# Third-party management

A third party represents an external organization that provides a product or service, processes data, or otherwise contributes risk to your compliance program.

## What to record

Keep the vendor record focused on the relationship, not only the company name:

- business and security contacts;
- services used by your organization;
- data and operational dependencies;
- DPA, BAA, and compliance-report status;
- parent, child, and subprocessor relationships;
- risk assessments and their expiry dates.

The hierarchy distinguishes a direct vendor from downstream parties. This makes it possible to review concentration and subprocessor risk without flattening every provider into one list.

## Assessment lifecycle

An assessment belongs to a third party and records the review performed for that relationship. Probo can run asynchronous vendor vetting to gather supporting information, but the resulting material still requires human review. Publish a third-party list only after ownership and relationship data are accurate.

## Access and automation

Third-party records are available through the web console and automation interfaces. Use [access reviews](/docs/product/access-review/overview) for identities imported from connected applications; use third-party management for the contractual, privacy, and operational relationship with the provider itself.
