Masters & Configuration
Configure your third party risk programme once. Every requirement downstream is inherited from the Vendor Type.
Vendor Types
Central configuration object driving all downstream requirements.
Vendor Master
Reusable third party catalog selectable during onboarding.
Contract Types
DPA, MSA, SaaS, NDA, SOW with mandatory clauses & approvals.
Compliance Frameworks
DPDP, GDPR, ISO 27001, SOC 2 and organization frameworks.
Compliance Rules
Framework → Clause → Vendor Type → Rule → Severity.
Contract Rules & Keywords
Required, prohibited and preferred contract language.
Certifications & Compliance
Evidence required per vendor type with expiry tracking.
Risk & Criticality
Risk factors, weights, thresholds and review frequency.
Offboarding Rules
Tasks by vendor type and risk tier, mandatory vs optional.
