Product
Everything a third-party risk program needs
VendorQ covers the full lifecycle: intake, inherent risk, assessment, evidence, scoring, findings, remediation, approval and continuous monitoring.
Vendor inventory & 360 view
A single record per vendor covering services, criticality, owners, contracts, contacts, scores, evidence, findings and full activity history.
Vendor intake & inherent risk
Structured intake questions on data access, PII, PHI, cardholder data, privileged access, AI processing and subprocessors calculate an inherent risk classification that routes the right workflow.
Questionnaire engine
Build questionnaires with weighted, conditional and critical questions, evidence requirements, control mappings and automatic scoring.
Vendor portal
Vendors respond in a secure portal with autosave, evidence upload, comments, delegation and progress tracking, then submit for review.
Certifications & report review
SOC 2, ISO 27001, HITRUST, PCI DSS, FedRAMP and more — with a dedicated SOC 2 review capturing TSC scope, opinion, exceptions, CUECs and subservice organizations.
Findings & remediation
Findings from questionnaires, certification review, monitoring, analysts or AI move through a defined status workflow to closure.
Approvals
Configurable approval chains across business owner, procurement, security, compliance, legal and executive reviewers.
Continuous monitoring
Assessment and certification expirations, contract renewals, score changes, new findings and outstanding remediation, watched continuously.