Intake
Capture service context, ownership, data exposure, criticality, and review cadence before work begins.
Vendor risk management
CoalDark turns third-party risk into a continuous operating workflow, from the first intake request through assessment, treatment, approval, and recurring review.
One connected lifecycle
Capture service context, ownership, data exposure, criticality, and review cadence before work begins.
Send focused questionnaires, collect evidence, and keep every response tied to the vendor record.
Turn gaps into owned findings with clear treatment, due dates, and decision context.
Approve, conditionally accept, or decline with a durable record of the rationale.
Bring overdue reviews, risk movement, and material vendor changes back into the priority queue.
The working system
CoalDark is intentionally narrower than a GRC suite. The product is organized around vendor decisions, not controls, audits, or internal compliance scores.
Owners, contacts, services, documents, criticality, contracts, and risk history stay together.
Secure external response links, reusable templates, progress tracking, evidence upload, and reminders.
Composite scoring, AI-assisted response analysis, risk narratives, and a clear priority queue.
Document gaps, assign accountable owners, track remediation, and preserve accepted-risk decisions.
Schedule review cycles by vendor criticality and see upcoming or overdue decisions before they drift.
Give leadership a concise view of exposure, coverage, high-risk vendors, and review health.
Clear for every role
See high-risk relationships, incomplete evidence, and treatment that needs escalation.
Know which requests, responses, and approvals are holding up a vendor decision.
Review risk concentration and program coverage without stepping into analyst workflow.
Switch isolated workspaces and apply one repeatable delivery model across the portfolio.