Vendor risk management

Identifying, assessing and monitoring the risks that suppliers bring to an organisation, from onboarding to offboarding.

It covers security, privacy, compliance, financial and operational risk. A typical program tiers vendors by the data and access they have, assesses them before signing (questionnaires, certifications, contract terms) and monitors them afterwards: incidents, certification renewals, and changes to their terms and subprocessors.

Monitoring is where most programs are thinnest, because vendors change their documents without asking.

ClauseTrail watches vendors' subprocessor lists, DPAs, privacy policies, terms and AI terms, and tells your team what changed and by when to object.