, surfacing supply-chain concentration.

Control coverage

Contractual controls held across the population — audit rights, exit provisions — and where expected controls are missing.

Automation

What the platform automates

Rules, workflows, alerts and scheduling that run the routine so your team works the exceptions.

Tier-based diligence routing

A new third party is routed to the diligence path its assessed tier requires, without manual sorting.

Continuous screening

Third parties and their principals are re-screened automatically when configured lists and sources update.

Certification-expiry alerts

Expiring or lapsed certifications and evidence are flagged automatically before they become gaps.

Re-assessment scheduling

Periodic re-assessments are scheduled automatically on each relationship's risk-based cycle.

Adverse-change escalation

Material monitoring events — adverse media, financial deterioration, screening hits — escalate automatically for review.

AI assistance

Where AI helps the analyst

Assistive, decision-support features that speed up the work on the record. Suggestions are always reviewable, and a person stays in control of every decision.

Assessment summarisation

Summarises a third party's diligence responses and evidence so the assessor can review it quickly, then verify before deciding.

Risk-signal detection

Flags concerning signals in monitoring feeds and adverse media for the analyst to evaluate, never auto-actioning them.

Questionnaire assistance

Suggests the diligence questions appropriate to a third party's tier and category, which the team reviews and applies.

The workflow

The enterprise workflow

A defined, end-to-end process with clear ownership at every stage.

The workflow, step by stepSchematic
01Register & tierA third party is added to the inventory with what it provides and accesses, andtiered by criticality and inherent risk.02Onboard & assessThe relationship goes through onboarding with due diligence, evidence and screeningproportionate to its tier.03Decide & contractA risk-based decision is recorded, and the contractual controls expected for thetier are tracked against the relationship.04MonitorThe live relationship is monitored for change — lapsed certifications, adversemedia, financial stress, screening hits.05Re-assessThe third party is re-assessed on a risk-based cycle, and any change in profileupdates its tier and controls.06OffboardWhen the relationship ends, exit provisions are actioned and the full history ispreserved for audit and examination.

Every result, decision and override is captured against the record it belongs to.

01

Register & tier

A third party is added to the inventory with what it provides and accesses, and tiered by criticality and inherent risk.

02

Onboard & assess

The relationship goes through onboarding with due diligence, evidence and screening proportionate to its tier.

03

Decide & contract

A risk-based decision is recorded, and the contractual controls expected for the tier are tracked against the relationship.

04

Monitor

The live relationship is monitored for change — lapsed certifications, adverse media, financial stress, screening hits.

05

Re-assess

The third party is re-assessed on a risk-based cycle, and any change in profile updates its tier and controls.

06

Offboard

When the relationship ends, exit provisions are actioned and the full history is preserved for audit and examination.

The value

What your team gains

One register

Know your third parties

A single inventory of who your third parties are and what they touch replaces scattered spreadsheets and unanswerable questions.

Proportionate

Effort follows exposure

Risk-based tiering puts deep diligence on the vendors that could hurt the firm and light touch on the ones that cannot.

Continuous

Deterioration caught in time

Monitoring and re-assessment surface a vendor whose certifications lapse or health declines, rather than discovering it at the point of failure.

Controlled

You know what controls you hold

Contractual controls tracked to the risk profile mean audit rights and exit provisions are known and actionable, not buried.

Concentration made visible

Heavy reliance on a single provider, and their critical sub-processors, reach the risk picture instead of hiding in the supply chain.

Defensible third-party governance

Because tiering, diligence, controls and monitoring are all on the record, showing your third-party programme is sound is retrieval.

Built for

Industries it serves

BankingFinancial ServicesFintechInsuranceInvestment FirmsHealthcareTechnologyCorporate & Trust Service ProvidersRegulated Enterprises
Integrations

Works with your existing systems

Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.

Procurement & vendor systems
  • Draws the third-party population from your existing procurement and vendor-management systems into one register
Screening & data sources
  • Screens third parties and their principals against the sanctions, PEP and adverse-media sources configured for your deployment
Risk & controls
  • Feeds third-party risk into your enterprise-risk register and links controls to the internal-controls framework
Contract & document stores
  • Connects to your existing contract and document repositories to track contractual controls and evidence
Collaboration & notification
  • Routes assessments, approvals and monitoring alerts through your existing email and messaging channels
Assurance

Security, compliance & reporting

Security & data handling

  • Third-party records, assessments and evidence are encrypted in transit and at rest.
  • Role-based access controls who can onboard, assess, approve and monitor third parties.
  • Segregation of duties can separate the assessor of a third party from the approver, where policy requires it.
  • Sensitive diligence findings are restricted to authorised roles under need-to-know.
  • Every assessment, decision, control and review is written to an append-only audit trail.
  • Data residency and retention for third-party records are configurable to your regulatory obligations.

Compliance support

  • Supports third-party and outsourcing risk-management expectations under operational-resilience regimes
  • Underpins vendor due-diligence and ongoing-monitoring obligations
  • Supports sanctions and financial-crime screening of third parties and their principals
  • Assists concentration- and fourth-party-risk assessment expectations
  • Provides documented, timestamped evidence of third-party governance for audit and examination

Reports & exports

  • Third-party inventory with tier, status and criticality
  • Due-diligence completion and outcome reports by tier
  • Monitoring and change-event reports across the population
  • Contractual-control coverage reports
  • Concentration and dependency reports
  • Third-party risk management information for risk committees and the board
Best practice

How to get the most from it

Build the inventory first

You cannot manage third-party risk you cannot see. Consolidate every third party into one register before refining assessment — the inventory is the foundation everything else stands on.

Tier before you assess

Classify by criticality first, then apply diligence proportionate to the tier. Assessing every vendor identically wastes effort on the trivial and starves the critical.

Treat monitoring as the main event

Onboarding diligence is a snapshot; the risk accrues over the life of the relationship. Invest in ongoing monitoring and re-assessment, not just the onboarding gate.

Track the controls you negotiated

Record the audit rights, security clauses and exit provisions against the relationship. A contractual control no one can find is a control you effectively do not have.

FAQ

Questions, answered

How does risk tiering work?

Each third party is classified by criticality and inherent risk — what it provides, what it accesses, how much the business depends on it — and that tier drives how deep the due diligence is and how closely the relationship is monitored. Effort follows exposure rather than treating every vendor the same.

What does ongoing monitoring actually watch for?

Changes that matter over the life of the relationship: lapsed or expiring certifications, adverse media, financial deterioration, new screening hits, and approaching re-assessment dates. The point is to surface a relationship that has degraded while there is still time to act.

Can it show us where we're over-concentrated?

Yes. The register surfaces where the firm relies heavily on a single provider across services and, where you capture it, on their critical sub-processors — so concentration and fourth-party risk reach your risk picture rather than hiding in the supply chain.

How does this relate to Vendor Due Diligence?

Third-Party Risk is the lifecycle and portfolio view — inventory, tiering, monitoring, concentration. Vendor Due Diligence is the deep assessment that runs within it for a given vendor. They work together: tiering decides how much diligence a vendor gets, and the diligence result feeds the relationship's risk profile.

Is OnyxOne approving our vendors?

No. The platform structures onboarding, sizes the diligence, tracks controls and monitors change, but a person makes the risk-based decision to onboard, retain or exit a third party and owns it. OnyxOne is decision-support software, not the approver.

See Third-Party Risk in your programme

Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.