GRC

Third-Party Risk Without the Spreadsheet Chase

June 10, 2026 TATER Security Team 7 min read

Every framework asks the same uncomfortable question in a different dialect: SOC 2 calls it vendor management, ISO 27001 calls it supplier relationships, and your cyber-insurance renewal calls it third-party risk. Underneath, the requirement is identical — know who your vendors are, know what data they touch, assess them proportionally to their risk, and prove you keep doing it.

Most organizations can produce a vendor list. Far fewer can produce the living program around it, because the program's artifacts scatter: questionnaires in email, SOC 2 reports in a shared drive, contracts in the legal system, complaints in someone's memory.

The Register as the Source of Truth

TATER's vendor register holds each third party with its criticality tier, data classification, production-access flag, and review cadence — the fields that determine how much scrutiny a vendor deserves. A payment processor with production access and confidential data gets annual deep review; the office plant service does not. That proportionality is what assessors look for, and it falls out of the data model instead of a policy PDF.

Questionnaires, Reports, and the Expiry Problem

Security questionnaires issue from TATER, track their response status, and score on return — no more "did they ever answer?" archaeology. Vendor compliance reports (SOC 2, ISO certificates, pen-test attestations) attach to the vendor record with expiry dates, and expiring documents surface before they lapse rather than during an audit. Contracts track alongside, so renewal conversations start with the full picture: risk posture, open complaints, review history, and terms in one view.

100%
of vendor artifacts — questionnaires, certs, contracts, complaints — on one record

Connected to the Rest of the Program

Because vendor management shares TATER's data model, a vendor risk raised during onboarding lands in the same risk register the board reviews, an audit finding about supplier oversight links to the vendors it concerns, and vendor metrics flow into Insights reporting. The module also covers the operational edges most tools ignore: complaint tracking for the vendor that keeps missing SLAs, structured on-site review records for the ones that warrant a visit, and RFP evaluation for choosing the next vendor with the same rigor you apply to the current ones.

Third-party risk is a program, not a list. The difference shows the first time an auditor asks not "who are your vendors?" but "show me the last twelve months of managing them."