CDL Intelligence’s third-party risk management covers the same identify-to-offboard lifecycle described in our TPRM guide — but a vendor’s risk tier lives next to every active contract with that vendor, not in a separate system someone has to remember to check before a renewal.
Vendor onboarding and due diligence
New vendors are logged before any data or system access is granted, with a due-diligence questionnaire delivered through a secure, token-gated vendor portal — vendors respond and upload supporting documents (SOC 2 reports, insurance certificates) directly, without email attachments changing hands.
Seven-dimension risk scoring
Every vendor gets a weighted risk score across seven dimensions: financial (20%), security (20%), privacy (15%), regulatory (15%), OFAC (10%), reputational (10%), and concentration (10%). The weighting is visible, not a black-box number — if a vendor is flagged high-risk, you can see exactly which dimension drove it.
Proactive vendor research, not point-in-time
Rather than only researching a vendor when someone happens to ask, an org-wide scheduled research cadence runs against every approved or pending vendor on a rolling basis. Each cycle is diffed against the last one, and genuinely new findings — a lapsed certification, a regulatory action, a security incident — are classified and surfaced as alerts, so a vendor’s risk profile doesn’t go stale between annual reviews.
Ownership, offboarding, and the contract connection
Vendor relationships are assigned an owner, so risk alerts reach the person actually accountable for that vendor rather than a generic inbox. When a vendor relationship ends, an offboarding checklist tracks access revocation and data-handling obligations — including a structured confirmation of how data was actually deleted — to closure, not just to "email sent."
The part a standalone TPRM tool can’t do: a vendor’s risk tier is visible directly next to every contract governing that relationship, and a converged dataset means a renewal decision can factor in whether anything about the vendor has changed since signature, not just whether the calendar date arrived.