Skip to content

Products

Compliance Officer Service Expert-led compliance, end to end Compliance Portal Share security documents securely Open-source platform Deploy Probo on your own infrastructure

Resources

Probo stories How teams get compliant with Probo Blog Ideas and guidance from the Probo team Guides & tools Practical compliance guides and free tools Love from Customers What customers say about working with Probo Changelog Latest product updates Download Get the Probo Agent

Company

About The people and vision powering Probo Careers Join the team building Probo Brand assets Official logos and visual resources Security Review our security and compliance posture
Overview Understand Probo and its core concepts Product Explore Probo's GRC capabilities Developers Explore GraphQL, CLI, MCP, n8n, and webhooks Deployment Probo Cloud, self-hosting, and configuration

Explore

GitHub Explore our open-source compliance tools

Third-party management

Track vendors, services, subprocessors, contracts, contacts, and risk assessments

View as Markdown

A third party represents an external organization that provides a product or service, processes data, or otherwise contributes risk to your compliance program.

Keep the vendor record focused on the relationship, not only the company name:

  • business and security contacts;
  • services used by your organization;
  • data and operational dependencies;
  • DPA, BAA, and compliance-report status;
  • parent, child, and subprocessor relationships;
  • risk assessments and their expiry dates.

The hierarchy distinguishes a direct vendor from downstream parties. This makes it possible to review concentration and subprocessor risk without flattening every provider into one list.

An assessment belongs to a third party and records the review performed for that relationship. Probo can run asynchronous vendor vetting to gather supporting information, but the resulting material still requires human review. Publish a third-party list only after ownership and relationship data are accurate.

Third-party records are available through the web console and automation interfaces. Use access reviews for identities imported from connected applications; use third-party management for the contractual, privacy, and operational relationship with the provider itself.