Reference · 22 terms


Vendor risk management software glossary

Plain-English definitions covering VRM and TPRM core concepts, the software and data underneath a risk score, relevant frameworks, and the procurement vocabulary that governs vendor sourcing. Written for risk, compliance, and procurement teams who need the vocabulary before a first vendor call.

Core VRM Concepts 8

Continuous Monitoring (Vendor Risk)

Also: Ongoing vendor monitoring, Real-time risk monitoring

The practice of tracking a vendor's risk signals on an ongoing basis, using external data feeds such as security ratings, financial health indicators, sanctions lists, and breach intelligence, rather than relying solely on a periodic (e.g. annual) questionnaire. It is the defining capability that separates modern VRM software from a static, point-in-time vendor check.

Related: Vendor Risk Management (VRM), Security Ratings

See: vendor risk management, vendor risk management software

Fourth-Party Risk

Also: Subprocessor risk, Nth-party risk

Risk that originates not from a direct vendor but from that vendor's own subcontractors or subprocessors. A vendor may have strong controls itself while relying on a fourth party with weaker ones. More mature VRM and TPRM platforms extend visibility beyond the direct vendor relationship to flag this kind of downstream exposure.

Related: Third-Party Risk Management (TPRM), Vendor Risk Management (VRM)

See: vendor risk management, third party risk management software

Inherent Risk vs. Residual Risk

Also: Inherent vs. residual risk

Inherent risk is the level of risk a vendor relationship carries before any controls or mitigations are applied, based on factors like data access and criticality. Residual risk is what remains after the vendor's own controls, contractual safeguards, and monitoring are accounted for. VRM software typically tracks both so a buyer can see how much a vendor's actual controls reduce their starting risk profile.

Related: Vendor Risk Tiering, Vendor Risk Score

See: vendor risk management

Third-Party Risk Management (TPRM)

Also: TPRM

A closely related term to vendor risk management, often used in regulated industries such as banking and insurance, where it signals a more formal, examiner-facing program covering every external party an organization relies on, including vendors, suppliers, contractors, and their subprocessors.

Related: Vendor Risk Management (VRM), Fourth-Party Risk

See: third party risk management software, vendor risk management

Vendor Lifecycle Management

Also: Supplier lifecycle management

Managing a vendor relationship end to end: sourcing and intake, onboarding and due diligence, ongoing performance and risk monitoring, contract renewal, and eventual offboarding. Vendor management platforms are built to support this full lifecycle in one system rather than treating each stage as a separate, disconnected process.

Related: Vendor Management Workflow, Vendor Management Platform (VMP)

See: vendor management platform

Vendor Risk Management (VRM)

Also: VRM

The ongoing practice of identifying, assessing, and monitoring the risk a third-party vendor poses across the full life of the relationship, not just at onboarding. Covers financial, operational, security, and compliance risk, and is increasingly delivered through dedicated software rather than periodic manual review.

Related: Third-Party Risk Management (TPRM), Continuous Monitoring (Vendor Risk), Vendor Risk Tiering

See: vendor risk management, vendor risk management software

Vendor Risk Score

Also: Third-party risk score, Risk rating

A composite rating, often numeric or a letter grade, that summarizes a vendor's assessed risk level based on inputs such as security posture, financial health, compliance status, and questionnaire responses. Scoring methodologies vary significantly by vendor and should always be checked for transparency before being treated as authoritative.

Related: Vendor Risk Tiering, Security Ratings

See: vendor risk management software

Vendor Risk Tiering

Also: Risk-based vendor segmentation

The practice of sorting vendors into risk categories, often labeled critical, high, medium, and low, at intake, so that assessment depth, monitoring frequency, and approval requirements scale with the actual risk a vendor poses rather than applying a uniform process to every vendor regardless of exposure.

Related: Vendor Risk Score, Inherent Risk vs. Residual Risk

See: vendor risk management

Frameworks & Compliance 4

ISO/IEC 27001

Also: ISO 27001

An internationally recognized standard for information security management systems, published by ISO/IEC. A vendor's ISO/IEC 27001 certification status is a commonly requested data point in vendor risk assessments, and legitimate certification requires an audit by an accredited third-party certification body, not a self-declaration.

Related: NIST Cybersecurity Framework (CSF), SIG Questionnaire

See: vendor risk management software

NIST Cybersecurity Framework (CSF)

Also: NIST CSF

A voluntary framework published by the U.S. National Institute of Standards and Technology (NIST) that organizes cybersecurity risk management into core functions. VRM and TPRM platforms frequently map their risk-assessment questions and scoring to NIST CSF so buyers can express findings in a widely-recognized reference structure rather than a proprietary one.

Related: SIG Questionnaire, ISO/IEC 27001

See: vendor risk management software, third party risk management software

Sanctions Screening

Also: Adverse media screening, Watchlist screening

The practice of checking a vendor, and often its beneficial owners, against government sanctions lists (such as OFAC's SDN list), watchlists, and adverse-media sources to confirm the vendor is not a prohibited or high-risk counterparty. Commonly run at onboarding and re-run on a recurring basis as part of continuous monitoring.

Related: Continuous Monitoring (Vendor Risk), Third-Party Risk Management (TPRM)

See: third party risk management software

SIG Questionnaire

Also: Standardized Information Gathering questionnaire

The Standardized Information Gathering (SIG) questionnaire, published and maintained by the Shared Assessments organization, is one of the most widely used standardized templates for assessing a vendor's information security, privacy, and risk-management practices. Many VRM platforms map their automated questionnaire engines directly to the SIG framework to reduce custom questionnaire-building.

Related: Shared Assessment, NIST Cybersecurity Framework (CSF)

See: vendor risk management software

Procurement & Sourcing 4

Procurement Software

Also: Procurement platform

Software that manages the process of sourcing, purchasing, and paying for goods and services on an organization's behalf. Modern procurement suites increasingly include vendor risk or supplier-risk modules alongside core sourcing, contracting, and invoicing functionality, positioning risk as one part of the broader spend and supplier lifecycle rather than a standalone concern.

Related: Source-to-Pay (S2P), Vendor Management Platform (VMP)

See: vendor management platform

RFP (Request for Proposal)

Also: Request for proposal

A formal document a buyer sends to prospective vendors describing a need and requesting a detailed proposal, including approach, pricing, and often responses to specific questions. In vendor sourcing, an RFP is typically the step after initial discovery and shortlisting, used to compare finalist vendors on a consistent, structured basis before a final selection.

Related: Source-to-Pay (S2P), Supplier Relationship Management (SRM)

See: vendor sourcing

Source-to-Pay (S2P)

Also: S2P, Procure-to-pay (P2P), related but narrower

The end-to-end procurement process from identifying and selecting a supplier (sourcing) through contracting, purchasing, receiving, and paying for goods or services. Source-to-pay suites are the broader procurement platforms that vendor-risk modules are often embedded within, distinct from a narrower procure-to-pay (P2P) scope that starts after a supplier is already selected.

Related: Procurement Software, Vendor Management Platform (VMP)

See: vendor management platform, vendor sourcing

Supplier Relationship Management (SRM)

Also: SRM

The discipline, and associated software category, focused on managing and improving ongoing relationships with strategic suppliers: performance reviews, collaboration, and joint planning, alongside risk monitoring. SRM overlaps with vendor management platforms but places more emphasis on the collaborative and performance side of the relationship rather than risk alone.

Related: Vendor Lifecycle Management, Vendor Scorecard

See: vendor management platform

Software & Data 6

Risk Register (Vendor)

Also: Vendor risk log

A structured, maintained record of identified risks associated with a vendor relationship, including the risk description, severity, owner, mitigation status, and review date. VRM software typically maintains this automatically as a byproduct of assessments and monitoring, rather than requiring a separately maintained spreadsheet.

Related: Vendor Risk Tiering, Vendor Scorecard

See: vendor risk management

Security Ratings

Also: Cyber risk ratings, Security posture ratings

An externally-generated, continuously-updated score of an organization's cybersecurity posture, typically derived from non-intrusive, outside-in data collection (open-source intelligence, scanning of public-facing infrastructure) rather than a self-reported questionnaire. Widely used as one input into a vendor's overall risk score by VRM and TPRM platforms.

Related: Vendor Risk Score, Continuous Monitoring (Vendor Risk)

See: vendor risk management software

Shared Assessment

Also: Reusable vendor assessment, Assessment exchange

A vendor risk assessment or security questionnaire response that a vendor completes once and makes available to multiple buyers, instead of re-answering the same, or a substantially similar, questionnaire for every customer that asks. Several VRM platforms operate a shared exchange or network of pre-completed assessments to reduce this duplicated effort on both sides.

Related: SIG Questionnaire, Vendor Risk Score

See: vendor risk management software

Vendor Management Platform (VMP)

Also: VMP, Vendor management software, Vendor management system

Software that manages the full vendor relationship, contracts, performance, spend, and typically a risk module, in one system of record, as distinct from a point-solution VRM tool that focuses on risk alone. Often built as part of, or alongside, a broader procurement or source-to-pay suite.

Related: Vendor Lifecycle Management, Source-to-Pay (S2P)

See: vendor management platform

Vendor Management Workflow

Also: Vendor onboarding workflow

The configured sequence of steps a vendor moves through inside a vendor management or VRM platform, such as intake, tiering, assessment, approval, ongoing monitoring, and periodic re-review, with automated routing, reminders, and escalation replacing manual email and spreadsheet tracking.

Related: Vendor Lifecycle Management, Vendor Management Platform (VMP)

See: vendor management platform, vendor risk management software

Vendor Scorecard

Also: Supplier scorecard

A structured summary of how a vendor is performing against defined criteria, commonly a blend of delivery/SLA performance, quality, cost, and risk posture. Distinct from a pure risk score in that it typically includes operational and performance metrics alongside risk, and is used in vendor reviews and renewal decisions.

Related: Risk Register (Vendor), Vendor Risk Score

See: vendor management platform

VRM software sourcing brief

Occasional emails when we publish a new guide, glossary update, or vendor addition. No spam, unsubscribe anytime.

Single opt-in. We store only your email to send these updates. See ourprivacy notice. This is procurement information, not a compliance guarantee or legal advice.