Vendor risk management

Every vendor.
One decision trail.

CoalDark turns third-party risk into a continuous operating workflow, from the first intake request through assessment, treatment, approval, and recurring review.

PRIORITY QUEUE3 decisions
01
Nexora CloudEvidence gap
Critical82
02
Archer PayrollReview responses
Moderate61
03
Northstar DataApproval due
Moderate46
Portfolio coverage91%

One connected lifecycle

Move risk forward
without losing context.

01

Intake

Capture service context, ownership, data exposure, criticality, and review cadence before work begins.

02

Assess

Send focused questionnaires, collect evidence, and keep every response tied to the vendor record.

03

Treat

Turn gaps into owned findings with clear treatment, due dates, and decision context.

04

Review

Approve, conditionally accept, or decline with a durable record of the rationale.

05

Monitor

Bring overdue reviews, risk movement, and material vendor changes back into the priority queue.

The working system

Built around what analysts actually do.

CoalDark is intentionally narrower than a GRC suite. The product is organized around vendor decisions, not controls, audits, or internal compliance scores.

01

Vendor system of record

Owners, contacts, services, documents, criticality, contracts, and risk history stay together.

02

Questionnaire workflows

Secure external response links, reusable templates, progress tracking, evidence upload, and reminders.

03

Risk intelligence

Composite scoring, AI-assisted response analysis, risk narratives, and a clear priority queue.

04

Findings and treatment

Document gaps, assign accountable owners, track remediation, and preserve accepted-risk decisions.

05

Recurring reviews

Schedule review cycles by vendor criticality and see upcoming or overdue decisions before they drift.

06

Portfolio reporting

Give leadership a concise view of exposure, coverage, high-risk vendors, and review health.

Clear for every role

Shared context.
Focused views.

SECURITY

Prioritize exposure.

See high-risk relationships, incomplete evidence, and treatment that needs escalation.

PROCUREMENT

Unblock onboarding.

Know which requests, responses, and approvals are holding up a vendor decision.

LEADERSHIP

Understand the portfolio.

Review risk concentration and program coverage without stepping into analyst workflow.

MSP / MSSP

Operate across clients.

Switch isolated workspaces and apply one repeatable delivery model across the portfolio.

Put the first vendor in motion

Build a risk program
people will use.

Book a working session