Gainfront home
Menu

Third-Party Risk Management

Risk you assess after onboarding is risk you already inherited.

RiskMetrix runs inside the onboarding workflow, not beside it. Inherent risk is scored on the supplier's first submission, a reliability index is set before go-live, and cyber, financial, compliance and delivery signals keep it current for as long as the supplier is active, all on the record your buyers, contracts and scorecards already use.

RiskMetrix · Smart TPRM by Gainfront

The difference isn't the assessment. It's when the assessment happens, and what record it lands on.

Definition

What is third-party risk management (TPRM) software?

Third-party risk management (TPRM) software assesses and monitors the risk a supplier, vendor or partner introduces across cyber, financial, compliance, data privacy, operational, geographic and ESG domains. Gainfront RiskMetrix runs that assessment inside the onboarding workflow rather than as a separate step, and keeps the score current with continuous monitoring on the same supplier record procurement already uses.

Coverage

Eight risk domains, read together rather than one at a time.

A supplier rarely fails for one reason. A thin balance sheet and a delivery slip and an unpatched system are three separate alerts in three separate tools, and one problem on one record here.

  • Cyber

    Cybersecurity & information security

    Security posture, control attestations, breach and incident history, and vulnerability exposure tracked against the supplier's declared technology footprint.

  • Financial

    Financial viability

    Credit and solvency signals, payment behaviour and concentration exposure, so a deteriorating supplier surfaces before a missed delivery does.

  • Compliance

    Regulatory, sanctions & ABAC

    Sanctions and denied-party screening, anti-bribery and anti-corruption attestations, adverse media, and licence or certification currency.

  • Privacy

    Data privacy

    What data the supplier touches, under which agreements, with GDPR and regional requirements assessed at intake rather than at audit.

  • Operational

    Operational & delivery

    On-time delivery, quality, responsiveness and capacity, pulled from your ERP, feeding the same score as every other domain.

  • Geographic

    Geographic & geopolitical

    Country and region exposure, trade restrictions, logistics disruption and single-region concentration across the supply base.

  • ESG

    ESG & ethical sourcing

    Environmental, labour and human-rights exposure, modern-slavery declarations, and mandate reporting on the same supplier ID.

  • Sub-tier

    Fourth-party & concentration

    Who your suppliers depend on, where several of them depend on the same source, and where that concentration puts your continuity at risk.

How RiskMetrix works

One assessment lifecycle, from intake form to remediation closure.

Every stage writes to the same supplier record, so nothing has to be re-keyed and nothing lives in a risk system your buyers never open.

  • Stage 01

    Intake & inherent risk

    Scored on the supplier's first submission, before approval.

    • Category, geography and data-access exposure
    • Spend and criticality tiering
    • Risk-based routing to the right reviewers
  • Stage 02

    Smart TPRM assessment

    The questionnaire matches the tier, not every supplier.

    • Standards-aligned question libraries
    • AI-assisted response prefill and evidence review
    • Document collection with expiry tracking
  • Stage 03

    Reliability index

    A single score attached to the supplier before go-live.

    • Weighted across all eight domains
    • Configurable model and thresholds
    • Residual risk after controls, not just inherent
  • Stage 04

    Continuous monitoring

    The score moves when the world does.

    • NIST and CVE vulnerability feeds
    • Sanctions, adverse media and financial signals
    • ERP performance data on the same index
  • Stage 05

    Mitigation & closure

    A finding becomes an owned task with a due date.

    • Remediation plans and evidence of closure
    • Escalation, hold and exit workflows
    • Full audit trail for regulators and boards

Cyber & vulnerability tracking

When a vulnerability is published, you should already know which suppliers it touches.

RiskMetrix holds what each supplier declared about their technology and controls. When a new CVE or advisory lands, that declaration is what turns an industry headline into a named list of suppliers, owners and due dates.

  • Vulnerability feeds, matched to your base

    NIST NVD and CVE advisories matched against declared platforms, components and hosting, rather than a generic feed you read and act on manually.

  • Security posture on the record

    Control attestations, certifications and their expiry dates, external security ratings where you subscribe to them, and breach history, all attached to the supplier, not a separate register.

  • Threshold-based workflows

    When a score crosses a line you set, the workflow fires: reassessment, evidence request, escalation, or a hold on new POs pending review.

  • Incident and disruption response

    A named contact, a documented plan and a continuity assessment for the suppliers you cannot afford to lose, ready before you need them.

Illustrative advisory response. Example data, not customer records.

Watch

Risk in action

Predictive risk across financial, operational, and regulatory exposure: surfaced on the supplier record.

  • RiskMetrix scores inherent risk and a Supplier Reliability Index from real-time feeds, so risk is continuous rather than an annual questionnaire.
  • Monitoring pulls NIST National Vulnerability Database feeds and compliance signals, with threshold workflows that fire when a supplier crosses a limit you set.
  • Smart TPRM runs category-aware due diligence at onboarding, so the depth of the check matches what the supplier is actually being bought for.

Mitigation

A risk score nobody acts on is a report, not a control.

Most of the value in risk management sits after the finding. RiskMetrix keeps mitigation on the supplier record your category managers and buyers already work in, which is the difference between a remediation plan that closes and one that lives in a spreadsheet.

  • Risk register on the supplierEvery open finding, its severity, owner, due date and status, visible on the same record as the contract and the spend.
  • Remediation plans with evidenceCorrective actions assigned to named owners on both sides, closed only when the evidence is attached and reviewed.
  • Escalation and supplier holdBreach a threshold and new purchase orders can be held pending review, because the risk system and the buying system are the same system.
  • Alternate supplier readinessWhen a critical supplier deteriorates, the qualified alternates are already on the record with their own current scores.
  • Reassessment triggersContract renewal, scope change, an incident, a score movement or a calendar cycle. Each can start the right depth of reassessment automatically.
  • Board and regulator reportingPortfolio exposure by domain, tier and region, with the audit trail behind every number and no reconciliation before the meeting.
  • Offboarding that actually closesAccess revoked, obligations settled, data returned or destroyed, and the record kept for the retention period rather than deleted.
  • Configurable scoring modelWeights, thresholds, tiers and questionnaire depth set to your risk appetite and your regulator's expectations, not ours.

Evaluating alternatives

Where a standalone risk platform stops.

Dedicated third-party risk tools do assessment and monitoring well. The gap is structural rather than functional: they sit next to the systems where supplier work actually happens, so the assessment starts late and the mitigation lands somewhere your buyers never look.

Feature comparison: Standalone risk platform versus RiskMetrix by Gainfront
CapabilityStandalone risk platformRiskMetrix by Gainfront
When the first assessment runsAfter the supplier exists in your ERP, as a separate onboarding stepInside the intake form, before approval
Where the score livesIn the risk platform, synced to other systems at bestOn the supplier record, next to spend, contracts and performance
Performance dataRarely available; no ERP delivery or quality feedDelivery, quality and responsiveness feed the same index
Acting on a findingNotify the owner and hope the action happens elsewhereHold POs, trigger reassessment, open remediation on the record
Diversity, ESG and CSR contextSeparate tool, separate supplier listSame supplier ID as risk, spend and contracts
Cost of the second systemA licence, an integration, and a supplier list that driftsNo separate TPRM licence; the risk system is the supplier system

Already evaluating us for the relationship side? Onboarding, scorecards, collaboration and PartnerIQ live on the supplier relationship management page: same record, same demo.

Supplier relationship management

Questions we get from risk teams

Before you shortlist anyone.

Do we have to replace our ERP or P2P to use RiskMetrix?

No. Run Gainfront as your supplier system of record, or keep Coupa, Ariba or your ERP and let AgentFlow orchestrate intake, assessment and mitigation across what you already own.

Can we keep our existing questionnaires and scoring model?

Yes. Question libraries, weights, tiers and thresholds are configurable, and existing assessments can be brought across so history is not lost at go-live.

How does this handle fourth-party exposure?

Suppliers declare their critical dependencies during assessment, so concentration across your base (several suppliers relying on the same source) is visible rather than assumed.

Who owns risk day to day, us or procurement?

Both, on one record. Risk owns the model, thresholds and reporting; procurement sees the score where they already work, which is why remediation closes instead of stalling.

Next step

Bring your supplier list. We'll show you what's already sitting in it.

Thirty minutes, your own data, with someone who has run procurement and carried a risk mandate.