Third-party management
Learn how to record relationships with suppliers on the platform, including contacts, services, DPAs, subprocessor hierarchies, and third-party risk assessments.
A third party is an external organization that provides a product or service, processes data, or otherwise contributes to the risk of your compliance program.
What to Record
Section titled “What to Record”Keep the seller’s record focused on the relationship, not just the company name:
- business and security contacts;
- the services used by your organization;
- data and operational dependencies;
- DPA, BAA, and compliance-report status;
- parent, child, and subprocessor relationships;
- risk assessments and their expiration dates.
This makes it possible to review the subprocessor’s concentration and risk without placing each provider on a single list.
Assessment lifecycle
Section entitled “Life Cycle Assessment”A review belongs to a third party and records the review carried out for that relationship. the platform can run an asynchronous provider verification to collect supporting information, but the resulting material still requires a human review.
Access and automation
“Access and Automation”Third-party records are available through the web console and automation interfaces. access reviews for identities imported from connected applications; use third-party management for contractual, confidentiality and operational relationships with the provider itself.