Risk & Vendor Management
Risks, Findings and Vendors, Closed With Proof
Findings, exceptions, risks, vendors and incidents live in the same record as your controls, so every risk shows what reduces it and every fix is proved before it is closed.
How it works
From Record to Proof
Detect
Failed tests raise findings automatically, with the evidence that shows what failed.
Decide
Fix it, or request a time-boxed exception. The person who requests an exception can never approve it.
Treat
Risks are scored before and after treatment and linked to the controls that reduce them. Every change is recorded on the ledger.
Verify
A finding closes only when a later test proves the fix held.
What’s included
- FindingsClosed only when a later test proves the fix held.
- ExceptionsTime-boxed and approved, with a reminder before they lapse.
- Risk registerOwners, treatment and the controls that reduce each risk.
- VendorsDue diligence with certificates on file and reviews on a schedule.
- IncidentsFrom detection to lessons learned, on the record.
What It Proves
- Segregation of duties enforced in the database, not just in the interface
- Exceptions expire, with a reminder before they lapse
- Vendors tiered by criticality, with document and review gates and certificates on file
- Incidents tracked against the regulator’s clock, and closed only after a post-incident review
Frameworks it serves
Questions
What People Ask
Why can’t a finding simply be marked as fixed?
Because an assertion is not proof. A finding closes when a later test shows the control operating again, so the closure is itself evidence.
How are vendors reviewed?
Each vendor has a criticality tier, an owner and a review date. Assessments and documents such as certificates are kept on the vendor, and the same person cannot both request and approve a decision.
Related
The Rest of the Platform
Ready to prove it?
Know what you are responsible for, control whether it works, and prove it to anyone who asks.