Third-party risk management

Managing the risks that come from any outside party an organisation relies on, including vendors, suppliers, partners and service providers.

It is the broader discipline that vendor risk management sits inside, and regulators increasingly expect it: financial entities in the EU must keep a register of their ICT third-party arrangements under DORA, and NIS2 asks the entities it covers to manage supply chain security. Most programs follow the same lifecycle: plan, due diligence, contract, monitor, offboard.

ClauseTrail watches vendors' subprocessor lists, DPAs, privacy policies, terms and AI terms, and tells your team what changed and by when to object.