Buying GRC

What should I look for in vendor risk management software?

Short answer

Look for a vendor inventory tiered by the data each vendor can reach, review dates that come due on their own, security questionnaires vendors answer online, and a way to turn a vendor finding into a tracked risk. If you also run SOC 2 or ISO 27001, a GRC platform with vendor risk built in saves you keeping a second inventory in a separate tool.

Last updated

Features that matter

Start with the inventory. Each vendor should carry a criticality tier set by the data and access it has, and a review date the tool raises when it comes due. Questionnaires should go out as a link the vendor answers online and come back scored. You also need a place for each vendor’s SOC 2 report or ISO 27001 certificate, and a way to raise a risk from a finding and give it an owner.

A separate tool or part of your GRC platform

Dedicated third-party risk tools suit large vendor programs with procurement workflows and hundreds of suppliers. A smaller company doing SOC 2 or ISO 27001 usually needs vendor risk as one part of its program, because the auditor tests how you manage vendors. Keeping vendors in the GRC platform puts that evidence next to the rest of it.

How Keel handles vendor risk

Keel ranks each vendor by criticality, sets a review cadence per vendor and shows which reviews are due. Security questionnaires are built from a question library, answered in a portal where the vendor can bring in colleagues, and scored automatically. On paid plans, where each run spends AI credits, Keel drafts a vendor profile from its name and website for you to review, with a suggested tier that a fixed rule raises when the data is sensitive. The same plans can look up a vendor’s public trust page and record the standards it claims, marked unverified, and draft scored risks from a profile for you to add to your risk register. The posture score uses no AI credits and works on every plan: Keel computes it from public DNS and known-exploited-vulnerability signals. Vendor limits are 5 on Free, 20 on Starter, 50 on Pro, and unlimited on Enterprise.

FAQ

Do I need a separate vendor risk tool for SOC 2?

Usually not. SOC 2 expects you to assess and manage the risk your vendors bring, and a GRC platform with a vendor module covers that alongside your other controls. A separate tool earns its cost when the vendor program needs its own procurement workflow.

How do I find the vendors I already use?

Start from what is already public. Keel’s free vendor discovery tool reads a domain’s DNS verification records, authorized email senders, mail routing and content-security policy, and lists the third parties they reveal. It needs no signup and stores nothing. Finance records and single sign-on logs cover the rest.

What should I ask a vendor for?

A current SOC 2 Type II report or ISO 27001 certificate is the strongest evidence. Without one, send a security questionnaire and ask for supporting documents such as policies or a recent penetration test summary.

Next step

Get audit-ready with Keel

The AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.