Third Party Risk Management (TPRM)

Assess and monitor your ICT third-party providers: the provider register, DORA Article 31 concentration analysis, and vendor questionnaire campaigns.

TPRM Overview & Questionnaire Campaigns

The Third-Party Risk Management (TPRM) module in Venvera enables your organisation to assess and monitor the cybersecurity posture of your ICT service providers through structured...

9 min

ICT Provider Register

The ICT Providers register (open it from Third-Party Risk ICT Providers ) is the master list of every ICT third-party service provider your organisation relies on. It is the...

1 min

Custom Fields for ICT Providers

Custom fields let your organisation add its own fields to ICT provider records - house conventions like a data-residency region, an internal owner, or an exit-plan status that...

2 min

Access Reviews

Access Reviews is a register of who holds which access rights over your ICT assets, together with the tools to recertify that access on a schedule. It is built for the periodic...

5 min

Concentration Analysis (DORA Article 31)

The Concentration Analysis page ( Third-Party Risk Concentration Analysis ) surfaces the portfolio-level third-party concentration metrics that DORA Article 31 expects supervised...

2 min

Answering Inbound Security Questionnaires

Upload the questionnaire a customer, insurer or auditor sent, draft answers from your controls and the answer library, review, and export the spreadsheet.

3 min