Third-Party Risk Management

CQ Vendor Risk

Connect Vendor Evidence, Risk, Ownership and Action.

CQ Vendor Risk is a third-party risk management (TPRM) platform for vendor due diligence, cyber risk assessment, remediation, approvals, ongoing oversight, and audit-ready traceability.

CQ Vendor Risk DashboardVendorsAssessmentsFindingsRemediation
Vendor Record
Cloud Services Provider
Third-party cyber risk
ElevatedTreatment active
Accountability
OwnerProcurement
Security reviewCurrent
Evidence reviewComplete
Remediation actionIn progress
Next reviewQ4
What it is

A structured operating environment for third-party cyber risk.

CQ Vendor Risk keeps vendor context, due diligence, evidence, findings, ownership, treatment, approvals, and review history within one governed vendor risk management lifecycle.

Vendor context

Keep the relationship and risk context together.

Maintain business ownership, criticality, services, review status, and relevant vendor history within the same record.

Assessment & evidence

Connect due diligence to supporting evidence.

Structure questionnaires, evidence collection, review activity, findings, and assessment records around the vendor relationship.

Risk treatment

Keep action, approval, and accountability visible.

Record remediation, treatment direction, owners, deadlines, approvals, and current status alongside the underlying risk information.

Why it matters

Third-party cyber risk changes across the vendor relationship.

Vendors may handle company data, access systems, support critical operations, or provide services that require ongoing security oversight.

Effective vendor risk management depends on keeping business context, evidence, findings, ownership, treatment, approvals, and review history connected over time.

Current vendor context
Evidence linked to findings
Visible ownership and remediation
Continuous review history
How it works

One governed third-party risk lifecycle.

Move from vendor context through due diligence, risk treatment, and ongoing oversight in one structured TPRM process.

01 · Vendor context

Establish the relationship

Capture business ownership, services, criticality, data or system access, and the context required for review.

02 · Due diligence & evidence

Assess the vendor

Run structured vendor due diligence, collect supporting evidence, document findings, and retain review records.

03 · Risk treatment & approvals

Assign action

Connect identified third-party risk to remediation, treatment direction, accountable owners, deadlines, and approvals.

04 · Oversight & review

Maintain governance

Track current status, reassessment, open actions, reporting, and the history required for ongoing vendor oversight.

Connected by design: vendor context → due diligence → evidence → findings → treatment → ownership → review.
Product capabilities

Capabilities across the vendor risk management lifecycle.

The product combines the records, workflows, and evidence required for structured third-party cyber risk management.

Vendor governance

Maintain a governed vendor inventory.

Keep business context, ownership, criticality, lifecycle status, review information, and vendor history in one controlled record.

Vendor inventoryOwnershipCriticalityLifecycle statusHistory
Vendor recordActive
CriticalityHigh
OwnerProcurement
ReviewCurrent
Due diligence & evidence

Structure vendor assessments and evidence.

Support due diligence with questionnaires, evidence collection, assessment records, findings, and clear review ownership.

QuestionnairesEvidence collectionAssessment recordsFindingsReview ownership
AssessmentReviewed
QuestionnaireComplete
EvidenceVerified
Findings3 open
Risk, remediation & approvals

Connect findings to treatment and accountable action.

Keep risk records, remediation actions, treatment direction, owners, deadlines, approvals, and status connected to the vendor record.

Risk recordsRemediationTreatmentApprovalsDecision history
RemediationActive
OwnerAssigned
Due date30 days
ApprovalRequired
Oversight, reporting & audit

Maintain current vendor risk oversight.

Support reassessment, monitoring, reporting, and audit preparation while retaining the context behind previous reviews, actions, and approvals.

ReassessmentMonitoringReportingExportsAudit trail
OversightCurrent
Open actions4
Next reviewQ4
Audit trailAvailable
Value by role

One vendor record. Different responsibilities.

The same third-party risk information supports procurement, security, risk leadership, and executive oversight without duplicating the underlying vendor record.

Procurement & Vendor Management

Manage review and obligations.

Keep vendor ownership, review status, required security information, approvals, and follow-up connected to the relationship.

Security Teams

Review evidence and treatment.

Work with vendor assessments, supporting evidence, findings, remediation, and current third-party cyber risk status.

CISO / Risk Leadership

Maintain third-party risk oversight.

Review critical vendors, open findings, treatment status, ownership, reassessment, and risk history from one governed view.

Executive Leadership

See material vendor exposure.

Review critical third parties, current risk status, accountability, treatment direction, and outstanding actions at management level.

Audit readiness

Keep the evidence behind each vendor risk decision.

CQ Vendor Risk retains the vendor context, assessment evidence, findings, ownership, treatment, approvals, and review history associated with third-party risk records for governance review and audit preparation.

EvidenceWhat was reviewed

Keep questionnaires, supporting evidence, assessment records, and findings connected to the vendor record.

OwnershipWho was accountable

Maintain visible responsibility for vendor review, remediation, risk treatment, and follow-up.

Treatment & approvalWhat was authorized

Retain remediation actions, treatment direction, approvals, deadlines, and current status.

HistoryHow the vendor record changed

Preserve review, reassessment, action, and approval history for management and audit review.

Operate with Control.
Govern with Confidence.