Solutions
Risk Management

Third-Party & Vendor Risk Management

Onboard, assess and monitor the third parties you depend on

The risks a firm carries increasingly sit outside its own walls — in the vendors, suppliers, intermediaries and partners it relies on. This programme composes vendor onboarding, due diligence, risk assessment and ongoing monitoring into one third-party lifecycle, so every relationship is assessed before it starts, monitored while it runs, and offboarded cleanly when it ends.

At a glance

One programme, on one platform

Third-Party & Vendor Risk Management on OnyxOneSchematic
Your teamsCompliance · risk · legalAnalysts & investigatorsScreen, review and decideOversight & approvalsSign-off and reportingOnyxOneCompliance & risk OSScreening · Due diligenceCases · Risk · MonitoringPolicy · Reporting · AuditSystems & sourcesConfigured per deploymentScreening data providersSanctions · PEP · mediaYour systems of recordOnboarding · core systemsOne platform for the whole programme — not a stack of disconnected tools and spreadsheets.

Your compliance, risk and legal teams run the programme in OnyxOne, which composes the relevant modules onto one record and connects to the systems and data sources your deployment requires.

The programme

What this programme is, and why it matters

A solution is a programme, not a single tool — the outcome a set of platform capabilities add up to when they run on one record.

Assessing likelihood against impactSchematic
51015202548121620369121524681012345Likelihood54321Impact12345LowModerateElevatedHighCritical

How the programme scores and prioritises risk so attention lands where exposure is greatest. Values are illustrative.

A lifecycle, not a spreadsheet

Third-party risk is a lifecycle — intake, diligence, assessment, approval, monitoring and offboarding. Running it as one programme replaces the scattered spreadsheets and questionnaires most firms use with a single record per vendor that stays current.

Risk-tiered diligence

A cleaning contractor and a core-system provider do not warrant the same scrutiny. The programme tiers vendors by inherent risk and criticality, so diligence and monitoring are proportionate and effort lands where the exposure is.

Diligence you can evidence

Vendor due diligence — screening, ownership, financial standing, security posture and the controls a vendor operates — is captured as structured, evidenced records, so the firm can show it understood a third party before relying on it.

Monitoring after signature

Risk does not stop at onboarding. The programme keeps watching — re-screening, reassessment on a defined cadence, and capturing issues and incidents against the vendor record — so a relationship that drifts into higher risk is caught.

The challenge

What makes this hard today

The operational realities this programme is designed to resolve.

Vendors tracked in spreadsheets

Third-party inventories held in disconnected spreadsheets go stale, miss relationships and cannot show when a vendor was last assessed.

One-size diligence

Applying the same questionnaire to every vendor wastes effort on low-risk suppliers and under-scrutinises the critical ones.

Assess once, forget

Diligence done at onboarding and never revisited means the firm's view of a vendor's risk drifts out of date while the dependency continues.

No line of sight to concentration

Without one record, a firm cannot see where it is over-reliant on a single provider or where the same fourth parties sit behind many vendors.

Offboarding that leaves loose ends

Ending a relationship without a defined offboarding process leaves access, data and obligations unresolved.

How it works

The operating model, at a glance

How the composed programme runs — from the data it takes in to the decisions and evidence it produces.

A representative flowSchematic
Item receivedOnboarding / eventRiskthreshold?Auto-clearLow risk · loggedEscalate to reviewAnalyst investigatesRecord &auditNoYes — parallel review paths

Work is triaged, escalated when it matters, and recorded either way — every path lands on the audit trail.

01

Build the inventory

Capture every third party in one register, with owner, criticality and the services each provides.

02

Tier by risk

Assess inherent risk and criticality so diligence and monitoring are proportionate to the exposure each vendor represents.

03

Diligence & approve

Run risk-tiered due diligence — screening, ownership, standing and controls — and route to approval with conditions recorded.

04

Monitor the relationship

Re-screen, reassess on cadence and capture issues and incidents against the vendor record throughout the relationship.

05

Offboard cleanly

End relationships through a defined offboarding process so access, data and obligations are resolved and recorded.

Capabilities

What the programme gives you

The concrete capabilities the composed programme provides, end to end.

Third-party register

One inventory of every vendor, supplier and partner, with owner, criticality and services captured against each record.

Risk tiering

Assess inherent risk and criticality so diligence and monitoring effort is proportionate to each relationship.

Vendor due diligence

Structured diligence — screening, ownership, financial standing, security posture and control attestations — captured as evidenced records.

Assessment questionnaires

Issue and track risk and control questionnaires, with responses and evidence held against the vendor record.

Ongoing monitoring & reassessment

Re-screen and reassess vendors on a defined cadence, and capture issues and incidents against the relationship as they arise.

Approval & offboarding

Route onboarding and material changes to approval, and offboard relationships through a defined, recorded process.

The workflow

The end-to-end workflow

A defined process with clear ownership at every stage, captured against the record it belongs to.

The workflow, step by stepSchematic
01IntakeA new third party is registered with its owner, the services it provides and initialcriticality.02Tier & scopeInherent risk and criticality are assessed to set the diligence and monitoring therelationship requires.03DiligenceScreening, ownership, standing and control assessments are completed and evidencedagainst the record.04ApproveThe relationship routes to approval, with conditions and residual risk recorded.05Monitor & reassessThe vendor is re-screened, reassessed on cadence, and issues and incidents arelogged as they occur.06OffboardWhen the relationship ends, a defined offboarding process resolves access, data andobligations, all recorded.

Every result, decision and override is captured against the record it belongs to.

01

Intake

A new third party is registered with its owner, the services it provides and initial criticality.

02

Tier & scope

Inherent risk and criticality are assessed to set the diligence and monitoring the relationship requires.

03

Diligence

Screening, ownership, standing and control assessments are completed and evidenced against the record.

04

Approve

The relationship routes to approval, with conditions and residual risk recorded.

05

Monitor & reassess

The vendor is re-screened, reassessed on cadence, and issues and incidents are logged as they occur.

06

Offboard

When the relationship ends, a defined offboarding process resolves access, data and obligations, all recorded.

Integrations

Works with your existing systems

Described as capabilities — OnyxOne connects to the systems the programme requires, configured per implementation.

Screening & data sources
  • Screens vendors and their owners against the sanctions, PEP and adverse-media providers configured for your deployment
Corporate registries & ownership
  • Connects to corporate-registry and ownership data services to establish who stands behind a vendor
Procurement & vendor systems
  • Ingests vendor and contract data from your existing procurement or ERP systems to keep the register current
Assessment evidence
  • Holds questionnaire responses and supporting documents against the vendor record
Collaboration & notification
  • Routes assessments, approvals and reassessment reminders through your existing email and messaging tools
Assurance

Security & reporting

Security & data handling

  • Vendor records, assessments and evidence are encrypted in transit and at rest.
  • Access to third-party risk information is role-based and restricted to authorised staff.
  • Every assessment, screening result, approval and offboarding action is written to an append-only audit trail.
  • Segregation of duties can separate those who assess a vendor from those who approve the relationship.
  • Data residency and retention are configurable to your obligations.

Reports & returns

  • Third-party inventory and criticality reports
  • Vendor risk-tier distribution and residual-risk reporting
  • Due-diligence and reassessment coverage and overdue reports
  • Vendor issue, incident and remediation reporting
  • Concentration and dependency reporting for management
The value

What your team gains

One current view of third parties

A single register replaces scattered spreadsheets, so the firm always knows who its vendors are and when each was last assessed.

Proportionate effort

Risk tiering concentrates diligence and monitoring on critical and higher-risk vendors rather than spreading it evenly.

Evidenced understanding

Structured, evidenced diligence lets the firm show it understood a third party before relying on it.

Risk caught over the relationship

Ongoing monitoring and reassessment surface a vendor drifting into higher risk while the dependency is still live.

FAQ

Questions, answered

How does it decide how much diligence a vendor needs?

Vendors are tiered by inherent risk and criticality against your methodology, so a critical core-system provider gets deeper diligence and closer monitoring than a low-risk supplier — and the tiering is recorded.

Does it keep vendor risk current after onboarding?

Yes. Vendors are re-screened and reassessed on a defined cadence, and issues and incidents are captured against the record, so a relationship drifting into higher risk is caught while it is still live.

Can it show where we are over-reliant on a provider?

Because every vendor sits on one register with criticality and services recorded, the programme supports concentration and dependency reporting for management.

Does OnyxOne assess our vendors for us?

No. OnyxOne provides the programme and orchestrates the checks against the data sources you contract; the assessment decisions and the responsibility for them remain with your firm.

Are SOC 2 or ISO 27001 held?

Not yet. Both are on our roadmap; we will publish attestations in the Trust Center once they are held rather than claim them beforehand.

Stand up your Third-Party & Vendor Risk Management programme

Book a walkthrough and we'll show how the composed programme fits your obligations, workflows and systems — then scope an implementation.