Third-party risk shouldn't go stale between reviews. Foundation keeps the picture current, and cited.
Most third-party risk lives in point-in-time questionnaires and spreadsheets that are out of date the day they are filed. Foundation reads across your vendor records, contracts, and evidence and gives you a current view of exposure across your tiers, the critical vendors first, each finding cited to its source, nothing changed without your sign-off.
Which critical vendors are carrying stale or missing evidence right now?
Foundation on Atlas Bank, an illustrative institution. The data is staged; the interactions are real.
Click a citation · find the fourth party · approve or decline the write
Asked · D. Okafor, TPRM Analyst
Which critical vendors are carrying stale or missing evidence right now?
Corvus Clearing → Northwind Data
Sub-processor · Not in the register
Card tokenisation is sub-contracted to Northwind Data. Northwind is in no vendor record.
It appears once, in the body of a bridge letter. No questionnaire asked, so nothing came back.
Needs action
Every finding is backed by a record you can open. Nothing is asserted without a source.
The remaining 33 critical vendors carry current evidence against their contracted obligations. Each check is in the log.
For risk teams accountable for vendors they can't watch continuously
Chief risk officers, vendor and third-party risk teams, and the compliance functions behind them, at banks and credit unions where the vendor list grew faster than the team. If a concentration or a lapsed control has to be defensible to an examiner, this is built for you.
Point-in-time risk is stale the day it is filed
Questionnaires and evidence capture a vendor on the day they are collected. Between reviews the risk moves, and no one sees it. The annual cycle is not going away; your examiner expects it. What is missing is everything that happens between the cycles.
The picture is always out of date
The SOC 2 that expired in March, the insurance certificate nobody re-collected, the contract clause that no longer matches how the vendor is actually used: it sits in your own files, unnoticed until the next review cycle.
Concentration and fourth parties hide
Your real exposure isn't one vendor; it's the ones many vendors quietly depend on. That fourth-party concentration is exactly what a spreadsheet of first-party questionnaires can't show.
Evidence you can't trace is evidence you can't defend
When an examiner asks how you know a control is in place, 'a vendor said so on a form' isn't an answer. Findings need a source you can open.
How Foundation keeps third-party risk current
Not another questionnaire tool. A layer that reads what you already hold and keeps the risk picture live, cited, and governed.
Same four steps everywhere Foundation runs. Only the domain changes.
What a live third-party view gets you
Answers ready when the exam request arrives
Every finding cites its source, retrievable with who asked, what ran, and which record, in minutes instead of a two-week scramble. What we retain, and how we delete it, is itemized on our trust page.
Concentration you can finally see
Fourth-party dependencies, concentration, and inconsistent tiering surface from the records you already hold, ready for board and committee reporting, not a new data-collection project.
Named on both sides
Your access is governed, and so is ours. Trucast's own access to your environment is a named, scoped, logged seat, not hidden admin: you see who we are, what we can read, and every action we take.
A clean exit
Read access is a credential you revoke in one click. Nothing changed in your systems except what your people approved, each change logged.
See your third-party risk, read live
The fastest way to see the difference is to watch Foundation read a stand-in of your vendor estate and cite each finding, built on representative data, not your live records. You operate it before either side commits, priced up front.