Home / Products / TPRM
Risk & Compliance

Know — and control — your third-party risk.

Onboard vendors with due diligence, run assessments against your controls, and monitor every third party continuously. Turn a compliance headache into a clear, auditable workflow.

Ideal for
Risk, security, procurement
Frameworks
ISO, SOC 2, DPDP
Audit
Full trail
Vendors +12% this week
SLA on track
Why TPRM

Everything you need, in one module

Guided onboarding

Standardise vendor intake with due-diligence questionnaires.

Risk scoring

Quantify each vendor's risk against your control library.

Continuous monitoring

Get alerted when a vendor's risk profile changes.

Audit-ready records

Every assessment and decision is logged and exportable.

TPRM in action
Real-time updates
Built for the job

From vendor intake to continuous oversight

Replace scattered spreadsheets and email chains with a structured lifecycle. Send assessments, collect evidence, calculate risk and schedule reviews — all with a defensible audit trail your auditors will love.

  • Assessment libraryReusable questionnaires mapped to frameworks.
  • Evidence collectionVendors upload documents against each control.
  • Review cadenceAutomatic re-assessment reminders by risk tier.
Features

Powerful out of the box

Every capability your team expects, thoughtfully designed and ready to use on day one.

Vendor onboarding

Intake forms, tiering and ownership from day one.

Control mapping

Map questions to ISO 27001, SOC 2 and DPDP.

Risk register

A live view of inherent and residual risk per vendor.

Alerts & SLAs

Escalations when assessments stall or risk rises.

Board reporting

Portfolio dashboards for leadership and auditors.

Remediation

Track findings to closure with owners and due dates.

How it works

Live in four simple steps

Step 1

Onboard

Capture the vendor and assign a risk tier.

Step 2

Assess

Send questionnaires and collect evidence.

Step 3

Score

Calculate risk and flag gaps automatically.

Step 4

Monitor

Re-assess on schedule and watch for changes.

Who it's for

Trusted across industries

From lean teams to large organisations, TPRM adapts to how you already work.

Banks & NBFCsIT & SaaS firmsHealthcareManufacturingInsuranceFintechEnterprises
Pricing

Simple plans that scale

Start free, then pay only for the seats you need. Bundle with other Umbrella Tech products for suite pricing.

Starter

Get going with the essentials.

₹0/ 14-day trial
  • Core TPRM features
  • Up to 5 users
  • Email support
Start free
Recommended

Growth

For teams that need more power.

₹499/user · mo
  • Everything in Starter
  • Unlimited users
  • Automations & analytics
  • Priority support
Book a demo

Enterprise

Advanced controls and SLAs.

Custom/ let's talk
  • SSO & audit logs
  • Dedicated success manager
  • Custom integrations
Contact sales
FAQ

Questions, answered

Which frameworks are supported?+

Out-of-the-box mappings for ISO 27001, SOC 2, and India's DPDP Act, plus custom control libraries.

Can vendors respond directly?+

Yes. Vendors get a secure portal to answer questionnaires and upload evidence without needing a licence.

How is risk scored?+

You define weightings per control; Umbrella Tech computes inherent and residual risk and tiers vendors automatically.

Is there an audit trail?+

Every action, response and decision is timestamped and exportable for auditors and regulators.

Better together

Pairs well with

TPRM shares data with the rest of the Umbrella Tech suite. Add these to go further.

Ready to try TPRM?

Spin up your workspace in minutes. Free for 14 days — no credit card, no lock-in.