Roles · Third-party risk manager

For third-party risk: fewer questions, better answers.

Most vendor reviews are reading three documents and arguing with them. TruOps does the reading and shows you the arguments worth having.

Your Monday view · Third-party risk managerlive data
412vendors tiered
41Tier 1
3contradictions flagged
12fourth parties mapped
Illustrative example
In short

For third-party risk managers, TruOps tiers vendors by service and data, sizes questionnaires to each tier, gives vendors a portal and shared data room, compares their answers with their SOC 2 and scan results, and turns gaps into findings you can share with the vendor.

This page is for you if
  • Volume is the problem, not policy
  • Low-risk vendors get the same questionnaire as critical ones
  • Answers are not checked against evidence

What the job asks of you

  • Assess hundreds of vendors with a small team.
  • Keep reviews proportional to each vendor's risk.
  • Catch answers that contradict the vendor's own evidence.
  • Reassess on schedule and when things change.

The actual challenge

TPRM products got good at sending. The remaining work is reading, checking the vendor’s SOC 2 against their answers, and putting residual risk on the register the examiner sees. A ratings feed is a signal, not that work.

  • The queue is longer than the team that reads.
  • Critical and long-tail vendors get the same workbook.
  • Findings never leave the TPRM tool.

Bring one real document. Watch the program get set up from it.

What you are probably using today

TPRM is a portal, a ratings feed, and a queue.

What you use nowWhere it breaksWith TruOps
A TPRM portal + inboxSending scaled. Review did not.Tiering, right-sized questionnaires, agent first-read, contradictions flagged.
Outside-in ratings as the programA score is not due diligence.Use ratings to inform tier; still assess, with evidence.
Spreadsheets, shared drives, and emailThe program lives in folders named after last year's audit. Owners paste screenshots the week before fieldwork. Nothing is dated, so you cannot show what was true last quarter.Upload those same files. TruOps pre-fills the assessment from them, cites every answer, and keeps technical checks running so evidence exists for the whole period.

Jobs this role actually runs

Titles are how org charts name the work. These are the packages a Third-party risk manager has to produce, and what “done” looks like when a board, examiner, auditor, or engineer asks.

Use caseWhat done looks like
Tier before you sendInherent risk from the service and the data involved, so a marketing tool and a core processor do not get the same 300 questions
A portal instead of an inboxThe vendor answers, uploads proof, and sees findings in their own space
A first read you can trust enough to start fromThe agent compares questionnaire claims with the vendor's SOC 2 or scans and flags contradictions — a person still decides
Residual risk the examiner can seeVendor findings on the same register as security and compliance, not a score that lives only in the TPRM tool
Reassessment when something changesOn a schedule, and when the service or data involved grows

What TruOps gives you

  • Tiering from the service and data involved.
  • Right-sized questionnaires through a vendor portal.
  • Answers compared with SOC 2 reports and scans.
  • Findings shared with the vendor, with fixes tracked.

If this is your situation

Bring the vendor list and one completed questionnaire plus the vendor’s SOC 2. TruOps will show a first read that flags contradictions — a person still decides.

Questions

Can vendors see each other's data?

No. Each vendor sees only its own tasks, findings, and files.

Is TruOps a security-ratings network?

No. Outside-in scores can inform tiering. They are not a substitute for a sized assessment with evidence. Examiners know the difference.

Do findings stay in a TPRM silo?

No. Gaps become findings you can share with the vendor and add to the same register as the rest of the program.

Do we have to rip out the tools we already use?

No. Connectors are read-only: they observe cloud, identity, endpoint, vulnerability, and code tools; they do not change them. Spreadsheets, prior reports, and policies upload into the Data Room. If you are on a SOC 2 automation tool or an enterprise GRC suite, you migrate the program (frameworks, evidence, vendors, risks), not the business.

See it run on your own data.

Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.