Skip to content
Sentinel Unity

Third-Party Risk (TPRM)

Tiering that a knockout rule can override

Inherent factors compute a score and a band, and a knockout rule can force a tier regardless, because some combinations are critical whatever the arithmetic says.

  • Tier factors and factor scores feeding configurable scoring profiles
  • Knockout rules that override the computed band outright
  • Fourth-party links, so the chain past your direct vendor is visible
  • Review schedule rules that set reassessment cadence by tier

Inherent risk factors

  • Data classificationConfidential,
  • System access levelPrivileged,
  • Service criticalityHigh,
  • Fourth-party reliancePresent,
Inherent score0 / 20

Knockout rule applied. Privileged access to confidential data forces Tier 1, whatever the computed score says.

Contracts

Obligations tracked, not just documents stored

Contracts carry categorised obligations with their own status, a full status history, and review decisions with approvals, so a contractual security commitment is a tracked object.

  • Contract obligations by category, each with status
  • Contract status history retained end to end
  • Review decisions with recorded approvals
  • Engagements scoped to entities, with service and asset links

Treatment decision

  1. 1Treatment planActions with owners, priority, and due dates
  2. 2Action trackingStatus per action, SLA where defined
  3. 3ReassessmentResidual score recalculated after closure

Due diligence

Evidence with an expiry date

Due diligence requests move through lifecycle phases and carry document validity, so expired attestations surface instead of silently ageing in a folder.

  • Requests typed by kind, with lifecycle phase and status
  • Document type and validity status tracked per artefact
  • Questionnaire assessments with sections, scoring dimensions, and methods
  • Score overrides captured with their own approval status

Level 3: Well Defined

A standard process is defined and followed across the organisation.

Every question in the control library carries its own written descriptor at each level.

Issues

Findings that come out of assessments

Assessment responses can trigger issues automatically, categorised and severity-rated, so a weak answer becomes tracked work rather than a note in a report.

  • Issues with severity, status, category, source, and type
  • Assessment-triggered issue creation
  • Comments and attachments per issue
  • Lifecycle history across the whole vendor relationship

Privileged access review not evidenced

Traced to control · raised from assessment

High
  1. Export current privileged accounts

    IT Ops

  2. Confirm owner for each account

    System owners

  3. Remove unowned accounts

    IT Ops · waiting on “Confirm owner for each account

  4. Attach review evidence

    Security · waiting on “Remove unowned accounts

Evidence is reviewed and accepted, not just attached

Framework alignment

Works with your control frameworks

This module shares the platform control library. Map national frameworks and global standards alongside jurisdiction-specific authorities.

See third-party risk in your environment

A walkthrough scoped to your entities, your frameworks, and the way your programme is actually run.