Third-party management
Learn how to record vendor relationships in Probo, including contacts, services, DPAs, subprocessor hierarchies, and third-party risk assessments.
A third party represents an external organization that provides a product or service, processes data, or otherwise contributes risk to your compliance program.
What to record
Section titled “What to record”Keep the vendor record focused on the relationship, not only the company name:
- business and security contacts;
- services used by your organization;
- data and operational dependencies;
- DPA, BAA, and compliance-report status;
- parent, child, and subprocessor relationships;
- risk assessments and their expiry dates.
The hierarchy distinguishes a direct vendor from downstream parties. This makes it possible to review concentration and subprocessor risk without flattening every provider into one list.
Assessment lifecycle
Section titled “Assessment lifecycle”An assessment belongs to a third party and records the review performed for that relationship. Probo can run asynchronous vendor vetting to gather supporting information, but the resulting material still requires human review. Publish a third-party list only after ownership and relationship data are accurate.
To disclose approved downstream providers to customers, see Publish subprocessors in the Compliance Portal.
Access and automation
Section titled “Access and automation”Third-party records are available through the web console and automation interfaces. Use access reviews for identities imported from connected applications; use third-party management for the contractual, privacy, and operational relationship with the provider itself.