Third-party Risk Management
Vendor registry tiered by risk (critical / high / medium / low) on configurable criteria — extends the master dependency registry
Questionnaire templates aligned to authority requirements and internal policies
Send, score, rate assessments; auto-score objective questions, flag subjective for review; link outcomes to specific Practice Instances and obligations
Onboarding approval workflow with threshold gating
Periodic reassessments at frequency configured per risk tier; API integrations where available, manual tickets otherwise
Scoped vendor portal — vendors see only what's shared with them; every external action logged
Dependency health flags surface the exact Practice Instances affected when any vendor degrades
Escalation and offboarding workflows