For the Vendor Risk Manager
Two hundred vendors. One inbox is not a methodology.
A vendor programme is a scheduling problem wearing a risk badge. Compli-Once turns it into campaigns, portals and scores that keep the register honest between cycles.
Questions you can answer on demand
- Which critical vendors are overdue for reassessment right now?
- What does our portfolio risk distribution look like this month versus last quarter?
- Which vendors hold personal data, and which of those are unassessed?
- Which vendor evidence has expired, and what does that do to their score?
Each answer drills to the control, the evidence, the owner and the date.
Today
Monday morning, before Compli-Once
The annual assessment cycle starts with a mail merge and ends with a folder of PDFs nobody scores the same way. The registrar's attestation expired in July; you found out in October.
The register ages between cycles
An annual assessment means eleven months of a register that reflects last year's estate, including vendors you stopped using.
Scoring drifts between reviewers
Without one model, two analysts score the same answer differently and the portfolio view stops meaning anything.
Expired vendor evidence stays green
A registrar's attestation expires quietly. In a folder-based programme, nothing changes colour until someone opens the PDF.
After
What changes
Campaigns, not mail merges
Criticality-tiered register, campaign sends to whole segments, responses through a vendor portal.
Review instead of retype
Vendors upload documents; the AI drafts cited first-pass answers; your team reviews instead of retyping.
Nothing goes stale
Scores update the register automatically, expired vendor evidence flags itself, reassessment runs on a cadence.
The number you take upstairs: portfolio risk distribution and the top-risk vendor list, live.
Your first week
What a proof of concept looks like from your desk
Day 1
Import the vendor list and tier it by criticality; the tier drives cadence and questionnaire depth.
Day 2
Launch a campaign to one segment. Vendors respond through the portal at no cost to them.
Day 4
Review AI-drafted first-pass answers with their citations rather than retyping from the vendor's uploads.
What you own
Artefacts you can produce from the platform
Criticality-tiered vendor register with owners and reassessment dates
Campaign status view showing who has responded and who has not
Per-vendor risk score with the answers and evidence behind it
Portfolio risk distribution and top-risk vendor list, live
The engine
The modules that do the work
Third-Party Risk
Vendor risk on evidence, not email.
OpenAI
Grounded, cited, reviewed.
OpenRisk
Registers and scoring on your methodology.
OpenAssess ten real vendors in the proof of concept.
Frequently asked questions
Do vendors need licences?
No. Vendors respond through the portal at no cost. They upload documents, answer questionnaires and track submissions without buying anything.
Can we use our own questionnaire?
Yes. Your questionnaire, your scoring model. The AI drafts first-pass answers from the vendor's uploaded documents with citations, and your reviewers approve the final answers.
