Fortellar

A questionnaire isn't a vendor program.

Risk-tiered onboarding, evidence-based assessment, and continuous monitoring of vendor posture. The obligations enforced, not filed.

Why This Matters

Most vendor incidents hit companies that already had a program. It just wasn't operating.

The supply-chain breaches you read about happened to companies whose TPRM function was annual questionnaires and a catalog last reviewed two years ago. The attacker didn't care about the SIG Lite on file. They cared that the vendor's posture changed and nobody was watching.

The work is moving the program from documentation to operations: a vendor inventory built around the data and access each vendor touches, risk tiers that drive onboarding diligence, evidence-based assessment, and continuous monitoring of vendor attack surface.

What an annual questionnaire misses
01

Inventory

A catalog last reviewed two years ago, built around names rather than access.

02

Tiering

Every vendor diligenced the same, so effort lands away from the real risk.

03

Evidence

Self-reported answers with nothing behind them, accepted and filed.

04

Posture change

The vendor's environment changed after the questionnaire. Nobody was watching.

Who this is for

Three situations where the vendor program got exposed.

Situation 01

Customer or auditor asked for the vendor program

A new enterprise customer wants to see how you manage your vendors. Their security questionnaire has six pages on it. The auditor expanded scope to TPRM this cycle. The program you have on paper is not the program they expect.

The outcomeA working TPRM program with risk-tiered onboarding, evidence-based assessments, and a vendor inventory the customer and the auditor can walk through.
Situation 02

Vendor incident in the news, board wants assurance

MOVEit. Okta. Snowflake. The latest supply-chain compromise reaches your vendor list. The board asks the question, and 'we have a questionnaire on file' is not the answer they want.

The outcomeA briefing the CISO can deliver: which vendors are affected, what data is exposed, what is being contained, and how the program will catch the next one earlier.
Situation 03

Hundreds of vendors, no real prioritization

The catalog has grown faster than the program. Every vendor gets the same questionnaire and the same review cadence. The critical data-handling vendor and the office-snack-delivery vendor sit at the same tier, which means none of them get real attention.

The outcomeA tiered vendor catalog with diligence and monitoring sized to risk, so the program's attention lands where it matters.
What's included

A vendor risk program that runs on evidence, not questionnaires

A complete vendor inventory, tiered by risk

Every vendor with data, system, or operational access identified. Data type, access scope, and business owner named for each. Catalog updated through procurement, not through annual reconciliation.

A risk tiering model and onboarding playbook

Tiers calibrated to your industry, your data types, and the regulators reaching your environment. Each tier has its own diligence depth, contract requirements, and review cadence.

Evidence-based assessment for tier-1 vendors

SOC 2, ISO 27001, HITRUST reports reviewed for scope, exceptions, and applicability. Architectural and operational diligence on the vendors whose failure would hurt you most.

Contractual security language standardized

MSA, DPA, BAA, and SOW templates with security obligations, breach notification, data handling, audit rights, and termination clauses written for enforcement. Legal and security signed off jointly.

Continuous monitoring on the vendors that matter

Attack-surface intelligence, breach feeds, financial health signals, and posture telemetry for tier-1 and tier-2 vendors. Findings reach the GRC forum on cadence and trigger the playbook when posture changes.

A quarterly TPRM review cadence

Top-risk vendor review, tier changes, contract renewal triggers, incident retrospectives, and program metrics. Run as a working group, reported to the GRC forum, with the executive view ready for the board.

An offboarding discipline

When the relationship ends, data return, access revocation, certificate revocation, and contractual closeout executed and documented. The exit is as managed as the onboarding.

A handoff into ongoing operations

The program operates after we step back. Your team, our managed service, or a hybrid model fits the org. The control set, the inventory, and the monitoring feeds remain the same on either side of the handoff.

How it works

Four phases. Built around your data, your vendors, and the regulators that reach them.

Phase 01

Inventory

Every vendor with data, system, or operational access identified. Data flows mapped. Business owners assigned. The catalog reflects reality, not the procurement system's last sync. Gaps and shadow vendors surfaced.

You walk away with
  • A complete, business-owned vendor inventory.
  • A data flow map showing what each vendor touches.
  • A shadow-vendor register of unsanctioned tools in active use.
Phase 02

Tier

Risk tiering model calibrated to your industry, data types, and regulators. Tiers drive different onboarding diligence, contract language, and monitoring cadence. Existing vendors re-classified against the new model.

You walk away with
  • A tiering model, signed off by security and the data owners.
  • Tier assignments for every vendor in the inventory.
  • Onboarding, contract, and monitoring playbooks per tier.
Phase 03

Assess

Evidence-based assessment of tier-1 and tier-2 vendors. SOC 2 and ISO reports reviewed for scope and exceptions. Architectural and operational diligence on the vendors that matter most. Decisions documented with rationale.

You walk away with
  • A vendor assessment register with sign-off and rationale.
  • Findings register for vendors requiring remediation or compensating controls.
  • Risk-acceptance documentation for residual exposures.
Phase 04

Operate

Continuous monitoring live. Quarterly working group reviewing tier-1 vendors. Annual recertification cadence on schedule. Contract enforcement rehearsed. Offboarding discipline executed when relationships end.

You walk away with
  • A running monitoring feed across tier-1 and tier-2 vendors.
  • A quarterly TPRM working group on cadence.
  • A handoff to your team or to Managed Security Services.
Expertise this work draws on

The components behind a working vendor risk program.

Cybersecurity & Compliance

Vendor Risk Assessment

Evidence-based vendor diligence, including SOC 2 and ISO report review, architectural and operational assessment, and the calibrated questionnaire-plus-evidence model that replaces self-attestation on the vendors that matter.

See expertise
Cybersecurity & Compliance

Contract & DPA Engineering

Security obligations, breach notification windows, data-handling requirements, audit rights, and termination clauses written into MSAs, DPAs, and BAAs. Reviewed by legal and security together, rehearsed for enforcement.

See expertise
Technology & Security Operations

Continuous Attack-Surface Monitoring

Vendor posture telemetry, breach intelligence, certificate hygiene, and dark-web exposure feeds. The signals that move between annual reviews, surfaced to the working group with the playbook attached.

See expertise
Cybersecurity & Compliance

Compliance Framework Alignment

TPRM controls mapped to SOC 2 CC9, HIPAA §164.308(b), NYDFS Part 500.11, ISO 27001 A.5.19-23, PCI 12.8, and the sector-specific rules reaching your vendor estate. Evidence captured against each one.

See expertise

A questionnaire on file is not a program.

Thirty minutes with a senior partner. Bring the vendor catalog, the data they touch, and the framework you report against. We will tell you what a working program would look like.