Premium Module • Corvus-Backed Intelligence

Third-Party Risk Management
Continuous. Evidence-Based. No Questionnaires Required.

Stop chasing vendors for annual spreadsheets that are out of date the day they're returned. GRCxAI TPRM continuously gathers evidence about your third parties — from official registries, sanctions and watchlists, and live attack-surface scans — and grades every finding for reliability. Know who you're really dealing with, and prove it.

3
Score Model: Risk / Confidence / Coverage
16
Continuous Assurance Feeds
15
Passive Attack-Surface Probes
7
Honest Evidence States
0
Questionnaires Required

Honest Scoring

One Number Was Never Enough

A single risk rating hides what you most need to know: how much do we actually know about this vendor? GRCxAI TPRM splits the score into three, so a confident "low risk" and a "low risk, but we couldn't check much" never look the same.

Risk

How risky the third party looks on the evidence we have — corporate, sanctions, cyber, financial, geographic and regulatory signals combined.

Confidence

The weakest-link reliability of that evidence, graded on the NATO Admiralty scale (A1–F). One unverifiable source drags confidence down — honestly.

Coverage

The percentage of required due diligence that actually ran. A missing data source shows as a coverage gap, never as a clean pass.

Evidence Ratings

Graded Like Intelligence — the NATO Admiralty Scale

Every single finding in your due-diligence register carries an Admiralty rating — the same two-axis grading system NATO uses to evaluate intelligence. Source reliability (A–F) times information credibility (1–6). A Companies House filing is not the same as a press rumour, and your register says so on every row.

Source Reliability — A to F

A · Completely reliable B · Usually reliable C · Fairly reliable D–F · Declining / unproven

How trustworthy is the source itself? An official register scores A; an aggregator scores lower; an unverifiable source is marked honestly, never hidden.

Information Credibility — 1 to 6

1 · Confirmed 2 · Probably true 3 · Possibly true 4–6 · Doubtful / unjudged

How well is this specific claim corroborated? A CRN-confirmed insolvency notice is a 1. A single uncorroborated news item never masquerades as fact.

Why it matters: the rating drives your Confidence score

Confidence is weakest-link: one poorly-graded source drags it down, visibly. So "low risk on A1–B2 evidence" and "low risk on C3 evidence" never look the same — and when a regulator or auditor asks "how do you know?", every row of the register answers with its grade, its source and its timestamp.

The Intelligence Behind It

Powered by the Corvus Intelligence Corpus

Behind every dossier sits a continuously refreshed evidence corpus, built by Corvus — our dedicated vendor-intelligence engine — independent of anything a vendor self-reports. Start from a pool of 370+ vendors already under continuous monitoring, and add any vendor you need with one action — new vendors are scanned automatically on entry. Every single finding arrives graded for reliability, timestamped, and audit-ready.

16 Continuous Assurance Feeds — Per Vendor
Companies House — UK CRN, officers, PSC, filings
Registry Search & Match — entity resolution
GLEIF LEI — global legal-entity identity
SEC EDGAR — US filings
Sanctions — UK · OFAC · EU, versioned lists
PEP Screening — politically exposed persons
Debarment — barred-supplier registers
Modern Slavery Registry — weekly sync
Insolvency & Distress — Gazette watch, hard stops
VAT (HMRC) — validity with proof-of-check
Certifications — ISO & Cyber Essentials evidence
Regulatory & ICO — registration + enforcement
Geographic Risk — jurisdiction exposure
Breach Exposure — domain breach history
Exposed Services — internet-facing infrastructure
Threat Intelligence — campaigns touching your portfolio

Official Registries

Companies House (UK) identity, status and filings; the GLEIF Global LEI Index for worldwide legal-entity identity; SEC EDGAR for US filers. Identity is verified against the register — never taken from the supplier's word.

Sanctions, PEP & Debarment

UK, OFAC and EU lists with weighted entity matching — every near-miss carries a defensible written rationale, not a naive fuzzy guess.

Insolvency & Gazette Watch

Gazette insolvency notices watched continuously. A notice confirmed against the company's registration number becomes a hard stop on the vendor — surfaced within hours, not at next year's questionnaire.

Live Attack-Surface Scans

Fifteen passive probes per vendor domain — DNS & DNSSEC, passive DNS, RDAP registration data, TLS certificates, certificate-transparency logs, HTTP security headers, email posture (SPF/DKIM/DMARC), subdomain discovery, related domains, technology stack, typosquatting, cloud exposure and security.txt. Passive by design — we observe, we never intrude.

Entity-Resolved News & Threats

News events and threat-campaign reporting resolved to the actual companies in your portfolio — with official-register events (filings, status changes) ranked first in every vendor's feed, above press noise.

Beneficial-Ownership Graph

PSC and ownership chains walked and refreshed nightly, control-weighted — majority, minority and related-party links — rendered as an interactive ownership tree in every dossier.

Predictive Threat Forecasts

Forward-looking, portfolio-relevant threat forecasting — distinct from current-campaign reporting, so you see what's coming, not just what's here.

The corpus supplies the evidence — your workspace owns the decisions

GRCxAI reads the Corvus corpus live. Your curation, approvals, monitoring selections, assessments and business context stay private to your organization. Every feed result is graded for source reliability and information credibility on the NATO Admiralty scale (A1–F), and every finding lands in an append-only, hash-chained register.

Coming SoonvCISO — the same corpus, turned inward

TPRM watches your suppliers; vCISO watches your own estate. Define your infrastructure — hardware, software, SaaS — and Corvus continuously matches live CVE/KEV, attack-campaign and threat intelligence against it, surfacing only what genuinely threatens you as plain-English advisories with a governance workflow and board-level exposure metrics on top.

Inside the Product

The Vendor Dossier

Every monitored third party gets a living dossier — the score header up top, then eight tabs of evidence: the due-diligence register, attack surface, alerts, intelligence, entity-resolved news, the network graph and a nightly-refreshed ownership tree. Here's a real vendor view (illustrative data).

app.grcxai.com/tprm/vendors/northwind-logistics
74OverallHigh
81RiskPoor
77ConfidenceHigh
85Coverageof applicable
Northwind Logistics Ltd
CRN 12345678 · northwind-logistics.com
Cat 1b High Pending Approval AI systems
19 checks complete · 2 sources awaiting credentials · 1 flagged for review · 4 not applicable.
Overview Due-Diligence Register Attack Surface Alerts Intelligence News Network Ownership
A code-faithful preview of the GRCxAI TPRM dossier — illustrative data, no real third party shown.

What's Inside

Continuous Due Diligence, End to End

From first request to board-ready dossier — every check below writes immutable, timestamped evidence, so your due-diligence record is always current and always defensible.

Corporate Identity & Registry Verification

Company identity, status and filings verified against Companies House (UK), the GLEIF Global LEI Index worldwide and SEC EDGAR (US) — never the supplier's word. Official-register events rank first in every vendor's news feed, above press noise.

Beneficial-Ownership Graph

Who really owns your supplier? Ownership and PSC chains are walked and refreshed nightly, rendered as an interactive control-weighted tree in the dossier — majority control, minority stakes and related-party links all visible, offshore opacity flagged.

Sanctions, PEP & Adverse Media

Screening against UK, OFAC and EU sanctions lists, plus politically-exposed-persons and debarment data — with weighted entity matching and a defensible note on every near-miss, not naive fuzzy guesses.

Attack-Surface Scanning

Fifteen passive probes — DNS & DNSSEC, passive DNS, RDAP, TLS & certificate-transparency logs, HTTP security headers, email posture (SPF/DKIM/DMARC), subdomains, related domains, tech stack, typosquatting, cloud exposure and security.txt — turning a vendor's domain into measurable cyber evidence, without ever intruding.

Financial & Credit

Always-on insolvency and Gazette signals, plus optional Creditsafe credit scores, County Court Judgements and going-concern checks (bring your own key) — financial distress surfaced as a hard stop.

Hard Stops, Not Footnotes

A confirmed insolvency notice or sanctions hit doesn't get buried in a report — it blocks the vendor's validation status, fires an urgent alert into your email and webhooks, and links straight to the evidence. You find out in hours, not at renewal.

Immutable Audit Trail

Every finding is an append-only, hash-chained record with a timestamp and a source grade. Review the register exactly as it stood on any past date — built for auditors and regulators.

Continuous Monitoring & Alerts

New critical findings, risk-score swings, fresh sanctions hits and decision changes raise alerts as they happen — urgent findings bridged into email and webhooks with links straight to the dossier, plus one-click raise-as-risk and certificate-expiry tracking.

Threat Radar & Predictive Forecasts

The inverse intelligence question: which threat campaigns are touching your portfolio right now? Campaigns are mapped to your monitored vendors with targeting detail — and forward-looking threat forecasts flag what's coming, not just what's current.

Supply-Chain & Intelligence Graph

Map concentration and blast radius across your third parties, see shared directors and ownership, and explore a live knowledge graph of related vendors, threats and regulatory items.

Third-Party Request Workflow

From "can we use this supplier?" to a monitored, scanned third party — in one governed flow. Anyone can propose a vendor with its business context; admins review, request more info, or approve; approval registers the vendor and queues its first full scan automatically. Duplicates are caught at the door, and your business justification never leaves your tenant.

Governance & Assessments

Two-tier approval workflow, per-company scoping, point-in-time approval snapshots, and native vendor assessments launched straight from a monitored vendor — evidence and workflow in one place.

Data Quality You Can Act On

Registry identity wrong? The Fix Queue routes corrections for admin review so the record gets fixed at the source — and org-defined tags plus named relationship owners keep the portfolio organized the way your business actually runs.

Inside the Product

The Due-Diligence Register

Every check is an immutable, timestamped record — graded for reliability on the NATO Admiralty scale, and tagged with an honest evidence state. A clean result, a finding, a "couldn't check" and a "doesn't apply" never look the same.

app.grcxai.com/tprm/vendors/northwind-logistics · Register
Corporate
8 tests · 12 evidence
Sanctions
3 tests · 2 evidence
PEPs
4 tests · 1 evidence
Finance
6 tests · 5 evidence
Cyber
12 tests · scan
Geographic
3 tests · 1 evidence
Identity & status
✓ CLEAR Northwind Logistics Ltd corporate.identity_status A2 16 Jun 2026
Directors & cross-company history
⚠ REVIEW Director linked to a dissolved entity B3 10 Jun 2026
Evidence state — Flagged as indeterminate: a current director also held a board seat at a company dissolved within 24 months. Source: Companies House · checked 10 Jun 2026.
Sanctions & watchlists
✓ CLEAR Northwind Logistics Ltd sanctions.ofac_sdn C1 16 Jun 2026
Credit & going concern
⏳ AWAITING SOURCE Creditsafe report — connect your key to enable finance.going_concern
Seven honest evidence states · NATO Admiralty grades on every source · immutable, hash-chained, audit-ready.

Built Differently

Depth Where It Matters — No Noise Where It Doesn't

Evidence, not self-reported questionnaires

Annual questionnaires measure how good a vendor is at filling in questionnaires. We measure what's actually true — gathered independently, graded for reliability, and refreshed continuously. And when you do want the vendor's voice, every answer is AI-checked against that independent evidence (see below).

A rating is not due diligence

Security-rating tools give you a letter grade. GRCxAI gives you the underlying evidence register — sanctions, ownership, financials and cyber — that a rating can't, with the audit trail to prove it.

Deliberately no dark-web noise

We don't pad the feature list with dark-web "monitoring." In practice it's high-noise and low-value for third-party due diligence — a constant stream of unverifiable alerts. We invest that effort in evidence you can act on and defend instead.

New — Vendor Response Portal

When You Do Want the Vendor's Voice — Verified

Send secure magic-link questionnaires when your process calls for them — Cat 1/2/3 question banks or your own. The difference: AI cross-validates every answer against the Corvus evidence pool, and an AI judge reads every uploaded document to verdict whether it actually proves the claim. Self-assessment stops being self-serving.

Magic-Link Portal — No Vendor Accounts

Secure tokenised links, resumable responses, expiry and reminders, colleague delegation, evidence upload with cryptographic receipts, and a return-for-revisions loop — friction-free for the third party, fully tracked for you.

AI Answer Cross-Validation

A vendor claiming ISO 27001 with no certificate in the evidence pool gets flagged — with the verdict, rationale and score impact shown per answer. Contradictions dock the rating, visibly.

AI Document Judge

Every uploaded file — pen tests, certificates, policies — is read and verdicted: supports, partial, insufficient or wrong document. It catches the 2019 pen test, and the lunch menu attached as a certificate.

An Explainable Combined Rating

75% external posture + 25% assessment lane, with published deductions per contradiction or bad document. The formula ships in the payload — no black-box score. Your combined rating stays private to your organisation.

Upload-Once Certificates

A certificate submitted through the portal can be promoted to the vendor's shared record — AI-read, independently re-validated, provenance-marked, and slotted into an expiry-sorted chain where an old upload can never displace a newer certificate.

Issues, Not Email Chains

Vendors can raise issues and propose updates after submitting; you accept or decline with a full activity trail. Everything lands in the same governed workflow as the rest of your due diligence.

The Difference in Practice

What Changes When the Evidence Comes to You

Without GRCxAI TPRM With GRCxAI TPRM
Annual questionnaire, stale on arrival Continuous evidence, refreshed by scans and registry watches
One opaque risk number Risk / Confidence / Coverage — with the evidence register behind it
Sanctions checked at onboarding Sanctions, insolvency and registry events watched continuously, urgent alerts pushed
"Who owns them?" = ask the vendor Nightly-walked ownership graph, control-weighted, offshore flags
New supplier = email chains Governed request → approve → auto-scan workflow

Pricing

£2,000/month Per Company — Add-on or Standalone

Add TPRM to your GRCxAI platform, or run it as a standalone product with no full-GRC requirement. Either way it's £2,000/month per company entity for unlimited monitored third parties.

Add-on to GRCxAI
+£2,000/mo

Layer TPRM on top of the £2,000 GRC platform. Full suite = £4,000/mo per company.

TPRM Standalone
£2,000/mo

TPRM as a dedicated product, no full GRC platform required. Unlimited monitored third parties.

Book a TPRM Demo

Multi-company groups billed per legal entity. See full pricing →