Stop chasing vendors for annual spreadsheets that are out of date the day they're returned. GRCxAI TPRM continuously gathers evidence about your third parties — from official registries, sanctions and watchlists, and live attack-surface scans — and grades every finding for reliability. Know who you're really dealing with, and prove it.
A single risk rating hides what you most need to know: how much do we actually know about this vendor? GRCxAI TPRM splits the score into three, so a confident "low risk" and a "low risk, but we couldn't check much" never look the same.
How risky the third party looks on the evidence we have — corporate, sanctions, cyber, financial, geographic and regulatory signals combined.
The weakest-link reliability of that evidence, graded on the NATO Admiralty scale (A1–F). One unverifiable source drags confidence down — honestly.
The percentage of required due diligence that actually ran. A missing data source shows as a coverage gap, never as a clean pass.
Every single finding in your due-diligence register carries an Admiralty rating — the same two-axis grading system NATO uses to evaluate intelligence. Source reliability (A–F) times information credibility (1–6). A Companies House filing is not the same as a press rumour, and your register says so on every row.
How trustworthy is the source itself? An official register scores A; an aggregator scores lower; an unverifiable source is marked honestly, never hidden.
How well is this specific claim corroborated? A CRN-confirmed insolvency notice is a 1. A single uncorroborated news item never masquerades as fact.
Confidence is weakest-link: one poorly-graded source drags it down, visibly. So "low risk on A1–B2 evidence" and "low risk on C3 evidence" never look the same — and when a regulator or auditor asks "how do you know?", every row of the register answers with its grade, its source and its timestamp.
Behind every dossier sits a continuously refreshed evidence corpus, built by Corvus — our dedicated vendor-intelligence engine — independent of anything a vendor self-reports. Start from a pool of 370+ vendors already under continuous monitoring, and add any vendor you need with one action — new vendors are scanned automatically on entry. Every single finding arrives graded for reliability, timestamped, and audit-ready.
Companies House (UK) identity, status and filings; the GLEIF Global LEI Index for worldwide legal-entity identity; SEC EDGAR for US filers. Identity is verified against the register — never taken from the supplier's word.
UK, OFAC and EU lists with weighted entity matching — every near-miss carries a defensible written rationale, not a naive fuzzy guess.
Gazette insolvency notices watched continuously. A notice confirmed against the company's registration number becomes a hard stop on the vendor — surfaced within hours, not at next year's questionnaire.
Fifteen passive probes per vendor domain — DNS & DNSSEC, passive DNS, RDAP registration data, TLS certificates, certificate-transparency logs, HTTP security headers, email posture (SPF/DKIM/DMARC), subdomain discovery, related domains, technology stack, typosquatting, cloud exposure and security.txt. Passive by design — we observe, we never intrude.
News events and threat-campaign reporting resolved to the actual companies in your portfolio — with official-register events (filings, status changes) ranked first in every vendor's feed, above press noise.
PSC and ownership chains walked and refreshed nightly, control-weighted — majority, minority and related-party links — rendered as an interactive ownership tree in every dossier.
Forward-looking, portfolio-relevant threat forecasting — distinct from current-campaign reporting, so you see what's coming, not just what's here.
GRCxAI reads the Corvus corpus live. Your curation, approvals, monitoring selections, assessments and business context stay private to your organization. Every feed result is graded for source reliability and information credibility on the NATO Admiralty scale (A1–F), and every finding lands in an append-only, hash-chained register.
TPRM watches your suppliers; vCISO watches your own estate. Define your infrastructure — hardware, software, SaaS — and Corvus continuously matches live CVE/KEV, attack-campaign and threat intelligence against it, surfacing only what genuinely threatens you as plain-English advisories with a governance workflow and board-level exposure metrics on top.
Every monitored third party gets a living dossier — the score header up top, then eight tabs of evidence: the due-diligence register, attack surface, alerts, intelligence, entity-resolved news, the network graph and a nightly-refreshed ownership tree. Here's a real vendor view (illustrative data).
From first request to board-ready dossier — every check below writes immutable, timestamped evidence, so your due-diligence record is always current and always defensible.
Company identity, status and filings verified against Companies House (UK), the GLEIF Global LEI Index worldwide and SEC EDGAR (US) — never the supplier's word. Official-register events rank first in every vendor's news feed, above press noise.
Who really owns your supplier? Ownership and PSC chains are walked and refreshed nightly, rendered as an interactive control-weighted tree in the dossier — majority control, minority stakes and related-party links all visible, offshore opacity flagged.
Screening against UK, OFAC and EU sanctions lists, plus politically-exposed-persons and debarment data — with weighted entity matching and a defensible note on every near-miss, not naive fuzzy guesses.
Fifteen passive probes — DNS & DNSSEC, passive DNS, RDAP, TLS & certificate-transparency logs, HTTP security headers, email posture (SPF/DKIM/DMARC), subdomains, related domains, tech stack, typosquatting, cloud exposure and security.txt — turning a vendor's domain into measurable cyber evidence, without ever intruding.
Always-on insolvency and Gazette signals, plus optional Creditsafe credit scores, County Court Judgements and going-concern checks (bring your own key) — financial distress surfaced as a hard stop.
A confirmed insolvency notice or sanctions hit doesn't get buried in a report — it blocks the vendor's validation status, fires an urgent alert into your email and webhooks, and links straight to the evidence. You find out in hours, not at renewal.
Every finding is an append-only, hash-chained record with a timestamp and a source grade. Review the register exactly as it stood on any past date — built for auditors and regulators.
New critical findings, risk-score swings, fresh sanctions hits and decision changes raise alerts as they happen — urgent findings bridged into email and webhooks with links straight to the dossier, plus one-click raise-as-risk and certificate-expiry tracking.
The inverse intelligence question: which threat campaigns are touching your portfolio right now? Campaigns are mapped to your monitored vendors with targeting detail — and forward-looking threat forecasts flag what's coming, not just what's current.
Map concentration and blast radius across your third parties, see shared directors and ownership, and explore a live knowledge graph of related vendors, threats and regulatory items.
From "can we use this supplier?" to a monitored, scanned third party — in one governed flow. Anyone can propose a vendor with its business context; admins review, request more info, or approve; approval registers the vendor and queues its first full scan automatically. Duplicates are caught at the door, and your business justification never leaves your tenant.
Two-tier approval workflow, per-company scoping, point-in-time approval snapshots, and native vendor assessments launched straight from a monitored vendor — evidence and workflow in one place.
Registry identity wrong? The Fix Queue routes corrections for admin review so the record gets fixed at the source — and org-defined tags plus named relationship owners keep the portfolio organized the way your business actually runs.
Every check is an immutable, timestamped record — graded for reliability on the NATO Admiralty scale, and tagged with an honest evidence state. A clean result, a finding, a "couldn't check" and a "doesn't apply" never look the same.
Annual questionnaires measure how good a vendor is at filling in questionnaires. We measure what's actually true — gathered independently, graded for reliability, and refreshed continuously. And when you do want the vendor's voice, every answer is AI-checked against that independent evidence (see below).
Security-rating tools give you a letter grade. GRCxAI gives you the underlying evidence register — sanctions, ownership, financials and cyber — that a rating can't, with the audit trail to prove it.
We don't pad the feature list with dark-web "monitoring." In practice it's high-noise and low-value for third-party due diligence — a constant stream of unverifiable alerts. We invest that effort in evidence you can act on and defend instead.
Send secure magic-link questionnaires when your process calls for them — Cat 1/2/3 question banks or your own. The difference: AI cross-validates every answer against the Corvus evidence pool, and an AI judge reads every uploaded document to verdict whether it actually proves the claim. Self-assessment stops being self-serving.
Secure tokenised links, resumable responses, expiry and reminders, colleague delegation, evidence upload with cryptographic receipts, and a return-for-revisions loop — friction-free for the third party, fully tracked for you.
A vendor claiming ISO 27001 with no certificate in the evidence pool gets flagged — with the verdict, rationale and score impact shown per answer. Contradictions dock the rating, visibly.
Every uploaded file — pen tests, certificates, policies — is read and verdicted: supports, partial, insufficient or wrong document. It catches the 2019 pen test, and the lunch menu attached as a certificate.
75% external posture + 25% assessment lane, with published deductions per contradiction or bad document. The formula ships in the payload — no black-box score. Your combined rating stays private to your organisation.
A certificate submitted through the portal can be promoted to the vendor's shared record — AI-read, independently re-validated, provenance-marked, and slotted into an expiry-sorted chain where an old upload can never displace a newer certificate.
Vendors can raise issues and propose updates after submitting; you accept or decline with a full activity trail. Everything lands in the same governed workflow as the rest of your due diligence.
Add TPRM to your GRCxAI platform, or run it as a standalone product with no full-GRC requirement. Either way it's £2,000/month per company entity for unlimited monitored third parties.
Layer TPRM on top of the £2,000 GRC platform. Full suite = £4,000/mo per company.
TPRM as a dedicated product, no full GRC platform required. Unlimited monitored third parties.
Multi-company groups billed per legal entity. See full pricing →