Skip to content
Osintpro

Third Party Risk Management Software With an Evidence Chain

A vendor file needs a document, not a browser history. If the screening was done across six tabs and summarized into a spreadsheet cell, there is nothing in the file that shows what was checked, when, or under what authority.

This page is written for whoever owns that file and gets asked about it during an audit.

See pricing
  • Scope recorded before collection.
  • Passive collection only.
  • Evidence a reviewer can re-run.
  • Built to clear procurement.

The question an auditor actually asks.

Not "do you screen vendors". Everybody says yes. The question is "show me the screening for this vendor, and tell me when it was done".

A spreadsheet row saying "checked, no issues, March" fails that question in three ways. It does not say what was checked, so the coverage is unknown. It does not say when, beyond a month, so the finding cannot be dated against events. And it does not say what the reviewer was authorized to look at, which matters as soon as a vendor is a company with people in it.

The fix is not more diligence. It is producing an artifact at screening time that answers all three, which costs nothing extra if the tool emits it and costs hours if a person assembles it.

The arithmetic on write-up time, shown so you can challenge it.

A risk team screening 120 vendors a year, at 3.5 hours of write-up per vendor, at an $85 loaded hourly cost, spends 420 hours and roughly $35,700 a year turning findings into documents. Team is $4,488 a year. Every input below is an assumption you can change, not a measurement from a customer.

Your numbers

hours a year on write-up

at your loaded cost

working days, at 7.5 hours a day

hours per analyst a year, across

Arithmetic: These are your assumptions, not a measurement we took.

What public-source third party risk management tools actually cover.

Passive collection only. Nothing here touches the vendor's systems, which is what makes it usable before a contract exists and without asking their permission.

Is this counterparty as old as it claims?

Registration date against stated trading history. A domain registered eleven weeks ago behind a company claiming twenty years is the most common signal in invoice and vendor fraud, and it is one lookup.

Can their domain be impersonated?

SPF and DMARC together. A vendor with no enforced DMARC policy is a vendor whose invoices can be spoofed at you, which makes this a finding about your own exposure, not just theirs.

Who controls their infrastructure?

Nameserver delegation and hosting attribution. Concentration risk, and the identity of the vendor behind the vendor.

Is the domain defended?

Transfer locks, expiry date, registry status codes. A business-critical name with no lock and an expiry inside ninety days is an operational risk with a deadline.

What is their public hostname surface?

Certificate transparency and common-label resolution. Administrative and pre-production hostnames resolving in public are a maturity signal.

Who may issue certificates for them?

CAA records. Absent on most estates, and a one-line control when present.

Screen a real vendor domain now.

Pick "Vendor due diligence" as the scope, tick the authorization box, and run a domain. The scope you declare is stamped on the report header before any collection happens, which is the part the audit file needs.

  • It runs in your browser. Queries go to public DNS and RDAP endpoints, not through us.

  • Nothing reaches the subject. The domain you enter is never contacted, probed or scanned.

  • A domain, never a person. There is no input on this panel that accepts an individual.

  • Findings carry their evidence. Raw record, source endpoint and the UTC moment of retrieval.

Domain footprint sweep

passive collection only

stamped on the report
Samples:

Every finding will carry four things

  • 1 Severity. What the record means for the decision in front of you.
  • 2 The raw record. Exactly as the source returned it, unedited.
  • 3 The source endpoint. The request that produced it, so it can be re-run.
  • 4 The UTC retrieval time. Records change. Without this it is an assertion.

Reads dns.google and rdap.org from your browser. Nothing is sent to the domain you enter.

Tick the authorization box, then run the sweep. Enter the domain you are authorized to assess, then run the sweep. Run the sweep. The report lands here.

What ends up in the vendor file.

  1. Step 1

    A scope header written before collection

    Subject, requester, purpose, the basis for the assessment, what was explicitly out of scope, and the method. Chronologically first, which is what makes it a decision rather than a justification.

  2. Step 2

    Findings, each with its own evidence

    A severity, the claim in one plain sentence, the raw record exactly as returned, the endpoint it came from, and the UTC moment of retrieval. A reviewer can re-run any line.

  3. Step 3

    Negative findings, kept rather than dropped

    What was looked for and not found, dated the same way. This is what shows the boundary of the work and stops silence being read as coverage.

  4. Step 4

    A re-runnable record

    Screen the same vendor at renewal, and the difference between the two collections is the finding. That is the part a spreadsheet can never produce.

Questions buyers ask about third party risk software.

Third party risk management is the program that decides whether an outside organization is safe to do business with, and keeps deciding it after the contract is signed. In practice it is a repeatable file per vendor: who they are, what they expose, what was checked, when it was checked and who accepted the residual risk.

No. Vendor management is commercial: contracts, spend, service levels and renewals. Third party risk management is the assurance layer underneath it and asks whether the counterparty introduces security, financial or regulatory exposure. The same vendor list feeds both, but only the risk side has to defend its evidence to an auditor.

In US banking it is a supervised process, not a best practice. Examiners expect documented due diligence proportionate to the criticality of the relationship, kept current through the life of the contract, with the evidence and the decision retrievable on request. That retrievability requirement is why an evidence chain matters more here than the tooling does.

Enterprise TPRM platforms are usually sales-quoted and land in five or six figures a year, priced on vendor count and modules. Our plans are published: $149, $449 and $1,190 a month. The figure worth comparing against either one is what your team currently spends in hours turning findings into a written assessment.

At minimum: the declared scope of what you were authorized to review, the identity evidence establishing the counterparty is a real registered entity, its published technical posture, the date each item was retrieved, the raw record behind each finding, and a named person accepting whatever risk remains. Anything missing one of those is a summary, not a file.

No, and it is not meant to. A questionnaire captures what a vendor asserts about controls you cannot observe from outside. Public-source screening captures what is externally verifiable without asking. The value of running both is that a contradiction between the two is itself a finding, and it is the one worth escalating.

What your own procurement will ask us.

Buying risk software means passing the review you run on everyone else. These are the line items, stated up front.

SSO and SAML

Okta, Entra ID or any SAML 2.0 provider

SCIM provisioning

Joiners and leavers handled by your directory

Roles and permissions

Who may open a case, who may sign one off

Audit log

Every case, every export, every scope declaration

Data residency

Choose where case data is stored

SLA

Written availability and support commitments

DPA

Signed data processing agreement

Invoicing and PO

Annual invoice, purchase order, net terms

What this is not.

This is corporate counterparty screening. It is not a background check on a person, and it never becomes one.

Osintpro is not a consumer reporting agency and its output is not a consumer report. It must not be used for employment, credit, insurance or tenancy decisions regulated under the US Fair Credit Reporting Act or equivalent regimes.

The demo takes a domain and has no input that accepts a person, which is a structural limit rather than a promise. Where individual screening is genuinely in scope, it is authorized and consent-backed corporate screening, and the pre-engagement screening page says so in its first line. The full boundary is published on social media OSINT.

Run one scoped sweep and see what a sourced finding looks like.

The demo is free, it takes a domain and never a person, and it produces the same evidence chain the paid report does.

See how a case runs
  • Passive collection only, from public sources.
  • A domain, never a person. There is no input for one.
  • Your case data stays yours. No card required.

Scope in, evidence out. The demo needs no card.