v3ndor.io
Blog
Blog
Third-party risk management, explained.
Practical, evergreen guides for the people who own vendor risk — what TPRM is, which vendor assurances actually mean something, and how to run a program that holds up to an auditor.
Articles
- ComplianceFrameworks
Mapping Vendor Controls Across SOC 2, ISO 27001, and NIST
When your vendor sends a SOC 2 report and your program runs on NIST CSF profiles, or vice versa, you face a translation problem that no single authoritative crosswalk solves. This guide walks through the common control spine, framework-by-framework mapping logic, and the gaps that require judgment rather than lookup tables.
June 7, 2026 · 10 min read
- ComplianceFrameworksNIST
NIST 800-53 vs NIST CSF for Third-Party Risk
People say "NIST" as if it's one thing. For vendor risk the CSF and 800-53 are different kinds of artifact - which to reach for, and the supply-chain publication most miss.
June 7, 2026 · 6 min read
- ComplianceFrameworksISO 27001
ISO 27001 for Vendor Risk: What the Certificate Covers
ISO 27001 is a certificate - but the badge means little without the scope and the Statement of Applicability. How to read past it in a vendor assessment.
June 7, 2026 · 6 min read
- ComplianceFrameworksGDPR
TPRM Under GDPR: Article 28 and Sub-Processors
GDPR Article 28 turns vendor diligence into a legal duty. What the DPA must contain, the sub-processor flow-down, and why your TPRM program is the evidence.
June 7, 2026 · 9 min read
- ComplianceFrameworksSOC 2
How to Read a SOC 2 Report (Without a CPA)
A SOC 2 has five sections and most of the signal is in two. How to read one without a CPA - opinion, scope, exceptions, and the controls you inherit.
June 7, 2026 · 9 min read
- ComplianceFrameworksSOC 2
SOC 2 Type I vs Type II: What's the Difference?
Type I checks control design on one date; Type II checks the controls actually worked over months. Which to require from a vendor, and how to read each.
June 7, 2026 · 8 min read
- TPRMFundamentalsVendor lifecycle
The Vendor Risk Lifecycle: Onboarding to Offboarding
The stages a vendor moves through from intake to offboarding - and why the last one is the stage most programs skip.
June 7, 2026 · 9 min read
- TPRMFundamentalsConcentration risk
What Is Concentration Risk in TPRM?
When too much rides on one vendor, cloud, region, or sub-processor, a single failure cascades. How to see concentration risk your per-vendor reviews miss.
June 5, 2026 · 8 min read
- TPRMFundamentalsRisk scoring
Inherent vs. Residual Risk, Explained
The two scores every risk register tracks - what each measures, how to rate them, and why the gap between them is the point.
June 5, 2026 · 8 min read
- TPRMFundamentalsDue Diligence
What Is Vendor Due Diligence? A Tier-Based Guide
The pre-contract evidence-gathering step: what vendor due diligence verifies, how deep to go by tier, and how it shapes the contract.
June 5, 2026 · 8 min read
- TPRMFundamentalsFourth-Party Risk
Third-Party vs. Fourth-Party Risk: What's the Difference?
How third- and fourth-party risk differ, why the vendors behind your vendors are the ones you can't see, and how to manage them.
June 5, 2026 · 8 min read
- TPRMFundamentalsVendor Risk
What Is a Vendor Risk Assessment? A Practical Guide
What a vendor risk assessment evaluates, when to run one, the steps to follow, and the artifacts it should leave behind.
June 5, 2026 · 8 min read
- TPRMFundamentals
What Is Third-Party Risk Management? A Practical Guide
What TPRM actually is, the lifecycle it follows, and how to run it without drowning in spreadsheets.
June 1, 2026 · 7 min read
- ComplianceVendor reviews
SOC 2 vs ISO 27001: Which Vendor Assurance Should You Require?
The two reports answer different questions. How to decide which assurance to require from a vendor — and how to read each one.
June 1, 2026 · 8 min read
- TPRMRisk tiering
How to Build a Vendor Risk-Tiering Model
Not every vendor deserves the same scrutiny. Build a tiering model that maps risk to a proportionate review cadence.
June 1, 2026 · 9 min read
Run third-party risk the way these guides describe.
Request access for a 30-day evaluation tenant — a complete vendor inventory, risk tiering, and audit-ready evidence in one place.