Third-party risk,
without the spreadsheet ritual.
Replace annual questionnaires with continuous, evidence-based ratings of every vendor you depend on. Score every supplier and partner from their live public attack surface, and get told when one slips.
Third-Party Risk, step by step
Questionnaires age like milk
A vendor's answers were true the day they typed them. Their score today is anyone's guess.
Continuous observation
Every vendor rated from their live public attack surface, refreshed automatically, evidence attached.
Alerts before incidents
A critical vendor's score drops and you know before their own security team does, and before it becomes your breach.

Every vendor discovered and rated, grouped by risk tier so the ones that need attention stand out
Why vendor questionnaires stopped working
Third-party risk management still runs, at most organisations, on a document. A vendor receives two hundred questions, someone in their sales team fills it in with help from someone in their security team, it comes back six weeks later, and it is filed. The next time anybody looks at it is the following year.
There are three problems with that, and none of them are fixable by writing a better questionnaire. The answers are self-reported, so they describe what the vendor believes about itself. They are a snapshot, so they describe a moment that has already passed. And they are unverifiable, so a confident answer and an accurate answer are indistinguishable to the person reading it.
Meanwhile the thing you are actually worried about, a vendor's security posture degrading between reviews, happens continuously. Certificates lapse. A subdomain gets stood up for a campaign and never taken down. An acquisition brings in infrastructure nobody has inventoried. A CVE lands against something they run. None of that waits for your review cycle, and none of it appears on a questionnaire filed in March.
Continuous external ratings, from evidence rather than assertion
Security ratings invert the model. Instead of asking a vendor what their security looks like, you observe what they publish to the public internet, the same vantage point an attacker has, and score it. Domains, subdomains, exposed services, TLS configuration, mail authentication, cloud posture, breach-exposed credentials, brand impersonation.
The practical consequence is that you can rate a vendor without their participation. No NDA, no questionnaire, no scheduling, no waiting on their security team to have capacity. You supply a domain and a rating comes back. That changes third-party risk management from a process you run on your largest twenty vendors to one you can run on all of them.
It also changes the cadence. A rating that refreshes continuously tells you when something moves, which is the actual question. Nobody genuinely wants to know a vendor's posture in March. They want to know the week it gets worse.
Ratings and questionnaires answer different questions
External ratings observe what is externally observable. That covers a great deal (it is, after all, the same surface an attacker starts from) but it does not cover everything, and any vendor telling you otherwise is selling.
What an outside-in rating cannot see: internal network segmentation, whether backups are tested, how privileged access is governed, what their incident response plan says, whether staff receive security training, how data is handled once it is inside their environment. Those are real controls and they matter, and a questionnaire or an audit report is the right instrument for them.
So the useful model is not replacement: it is triage. Rate everything continuously, and spend your limited questionnaire and audit capacity on the vendors where the rating says something is wrong, or where the data they hold means you need assurance beyond what the outside shows. Most third-party risk programmes are capacity-bound rather than intent-bound; ratings are what let you allocate the capacity you have.
What a vendor risk programme looks like in the first quarter
Start with the vendors whose failure would actually hurt you. Not the longest list: the shortest one where a compromise reaches your data, your customers, or your ability to operate. For most organisations that is between ten and forty companies, and it is rarely the same list as the one procurement maintains.
Rate them, then read the outliers rather than the average. A portfolio-wide score is a board metric; the operational value is in the specific findings: the vendor with expired TLS on a payment subdomain, the one whose SPF record permits the whole internet to send as them, the one with credentials in recent breach data.
Then set the alert threshold and leave it running. The programme becomes valuable at the point where a score drops and somebody is told, without anybody having scheduled a review. That is the difference between third-party risk management as an annual compliance exercise and as a control that actually works.
Questionnaires vs continuous ratings
| Security questionnaire | External security rating | |
|---|---|---|
| Source | Vendor's own description | Observed public evidence |
| Frequency | Annual, at best | Continuous |
| Vendor effort | Weeks of their time | None, no participation needed |
| Time to first answer | 4–8 weeks | Within 24 hours |
| Verifiable | No | Yes, evidence attached to every finding |
| Covers internal controls | Yes | No |
| Scales to 200 vendors | Not realistically | Yes |
The two are complements. Ratings tell you where to spend questionnaire capacity, not how to avoid needing it.
“Our vendor review went from a quarterly spreadsheet ritual to a live dashboard.”
Third-Party Risk | common questions
Do we need the vendor's permission to rate them?
No. Assessment observes only what an organisation publishes to the public internet, the same vantage point any visitor or attacker has. Nothing is exploited and no system is accessed, which is what makes vendor and supply-chain review workable without a questionnaire round.
How long does a first rating take?
Within 24 hours of supplying a domain. There is nothing for the vendor to install and nothing for them to approve.
Does this replace our questionnaires?
No, and we would not claim it does. Ratings cover what is externally observable; questionnaires and audit reports cover internal controls like segmentation, backup testing and access governance. Ratings tell you where to spend your limited questionnaire capacity.
What if a vendor disputes a finding?
Every finding carries the evidence it was derived from, so a dispute is a factual conversation rather than an argument about methodology. If the evidence is wrong or stale, the finding goes.
How many vendors can we monitor?
Pricing scales with the number of monitored companies rather than per seat, so the whole risk team uses it. Most programmes start with ten to forty critical vendors and widen once the alerting proves itself.
What happens when a vendor's score drops?
You are alerted, with the specific findings that moved it. That is the whole point of continuous monitoring. The value is not the score itself but being told the week it changes rather than at the next annual review.
Where this connects
Provider concentration →
Fourth parties and shared-provider concentration risk across the whole portfolio.
Vendor onboarding →
Rate a supplier before the contract is signed, not after.
How scoring works →
The deterministic model behind every rating, and how to refute a finding.
Put your vendors on the board
Start with ten vendors. Expand when the first alert pays for the year.