App navigation: Governance ? Third-Party Inventory
Third-Party Inventory is the central register of all external vendors, suppliers, and partners your organization manages for risk and compliance purposes. Records here are linked to vendor assessments in the Compliance module.
Screen Layout #
Navigate to Governance ? Third-Party Inventory to open the Third-Party Inventory screen. The toolbar provides Refresh, Filter, + Create, and Export.
[Screenshot: Third-Party Inventory screen]
Creating a Third-Party Record #
- Select + on the toolbar.
- The Third-Party Detail wizard opens with five steps:
| Step | What to complete |
|---|---|
| 1 – Third-Party | Vendor name, type, tier (1/2/3), description, and website. |
| 2 – Contract Details | Contract start/end dates, contract value, and renewal terms. |
| 3 – Onboard Questionnaire | Initial due diligence questions completed during vendor onboarding. |
| 4 – Contact | Primary vendor contact name, email, and phone number. |
| 5 – Artifacts | Upload vendor-related documents (contracts, SOC 2 reports, certifications). |
[Screenshot: Third-Party Detail wizard Step 1]
Vendor Tiers #
Vendors are classified by Tier (1, 2, or 3) reflecting their risk level and the depth of due diligence required:
- Tier 1 – highest risk / most critical vendors. Full assessment required.
- Tier 2 – moderate risk. Standard assessment.
- Tier 3 – low risk / commodity vendors. Lightweight review.
Running a Vendor Assessment #
Once a vendor record exists in Third-Party Inventory, you can run a Third Party Assessment against them from Compliance ? Assessments ? Third Party Assessment. The assessment links back to this record via the Third Party Name field. See Complete a Vendor Assessment for the full workflow.
