Product

Everything a third-party risk program needs

VendorQ covers the full lifecycle: intake, inherent risk, assessment, evidence, scoring, findings, remediation, approval and continuous monitoring.

Vendor inventory & 360 view

A single record per vendor covering services, criticality, owners, contracts, contacts, scores, evidence, findings and full activity history.

Vendor intake & inherent risk

Structured intake questions on data access, PII, PHI, cardholder data, privileged access, AI processing and subprocessors calculate an inherent risk classification that routes the right workflow.

Questionnaire engine

Build questionnaires with weighted, conditional and critical questions, evidence requirements, control mappings and automatic scoring.

Vendor portal

Vendors respond in a secure portal with autosave, evidence upload, comments, delegation and progress tracking, then submit for review.

Certifications & report review

SOC 2, ISO 27001, HITRUST, PCI DSS, FedRAMP and more — with a dedicated SOC 2 review capturing TSC scope, opinion, exceptions, CUECs and subservice organizations.

Findings & remediation

Findings from questionnaires, certification review, monitoring, analysts or AI move through a defined status workflow to closure.

Approvals

Configurable approval chains across business owner, procurement, security, compliance, legal and executive reviewers.

Continuous monitoring

Assessment and certification expirations, contract renewals, score changes, new findings and outstanding remediation, watched continuously.