Reference · 22 terms
Vendor risk management software glossary
Plain-English definitions covering VRM and TPRM core concepts, the software and data underneath a risk score, relevant frameworks, and the procurement vocabulary that governs vendor sourcing. Written for risk, compliance, and procurement teams who need the vocabulary before a first vendor call.
Core VRM Concepts 8
Continuous Monitoring (Vendor Risk)
Also: Ongoing vendor monitoring, Real-time risk monitoring
The practice of tracking a vendor's risk signals on an ongoing basis, using external data feeds such as security ratings, financial health indicators, sanctions lists, and breach intelligence, rather than relying solely on a periodic (e.g. annual) questionnaire. It is the defining capability that separates modern VRM software from a static, point-in-time vendor check.
Related: Vendor Risk Management (VRM), Security Ratings
See: vendor risk management, vendor risk management software
Fourth-Party Risk
Also: Subprocessor risk, Nth-party risk
Risk that originates not from a direct vendor but from that vendor's own subcontractors or subprocessors. A vendor may have strong controls itself while relying on a fourth party with weaker ones. More mature VRM and TPRM platforms extend visibility beyond the direct vendor relationship to flag this kind of downstream exposure.
Related: Third-Party Risk Management (TPRM), Vendor Risk Management (VRM)
See: vendor risk management, third party risk management software
Inherent Risk vs. Residual Risk
Also: Inherent vs. residual risk
Inherent risk is the level of risk a vendor relationship carries before any controls or mitigations are applied, based on factors like data access and criticality. Residual risk is what remains after the vendor's own controls, contractual safeguards, and monitoring are accounted for. VRM software typically tracks both so a buyer can see how much a vendor's actual controls reduce their starting risk profile.
Related: Vendor Risk Tiering, Vendor Risk Score
Third-Party Risk Management (TPRM)
Also: TPRM
A closely related term to vendor risk management, often used in regulated industries such as banking and insurance, where it signals a more formal, examiner-facing program covering every external party an organization relies on, including vendors, suppliers, contractors, and their subprocessors.
Related: Vendor Risk Management (VRM), Fourth-Party Risk
See: third party risk management software, vendor risk management
Vendor Lifecycle Management
Also: Supplier lifecycle management
Managing a vendor relationship end to end: sourcing and intake, onboarding and due diligence, ongoing performance and risk monitoring, contract renewal, and eventual offboarding. Vendor management platforms are built to support this full lifecycle in one system rather than treating each stage as a separate, disconnected process.
Related: Vendor Management Workflow, Vendor Management Platform (VMP)
Vendor Risk Management (VRM)
Also: VRM
The ongoing practice of identifying, assessing, and monitoring the risk a third-party vendor poses across the full life of the relationship, not just at onboarding. Covers financial, operational, security, and compliance risk, and is increasingly delivered through dedicated software rather than periodic manual review.
Related: Third-Party Risk Management (TPRM), Continuous Monitoring (Vendor Risk), Vendor Risk Tiering
See: vendor risk management, vendor risk management software
Vendor Risk Score
Also: Third-party risk score, Risk rating
A composite rating, often numeric or a letter grade, that summarizes a vendor's assessed risk level based on inputs such as security posture, financial health, compliance status, and questionnaire responses. Scoring methodologies vary significantly by vendor and should always be checked for transparency before being treated as authoritative.
Related: Vendor Risk Tiering, Security Ratings
Vendor Risk Tiering
Also: Risk-based vendor segmentation
The practice of sorting vendors into risk categories, often labeled critical, high, medium, and low, at intake, so that assessment depth, monitoring frequency, and approval requirements scale with the actual risk a vendor poses rather than applying a uniform process to every vendor regardless of exposure.
Frameworks & Compliance 4
ISO/IEC 27001
Also: ISO 27001
An internationally recognized standard for information security management systems, published by ISO/IEC. A vendor's ISO/IEC 27001 certification status is a commonly requested data point in vendor risk assessments, and legitimate certification requires an audit by an accredited third-party certification body, not a self-declaration.
Related: NIST Cybersecurity Framework (CSF), SIG Questionnaire
NIST Cybersecurity Framework (CSF)
Also: NIST CSF
A voluntary framework published by the U.S. National Institute of Standards and Technology (NIST) that organizes cybersecurity risk management into core functions. VRM and TPRM platforms frequently map their risk-assessment questions and scoring to NIST CSF so buyers can express findings in a widely-recognized reference structure rather than a proprietary one.
Related: SIG Questionnaire, ISO/IEC 27001
See: vendor risk management software, third party risk management software
Sanctions Screening
Also: Adverse media screening, Watchlist screening
The practice of checking a vendor, and often its beneficial owners, against government sanctions lists (such as OFAC's SDN list), watchlists, and adverse-media sources to confirm the vendor is not a prohibited or high-risk counterparty. Commonly run at onboarding and re-run on a recurring basis as part of continuous monitoring.
Related: Continuous Monitoring (Vendor Risk), Third-Party Risk Management (TPRM)
SIG Questionnaire
Also: Standardized Information Gathering questionnaire
The Standardized Information Gathering (SIG) questionnaire, published and maintained by the Shared Assessments organization, is one of the most widely used standardized templates for assessing a vendor's information security, privacy, and risk-management practices. Many VRM platforms map their automated questionnaire engines directly to the SIG framework to reduce custom questionnaire-building.
Related: Shared Assessment, NIST Cybersecurity Framework (CSF)
Procurement & Sourcing 4
Procurement Software
Also: Procurement platform
Software that manages the process of sourcing, purchasing, and paying for goods and services on an organization's behalf. Modern procurement suites increasingly include vendor risk or supplier-risk modules alongside core sourcing, contracting, and invoicing functionality, positioning risk as one part of the broader spend and supplier lifecycle rather than a standalone concern.
Related: Source-to-Pay (S2P), Vendor Management Platform (VMP)
RFP (Request for Proposal)
Also: Request for proposal
A formal document a buyer sends to prospective vendors describing a need and requesting a detailed proposal, including approach, pricing, and often responses to specific questions. In vendor sourcing, an RFP is typically the step after initial discovery and shortlisting, used to compare finalist vendors on a consistent, structured basis before a final selection.
Related: Source-to-Pay (S2P), Supplier Relationship Management (SRM)
See: vendor sourcing
Source-to-Pay (S2P)
Also: S2P, Procure-to-pay (P2P), related but narrower
The end-to-end procurement process from identifying and selecting a supplier (sourcing) through contracting, purchasing, receiving, and paying for goods or services. Source-to-pay suites are the broader procurement platforms that vendor-risk modules are often embedded within, distinct from a narrower procure-to-pay (P2P) scope that starts after a supplier is already selected.
Related: Procurement Software, Vendor Management Platform (VMP)
Supplier Relationship Management (SRM)
Also: SRM
The discipline, and associated software category, focused on managing and improving ongoing relationships with strategic suppliers: performance reviews, collaboration, and joint planning, alongside risk monitoring. SRM overlaps with vendor management platforms but places more emphasis on the collaborative and performance side of the relationship rather than risk alone.
Related: Vendor Lifecycle Management, Vendor Scorecard
Software & Data 6
Risk Register (Vendor)
Also: Vendor risk log
A structured, maintained record of identified risks associated with a vendor relationship, including the risk description, severity, owner, mitigation status, and review date. VRM software typically maintains this automatically as a byproduct of assessments and monitoring, rather than requiring a separately maintained spreadsheet.
Related: Vendor Risk Tiering, Vendor Scorecard
Security Ratings
Also: Cyber risk ratings, Security posture ratings
An externally-generated, continuously-updated score of an organization's cybersecurity posture, typically derived from non-intrusive, outside-in data collection (open-source intelligence, scanning of public-facing infrastructure) rather than a self-reported questionnaire. Widely used as one input into a vendor's overall risk score by VRM and TPRM platforms.
Related: Vendor Risk Score, Continuous Monitoring (Vendor Risk)
Vendor Management Platform (VMP)
Also: VMP, Vendor management software, Vendor management system
Software that manages the full vendor relationship, contracts, performance, spend, and typically a risk module, in one system of record, as distinct from a point-solution VRM tool that focuses on risk alone. Often built as part of, or alongside, a broader procurement or source-to-pay suite.
Vendor Management Workflow
Also: Vendor onboarding workflow
The configured sequence of steps a vendor moves through inside a vendor management or VRM platform, such as intake, tiering, assessment, approval, ongoing monitoring, and periodic re-review, with automated routing, reminders, and escalation replacing manual email and spreadsheet tracking.
Related: Vendor Lifecycle Management, Vendor Management Platform (VMP)
See: vendor management platform, vendor risk management software
Vendor Scorecard
Also: Supplier scorecard
A structured summary of how a vendor is performing against defined criteria, commonly a blend of delivery/SLA performance, quality, cost, and risk posture. Distinct from a pure risk score in that it typically includes operational and performance metrics alongside risk, and is used in vendor reviews and renewal decisions.
Related: Risk Register (Vendor), Vendor Risk Score
No terms match your search. Try a different word, or ask us directly.
VRM software sourcing brief
Occasional emails when we publish a new guide, glossary update, or vendor addition. No spam, unsubscribe anytime.
Single opt-in. We store only your email to send these updates. See ourprivacy notice. This is procurement information, not a compliance guarantee or legal advice.