Platform

Every vendor, right-sized.

A vendor review is mostly reading three documents and then arguing with them. TruOps does the reading and surfaces the arguments worth having.

Vendor register · sized to riskreassessing on schedule
VendorTierQuestionnaireClaims vs. evidenceRisk
DataTemp IncCriticalSIG Lite · in portal1 contradiction7.8
Payroll CoHighSIG Core · completeconsistent5.1
Design SaaSModerate12 questions · completeconsistent3.2
Swag SupplierLowscreening onlyn/a1.0
41Tier 1 vendors3overdue12fourth parties mapped
Illustrative example
In short

Vendor risk management in TruOps starts from a vendor's domain: TruOps tiers each vendor by the service and data involved, sends a questionnaire sized to that tier through a vendor portal, compares the vendor's answers with their SOC 2 report and scan results, and turns failed checks into findings with a recommended action. Vendors see only their own tasks and findings.

This page is for you if
  • The queue is longer than the team
  • Critical and low-risk vendors get the same workbook
  • SOC 2 reports are stored, not compared with answers

The actual challenge

TPRM products optimized sending. The remaining work is reading, checking, and deciding. That is where programs stall.

  • The current tool starts empty, or only works for one framework.
  • Evidence, vendors, and risk do not share a record.
  • AI, if it exists, suggests; it does not do the work with sources.

What you are probably using today

This module is usually replacing a folder, a suite module, or a point tool, not a blank page.

What you use nowWhere it breaksWith TruOps
TPRM portals and SIG factoriesThroughput of sending, bottleneck of review.Tier, right-size, agent first-read, claims vs. evidence.
BitSight / SecurityScorecard as the reviewA rating is a signal, not a file review.Use outside-in context; still run a sized assessment with evidence.
Spreadsheets, shared drives, and emailThe program lives in folders named after last year's audit. Owners paste screenshots the week before fieldwork. Nothing is dated, so you cannot show what was true last quarter.Upload those same files. TruOps pre-fills the assessment from them, cites every answer, and keeps technical checks running so evidence exists for the whole period.

Bring one real document. Watch the program get set up from it.

Tier first, then ask

A payroll processor and a swag vendor should not both get 300 questions. TruOps tiers each vendor by the service it provides and the data it touches, starting with inherent risk and moving to residual risk once evidence arrives, and sizes the questionnaire to the tier.

A portal for the other side

Invite a vendor as an outside guest. They get a portal with their tasks, the findings that apply to them, and a data room to share files both ways. Past answers pre-fill what they already told you. They see only their own work.

  1. InviteScope an assessment to the vendor and invite them as a guest.
  2. AnswerThe vendor answers and uploads evidence; past answers pre-fill.
  3. CheckThe agent reviews the evidence and flags weak spots for you.
  4. Share findingsShare relevant findings in the portal; the vendor fixes and re-uploads proof.
  5. DecideAccept, fix, or add to the risk register. The result includes a vendor risk score.

Answers, checked

The agent compares what a vendor claims with their SOC 2 report and scan results, and surfaces contradictions instead of filing them. Reassessments run on a schedule, and can be triggered when a certificate expires or something changes.

How TruOps helps

Onboard from a domain
Outside-in scanning helps populate the vendor register and industry.
Risk tiering
Inherent tier from service and data; residual once evidence lands.
Right-sized questionnaires
SIG, CAIQ, or your own, sized to the tier.
Vendor portal
Tasks, findings, and a two-way data room for each vendor.
Claims vs. evidence
Answers compared with SOC 2 reports and scans; contradictions flagged.
Findings to the register
Vendor findings carry their rating, evidence, and recommendation.

Questions

What is third-party risk management?

Third-party risk management (TPRM) is identifying, assessing, and monitoring the risks that vendors and other outside parties introduce. See What is TPRM?

Can vendors fill in questionnaires directly in TruOps?

Yes. Vendors join as outside guests with their own portal and data room. They see only their own tasks and findings.

Which vendor questionnaires are supported?

Standard questionnaires such as SIG and CAIQ, and any questionnaire you upload, sized to the vendor's tier.

What if a vendor does not respond in time?

The assessor can take the assessment back, extend it, or finish with the vendor's part marked incomplete. Nothing is auto-submitted.

Do we have to rip out the tools we already use?

No. Connectors are read-only: they observe cloud, identity, endpoint, vulnerability, and code tools; they do not change them. Spreadsheets, prior reports, and policies upload into the Data Room. If you are on a SOC 2 automation tool or an enterprise GRC suite, you migrate the program (frameworks, evidence, vendors, risks), not the business.

Can we bring our existing assessments, control lists, and vendor files?

Yes. Upload workbooks, reports, policies, and vendor exports. TruOps turns them into structured questionnaires, controls, and register entries, each cited back to the file they came from, for you to review.

See it run on your own data.

Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.