Third-Party & Vendor Risk Management
Onboard, assess and monitor the third parties you depend on
The risks a firm carries increasingly sit outside its own walls — in the vendors, suppliers, intermediaries and partners it relies on. This programme composes vendor onboarding, due diligence, risk assessment and ongoing monitoring into one third-party lifecycle, so every relationship is assessed before it starts, monitored while it runs, and offboarded cleanly when it ends.
One programme, on one platform
Your compliance, risk and legal teams run the programme in OnyxOne, which composes the relevant modules onto one record and connects to the systems and data sources your deployment requires.
What this programme is, and why it matters
A solution is a programme, not a single tool — the outcome a set of platform capabilities add up to when they run on one record.
How the programme scores and prioritises risk so attention lands where exposure is greatest. Values are illustrative.
A lifecycle, not a spreadsheet
Third-party risk is a lifecycle — intake, diligence, assessment, approval, monitoring and offboarding. Running it as one programme replaces the scattered spreadsheets and questionnaires most firms use with a single record per vendor that stays current.
Risk-tiered diligence
A cleaning contractor and a core-system provider do not warrant the same scrutiny. The programme tiers vendors by inherent risk and criticality, so diligence and monitoring are proportionate and effort lands where the exposure is.
Diligence you can evidence
Vendor due diligence — screening, ownership, financial standing, security posture and the controls a vendor operates — is captured as structured, evidenced records, so the firm can show it understood a third party before relying on it.
Monitoring after signature
Risk does not stop at onboarding. The programme keeps watching — re-screening, reassessment on a defined cadence, and capturing issues and incidents against the vendor record — so a relationship that drifts into higher risk is caught.
What makes this hard today
The operational realities this programme is designed to resolve.
Vendors tracked in spreadsheets
Third-party inventories held in disconnected spreadsheets go stale, miss relationships and cannot show when a vendor was last assessed.
One-size diligence
Applying the same questionnaire to every vendor wastes effort on low-risk suppliers and under-scrutinises the critical ones.
Assess once, forget
Diligence done at onboarding and never revisited means the firm's view of a vendor's risk drifts out of date while the dependency continues.
No line of sight to concentration
Without one record, a firm cannot see where it is over-reliant on a single provider or where the same fourth parties sit behind many vendors.
Offboarding that leaves loose ends
Ending a relationship without a defined offboarding process leaves access, data and obligations unresolved.
The operating model, at a glance
How the composed programme runs — from the data it takes in to the decisions and evidence it produces.
Work is triaged, escalated when it matters, and recorded either way — every path lands on the audit trail.
Build the inventory
Capture every third party in one register, with owner, criticality and the services each provides.
Tier by risk
Assess inherent risk and criticality so diligence and monitoring are proportionate to the exposure each vendor represents.
Diligence & approve
Run risk-tiered due diligence — screening, ownership, standing and controls — and route to approval with conditions recorded.
Monitor the relationship
Re-screen, reassess on cadence and capture issues and incidents against the vendor record throughout the relationship.
Offboard cleanly
End relationships through a defined offboarding process so access, data and obligations are resolved and recorded.
The modules this solution composes
A solution is a curated set of platform modules working as one programme. Turn on what the programme needs and add more as it scales.
What the programme gives you
The concrete capabilities the composed programme provides, end to end.
Third-party register
One inventory of every vendor, supplier and partner, with owner, criticality and services captured against each record.
Risk tiering
Assess inherent risk and criticality so diligence and monitoring effort is proportionate to each relationship.
Vendor due diligence
Structured diligence — screening, ownership, financial standing, security posture and control attestations — captured as evidenced records.
Assessment questionnaires
Issue and track risk and control questionnaires, with responses and evidence held against the vendor record.
Ongoing monitoring & reassessment
Re-screen and reassess vendors on a defined cadence, and capture issues and incidents against the relationship as they arise.
Approval & offboarding
Route onboarding and material changes to approval, and offboard relationships through a defined, recorded process.
The end-to-end workflow
A defined process with clear ownership at every stage, captured against the record it belongs to.
Every result, decision and override is captured against the record it belongs to.
Intake
A new third party is registered with its owner, the services it provides and initial criticality.
Tier & scope
Inherent risk and criticality are assessed to set the diligence and monitoring the relationship requires.
Diligence
Screening, ownership, standing and control assessments are completed and evidenced against the record.
Approve
The relationship routes to approval, with conditions and residual risk recorded.
Monitor & reassess
The vendor is re-screened, reassessed on cadence, and issues and incidents are logged as they occur.
Offboard
When the relationship ends, a defined offboarding process resolves access, data and obligations, all recorded.
Industries this programme serves
The sectors this programme is most often deployed in. The same programme, framed around each sector's obligations.
Works with your existing systems
Described as capabilities — OnyxOne connects to the systems the programme requires, configured per implementation.
- Screens vendors and their owners against the sanctions, PEP and adverse-media providers configured for your deployment
- Connects to corporate-registry and ownership data services to establish who stands behind a vendor
- Ingests vendor and contract data from your existing procurement or ERP systems to keep the register current
- Holds questionnaire responses and supporting documents against the vendor record
- Routes assessments, approvals and reassessment reminders through your existing email and messaging tools
Security & reporting
Security & data handling
- Vendor records, assessments and evidence are encrypted in transit and at rest.
- Access to third-party risk information is role-based and restricted to authorised staff.
- Every assessment, screening result, approval and offboarding action is written to an append-only audit trail.
- Segregation of duties can separate those who assess a vendor from those who approve the relationship.
- Data residency and retention are configurable to your obligations.
Reports & returns
- Third-party inventory and criticality reports
- Vendor risk-tier distribution and residual-risk reporting
- Due-diligence and reassessment coverage and overdue reports
- Vendor issue, incident and remediation reporting
- Concentration and dependency reporting for management
What your team gains
One current view of third parties
A single register replaces scattered spreadsheets, so the firm always knows who its vendors are and when each was last assessed.
Proportionate effort
Risk tiering concentrates diligence and monitoring on critical and higher-risk vendors rather than spreading it evenly.
Evidenced understanding
Structured, evidenced diligence lets the firm show it understood a third party before relying on it.
Risk caught over the relationship
Ongoing monitoring and reassessment surface a vendor drifting into higher risk while the dependency is still live.
Questions, answered
How does it decide how much diligence a vendor needs?
Vendors are tiered by inherent risk and criticality against your methodology, so a critical core-system provider gets deeper diligence and closer monitoring than a low-risk supplier — and the tiering is recorded.
Does it keep vendor risk current after onboarding?
Yes. Vendors are re-screened and reassessed on a defined cadence, and issues and incidents are captured against the record, so a relationship drifting into higher risk is caught while it is still live.
Can it show where we are over-reliant on a provider?
Because every vendor sits on one register with criticality and services recorded, the programme supports concentration and dependency reporting for management.
Does OnyxOne assess our vendors for us?
No. OnyxOne provides the programme and orchestrates the checks against the data sources you contract; the assessment decisions and the responsibility for them remain with your firm.
Are SOC 2 or ISO 27001 held?
Not yet. Both are on our roadmap; we will publish attestations in the Trust Center once they are held rather than claim them beforehand.
Stand up your Third-Party & Vendor Risk Management programme
Book a walkthrough and we'll show how the composed programme fits your obligations, workflows and systems — then scope an implementation.