Two portals, a ~3,800-control multi-framework brain, and an AI copilot that does the toil. Risk you can defend in an audit.
Chasing vendors, reconciling spreadsheet answers, reading 90-page SOC 2 reports to check one control, drafting "you didn't answer question 14" emails.
Deciding whether a residual risk is acceptable, escalating, owning the regulator conversation. This is where your senior people should actually spend their time.
For the risk / vendor-management team. Portfolio dashboard across every vendor, rate inherent criticality (1–4), tailor and send questionnaires, review answers, set residual risk, complete.
For the third party being assessed. Receive a questionnaire tailored to them, answer controls with response + maturity + evidence, upload compliance reports, review AI-prefilled answers, then submit.
Runs in demo mode with zero config, pick a profile and explore both sides instantly. The seeded database is a real, inspectable file.
| Maturity band | Strong ≥80% | Moderate 60–80% | Limited 40–60% | Weak <40% | Unassessed |
|---|---|---|---|---|---|
| Tier shift | −2 tier | −1 tier | 0 tier | +1 tier | 0 tier |
A Critical vendor with weak controls stays Critical. A Low-impact vendor with weak controls tops out at Medium. No silent overrides.
Every scope ships with a "why these controls?" audit rationale.
Every action is a real DB operation, scoped and logged. The copilot drives the product, it isn't a chatbot bolted on the side.
Expired or soon-to-expire certs flagged before they reach a human.
Does that SOC 2 actually cover the right criteria, systems, and locations?
Claimed controls that don't match the documented evidence.
Copy-pasted responses that don't match the supporting evidence.
Where evidence is thin, an AI follow-up loop auto-drafts targeted queries. The questionnaire grows where there's risk, shrinks where a report already answers it.
Classify criticality, assign a risk tier.
Tailored from the bank by tier + service.
Vendor portal with an embedded AI assistant.
AI reads evidence, cross-checks answers.
Auto-drafts queries where evidence is thin.
Scored with full rationale, weighted by criticality.
One-click reports; every AI decision logged.
Re-assessment fires on expiry, breach, drift.
Commitments and SLAs tracked to closure.
Stage 8 feeds back into Stage 1, TPRM stops being an annual event and becomes a living, always-on programme.
Reviewer and AI step through controls together, in real time.
Each answer checked against uploaded evidence on the spot.
Thin or contradictory? The AI drafts the query mid-session.
| Regulation | How it's handled |
|---|---|
| RBI · Outsourcing of IT Services (2023) | Periodic re-assessment, continuous monitoring, fourth-party visibility, exit clauses |
| SEBI · MAS | Materiality-based tiering and ongoing oversight aligned to multiple regulators |
| DPDP Act 2023 · CERT-In | Data-processor control mapping; incident-reporting clauses tracked per vendor |
| ISO 27001 · SOC 2 · PCI DSS · HIPAA · GDPR | Native control libraries with automated evidence validation |
| Vendor band | TPRM | + AI | + Live Review |
|---|---|---|---|
| 1–10 (pilot) | $800 | $900 | $1,200 |
| 11–25 | $520 | $580 | $760 |
| 26–50 | $360 | $400 | $520 |
| 51–100 | $280 | $310 | $400 |
| 101–250 | $210 | $235 | $300 |
| 251–500 | $170 | $190 | $240 |
All figures are $ per vendor / year, for vendors in that band only. How to read it: 50 vendors on TPRM = first 10 × $800 + next 15 × $520 + next 25 × $360 = $24,800/year. Vendor portal access is unlimited and free, only your own usage is billed.
See AI-Powered TPRM run against your own vendor list. We'll follow up within one business day.
Your information stays confidential and is never shared with third parties.