← All Tools

Third-Party Risk Register

Every noodle supplier, tracked, so none goes stale. Vendors, criticality tier, status, review dates with overdue flags, open findings — and a one-click hand-off to the questionnaire generator.

⚠ This is a local, single-browser register, not a shared system of record. The list lives in this tab, or in this browser only if you turn on local saving below; clearing your browser data deletes it. Export regularly — CSV / JSON for your GRC tool, or the encrypted backup to carry it elsewhere. Nothing you enter leaves your device.
Frameworks

No vendors yet. Add one, or import your existing list as CSV.

Criticality follows the DORA logic for critical or important functions (Art. 3(22)): a vendor whose failure would materially impair operations is critical on that alone; two or more of the four criteria make it critical, one makes it important. The tier drives how deep the questionnaire goes. This is the operational register; for the regulatory Register of Information (DORA Art. 28(3), ITS templates) use the DORA Register of Information builder. The policy this register implements can be drafted with the Policy Document Generator (Third-Party / Supplier Security Policy). Informational only — not legal advice.