Archiving & Restoring
Key Enhancements archive across the platform: third parties, contracts, action plans, risks, issues and finished assessments can all be archived, using the same action and the same behaviour everywhere. hidden, not lost: an archived record leaves the default overview and stops counting toward open-item indicators and dashboard figures. All its data, links and history stay intact, and an "is archived" filter brings it back into view. still in your exports: archived records remain in Excel exports and are marked as archived, so an export stays a complete record. you see what will happen: archiving a third party tells you first how many contracts and action plans go with it, how many of those contracts are still active, and whether it has child third parties. connected records handled deliberately: contracts and action plans belonging to the third party are archived with it. Contracts where it is only a subcontractor stay active. Child third parties are never archived, and you choose whether they stay attached or are detached. Linked issues, risks and assessments are left exactly as they are. all or nothing: if any part of an archive cannot be completed, nothing is archived and you are told why. names never disappear: a record that links to an archived third party shows that third party's real name marked as archived, instead of a blank field. archiving is reversible: restore a third party, contract or action plan from the same menu you archived it from, with everything intact. A contract can be restored while its third party is still archived. restore a user yourself: bring back an archived user without contacting support. Their roles and access return if they were not transferred to someone else; if they were, the user comes back able to sign in and an administrator reassigns the rest. delete your own scheduled assessments: remove a schedule you no longer need, rather than raising a request.

Kamilla Dajani 21 days ago
Roadmap 2026
Archiving & Restoring
Key Enhancements archive across the platform: third parties, contracts, action plans, risks, issues and finished assessments can all be archived, using the same action and the same behaviour everywhere. hidden, not lost: an archived record leaves the default overview and stops counting toward open-item indicators and dashboard figures. All its data, links and history stay intact, and an "is archived" filter brings it back into view. still in your exports: archived records remain in Excel exports and are marked as archived, so an export stays a complete record. you see what will happen: archiving a third party tells you first how many contracts and action plans go with it, how many of those contracts are still active, and whether it has child third parties. connected records handled deliberately: contracts and action plans belonging to the third party are archived with it. Contracts where it is only a subcontractor stay active. Child third parties are never archived, and you choose whether they stay attached or are detached. Linked issues, risks and assessments are left exactly as they are. all or nothing: if any part of an archive cannot be completed, nothing is archived and you are told why. names never disappear: a record that links to an archived third party shows that third party's real name marked as archived, instead of a blank field. archiving is reversible: restore a third party, contract or action plan from the same menu you archived it from, with everything intact. A contract can be restored while its third party is still archived. restore a user yourself: bring back an archived user without contacting support. Their roles and access return if they were not transferred to someone else; if they were, the user comes back able to sign in and an administrator reassigns the rest. delete your own scheduled assessments: remove a schedule you no longer need, rather than raising a request.

Kamilla Dajani 21 days ago
Roadmap 2026
API - Connecting Systems
If your suppliers, contracts or users are maintained in another system, you can keep 3rdRisk in step with it automatically instead of anyone retyping the same information twice. That connection now follows exactly the same rules as working in the platform by hand. Key Enhancements the same result either way: a record created or changed through the connection is checked the same way, and ends up the same, as one entered in the platform. read what you need: pull records out to feed your own reporting, warehouse or internal tools. change everything or just one field: send a complete record, or only what has changed. clearer errors: when something is rejected, the response names the fields you sent, so your team can see what to correct. available now: third parties, risks, action plans, frameworks, controls, issues, users and your organisation structure. coming next: contracts, assessments, questions, and AI risk and country risk profiles, followed by documents, schedules, questionnaires, sanctions and news monitoring.

Kamilla Dajani 21 days ago
Roadmap 2026
API - Connecting Systems
If your suppliers, contracts or users are maintained in another system, you can keep 3rdRisk in step with it automatically instead of anyone retyping the same information twice. That connection now follows exactly the same rules as working in the platform by hand. Key Enhancements the same result either way: a record created or changed through the connection is checked the same way, and ends up the same, as one entered in the platform. read what you need: pull records out to feed your own reporting, warehouse or internal tools. change everything or just one field: send a complete record, or only what has changed. clearer errors: when something is rejected, the response names the fields you sent, so your team can see what to correct. available now: third parties, risks, action plans, frameworks, controls, issues, users and your organisation structure. coming next: contracts, assessments, questions, and AI risk and country risk profiles, followed by documents, schedules, questionnaires, sanctions and news monitoring.

Kamilla Dajani 21 days ago
Roadmap 2026
AI findings across your portfolio
Working out whether something matters means correlating a supplier's assessment history, recent news, sanction status and contract state by hand, across several screens. And when one event affects many suppliers, it arrives as many separate alerts rather than one piece of information. Key Enhancements the platform notices on its own: it reviews a third party or a country when something changes, such as a news item, a completed assessment, a sanction hit, a tier change or a contract update, and also sweeps overnight for patterns that only appear when looking at everything at once. one insight instead of many alerts: when a single event affects a group of your suppliers, you get one finding covering the group, telling you how many are affected and which ones, rather than a separate alert per supplier. every finding shows its working: open any finding to see what the AI was asked, which of your records and sources it consulted, and what it concluded at each step. evidence you can follow: findings cite the news items, sanction reports, assessments and contracts they rest on. you decide what happens next: acknowledge, dismiss or comment on a finding. The history is kept and cannot be altered afterwards. shaped by your priorities: the AI works from your own settings, including the countries that matter to you, the regulations you follow and your industry focus, using the same prompt configuration as the rest of the platform's AI. Sits behind the AI setting, off until you turn it on.

Kamilla Dajani 21 days ago
Roadmap 2026
AI findings across your portfolio
Working out whether something matters means correlating a supplier's assessment history, recent news, sanction status and contract state by hand, across several screens. And when one event affects many suppliers, it arrives as many separate alerts rather than one piece of information. Key Enhancements the platform notices on its own: it reviews a third party or a country when something changes, such as a news item, a completed assessment, a sanction hit, a tier change or a contract update, and also sweeps overnight for patterns that only appear when looking at everything at once. one insight instead of many alerts: when a single event affects a group of your suppliers, you get one finding covering the group, telling you how many are affected and which ones, rather than a separate alert per supplier. every finding shows its working: open any finding to see what the AI was asked, which of your records and sources it consulted, and what it concluded at each step. evidence you can follow: findings cite the news items, sanction reports, assessments and contracts they rest on. you decide what happens next: acknowledge, dismiss or comment on a finding. The history is kept and cannot be altered afterwards. shaped by your priorities: the AI works from your own settings, including the countries that matter to you, the regulations you follow and your industry focus, using the same prompt configuration as the rest of the platform's AI. Sits behind the AI setting, off until you turn it on.

Kamilla Dajani 21 days ago
Roadmap 2026
Third-party Catalogue
Working in the catalogue takes more clicks than it should, duplicates get created, and there is no way to produce a shareable summary of a third party's risk. Key Enhancements click a name to open it: clicking a name or title opens that record directly, across the catalogue, contracts, issues, action plans, risks, controls and assessments. A third-party name opens its cockpit. The ID still opens messages and the audit log. third-party risk report: generate a report for one third party, viewable on screen and downloadable as a PDF, covering its risk profile by component with a short summary of each. ecosystem risk report: select any number of third parties and produce one portfolio report covering overall risk, the highest-risk third parties, hotspots by domain, sector and geography, data gaps and recommended next steps. duplicate warning when adding: a matching VAT, DUNS, KvK or internal reference blocks the save and names the existing record. A matching name and country shows a warning without blocking. update existing records on bulk import: the import checks and matches the file first, then shows you what will change so you can accept or skip each match. Only values that differ are written, blanks never clear a field, and every update is logged. link a risk without leaving the catalogue: search existing risks or create a new one on the spot, the same way linking an issue already works. next review date column: see and sort by when each third party is next due for review, without opening each record.

Kamilla Dajani 21 days ago
Roadmap 2026
Third-party Catalogue
Working in the catalogue takes more clicks than it should, duplicates get created, and there is no way to produce a shareable summary of a third party's risk. Key Enhancements click a name to open it: clicking a name or title opens that record directly, across the catalogue, contracts, issues, action plans, risks, controls and assessments. A third-party name opens its cockpit. The ID still opens messages and the audit log. third-party risk report: generate a report for one third party, viewable on screen and downloadable as a PDF, covering its risk profile by component with a short summary of each. ecosystem risk report: select any number of third parties and produce one portfolio report covering overall risk, the highest-risk third parties, hotspots by domain, sector and geography, data gaps and recommended next steps. duplicate warning when adding: a matching VAT, DUNS, KvK or internal reference blocks the save and names the existing record. A matching name and country shows a warning without blocking. update existing records on bulk import: the import checks and matches the file first, then shows you what will change so you can accept or skip each match. Only values that differ are written, blanks never clear a field, and every update is logged. link a risk without leaving the catalogue: search existing risks or create a new one on the spot, the same way linking an issue already works. next review date column: see and sort by when each third party is next due for review, without opening each record.

Kamilla Dajani 21 days ago
Roadmap 2026
Contract Management
Contract oversight does not scale. Review procedures are retyped per contract, renewal deadlines surface too late to act on, and a contract can only be opened in a modal with no single view of it. Key Enhancements warnings while you can still act: notifications before a contract's notice deadline or end date, by email and in the platform, to the contract manager and business owner. The expiry window is configurable and defaults to 90 days. contract duration types: mark a contract as indefinite, fixed-term with tacit renewal, or fixed-term without. Contracts that renew tacitly have their end date extended automatically; contracts that expire become inactive when the date passes. Both are recorded in the audit log. notice periods on every contract: a notice period in days, optional, no longer limited to DORA contracts. The renew or exit reminder now fires ahead of the notice period rather than the end date, and the contract timeline shows time until notice separately from notice until end. reusable review templates: a library of review procedures in Configuration, usable on contracts and third parties. Each review gets a title and a criticality, reviews can be removed, and editing a template can push the change to reviews already open. a contract cockpit: a page per contract showing its master data alongside its notes, documents, issues, risks, assessments, reviews, subcontractors, internal controls, related contracts and security posture, with a timeline of the whole contract. contract-level assessment contacts: an optional email per contract, automatically copied in when you send an assessment for that contract.

Kamilla Dajani 21 days ago
Roadmap 2026
Contract Management
Contract oversight does not scale. Review procedures are retyped per contract, renewal deadlines surface too late to act on, and a contract can only be opened in a modal with no single view of it. Key Enhancements warnings while you can still act: notifications before a contract's notice deadline or end date, by email and in the platform, to the contract manager and business owner. The expiry window is configurable and defaults to 90 days. contract duration types: mark a contract as indefinite, fixed-term with tacit renewal, or fixed-term without. Contracts that renew tacitly have their end date extended automatically; contracts that expire become inactive when the date passes. Both are recorded in the audit log. notice periods on every contract: a notice period in days, optional, no longer limited to DORA contracts. The renew or exit reminder now fires ahead of the notice period rather than the end date, and the contract timeline shows time until notice separately from notice until end. reusable review templates: a library of review procedures in Configuration, usable on contracts and third parties. Each review gets a title and a criticality, reviews can be removed, and editing a template can push the change to reviews already open. a contract cockpit: a page per contract showing its master data alongside its notes, documents, issues, risks, assessments, reviews, subcontractors, internal controls, related contracts and security posture, with a timeline of the whole contract. contract-level assessment contacts: an optional email per contract, automatically copied in when you send an assessment for that contract.

Kamilla Dajani 21 days ago
Roadmap 2026
Access Domains
Any user could see any third party, regardless of whether it was their responsibility. Access can now be limited per third party, and will become more granular. Key Enhancements access per third party: a user only sees the third parties they have access to. Restricted ones do not appear in searches, dropdowns, reports or dashboards, cannot be linked to assessments, issues or action plans, and are refused if reached by direct link. access per risk domain: restrict access to individual risk domains within a third party, so a team responsible for one domain cannot edit another team's, on the same third party. start with no access: add a user to specific third parties only, so they see nothing by default. The existing model, where access to everything is narrowed down per third party, stays available. a cleaner permission list: role management shows only the permissions for modules and features active on your environment. Nothing is removed, and roles keep permissions that are hidden.

Kamilla Dajani 21 days ago
Roadmap 2026
Access Domains
Any user could see any third party, regardless of whether it was their responsibility. Access can now be limited per third party, and will become more granular. Key Enhancements access per third party: a user only sees the third parties they have access to. Restricted ones do not appear in searches, dropdowns, reports or dashboards, cannot be linked to assessments, issues or action plans, and are refused if reached by direct link. access per risk domain: restrict access to individual risk domains within a third party, so a team responsible for one domain cannot edit another team's, on the same third party. start with no access: add a user to specific third parties only, so they see nothing by default. The existing model, where access to everything is narrowed down per third party, stays available. a cleaner permission list: role management shows only the permissions for modules and features active on your environment. Nothing is removed, and roles keep permissions that are hidden.

Kamilla Dajani 21 days ago
Roadmap 2026
Connect Your AI Assistant to 3rdRisk
Finding data means building filters on each page. This lets you connect an AI assistant instead, and ask it directly. Key Enhancements connect your own assistant: link a tool such as Claude Desktop or ChatGPT to 3rdRisk, authorising it once through a consent screen. read and update your records: list, open, create and update third parties, issues, action plans and framework sections. Risks, contracts and assessments follow. your permissions apply: every request runs through the same permission checks, validation and access restrictions as the interface. Nothing is deleted through this route. the same filters you already use: each list can be narrowed by the same filters as its page in the platform. explicit access: a connection has to be granted permission to use this specifically, so an ordinary token cannot reach it.

Kamilla Dajani 21 days ago
Roadmap 2026
Connect Your AI Assistant to 3rdRisk
Finding data means building filters on each page. This lets you connect an AI assistant instead, and ask it directly. Key Enhancements connect your own assistant: link a tool such as Claude Desktop or ChatGPT to 3rdRisk, authorising it once through a consent screen. read and update your records: list, open, create and update third parties, issues, action plans and framework sections. Risks, contracts and assessments follow. your permissions apply: every request runs through the same permission checks, validation and access restrictions as the interface. Nothing is deleted through this route. the same filters you already use: each list can be narrowed by the same filters as its page in the platform. explicit access: a connection has to be granted permission to use this specifically, so an ordinary token cannot reach it.

Kamilla Dajani 21 days ago
Roadmap 2026
Ecosystem Assessment Improvements
Recurring assessments made third parties re-enter answers they had already given, and reviewers were fixed on the questionnaire rather than the assessment. These changes shorten the questionnaire for suppliers and give your team more control over each round. Key Enhancements build and edit in the platform: create questionnaires from Content β Questionnaires in the interface rather than through Excel. autofill on re-assessment: where a third party has completed the same questionnaire before, they are prompted per questionnaire to fill in their previous answers and review them. Answers only, not comments or attachments. optional questions: define whether a question must be answered or can be skipped. conditional questions: a question can stay hidden until an earlier one is answered a particular way. Hidden questions are cleared, skipped in scoring and left out of exports. a copy for the third party: on finishing, they can download their answers as a PDF or have it emailed, organised by questionnaire, domain, question, answer, comments and attachment, and styled to your branding. Emailed copies are password-protected. document types per question: a question accepts only the document types you allow. reviewers per assessment: assign the reviewer on the assessment rather than the questionnaire, changeable while in flight but not removable once they have taken review actions. a reason when reverting: sending an assessment back from verification to review prompts an optional comment, shown to the reviewer and recorded in the audit log. cancelled assessments stay readable: open a cancelled assessment read-only, the same as a finished one. schedule the next round as you finish: set an optional next-assessment date at finalisation, editable or removable afterwards.

Kamilla Dajani 21 days ago
Roadmap 2026
Ecosystem Assessment Improvements
Recurring assessments made third parties re-enter answers they had already given, and reviewers were fixed on the questionnaire rather than the assessment. These changes shorten the questionnaire for suppliers and give your team more control over each round. Key Enhancements build and edit in the platform: create questionnaires from Content β Questionnaires in the interface rather than through Excel. autofill on re-assessment: where a third party has completed the same questionnaire before, they are prompted per questionnaire to fill in their previous answers and review them. Answers only, not comments or attachments. optional questions: define whether a question must be answered or can be skipped. conditional questions: a question can stay hidden until an earlier one is answered a particular way. Hidden questions are cleared, skipped in scoring and left out of exports. a copy for the third party: on finishing, they can download their answers as a PDF or have it emailed, organised by questionnaire, domain, question, answer, comments and attachment, and styled to your branding. Emailed copies are password-protected. document types per question: a question accepts only the document types you allow. reviewers per assessment: assign the reviewer on the assessment rather than the questionnaire, changeable while in flight but not removable once they have taken review actions. a reason when reverting: sending an assessment back from verification to review prompts an optional comment, shown to the reviewer and recorded in the audit log. cancelled assessments stay readable: open a cancelled assessment read-only, the same as a finished one. schedule the next round as you finish: set an optional next-assessment date at finalisation, editable or removable afterwards.

Kamilla Dajani 21 days ago
Roadmap 2026
Sorting & Filtering Consistency
To make lists behave predictably wherever a user happens to be working, sorting and filtering will be standardised across every module in the platform. Today each list carries its own subset of sortable columns and its own incomplete filter set, so knowledge gained on one page does not transfer to the next and finding records depends on which page you are on. Key Enhancements full column sorting: every column where sorting is meaningful becomes sortable ascending and descending, across third parties, contracts, ecosystem assessments, questionnaires, schedules, risks, frameworks, controls, issues, action plans and control assessments. custom field filtering: custom fields can be marked as filterable and then used to narrow third party and contract lists on empty, not empty, or matching values, with multiple conditions combined. complete filter sets: filters missing today are added per module, including treatment, contract, risk officer, reporter and specific measures on the risk register, framework section, manager and risk officer on frameworks, and frequency, tags and scheduled items on the schedule page. presence filters: quick checks for records that have action plans, issues, controls or measures, so coverage gaps are visible without opening records. aligned internal control filters: one consistent set across the controls page, all four assessment stages and the dashboard, including correction of two filters that are currently mislabelled or broken. case-insensitive matching: filter searches return the same results regardless of capitalisation, so "erp" finds "ERP". This update will reduce the time users spend locating records, make list behaviour predictable from one module to the next, and remove a source of silently incorrect exports.

Kamilla Dajani 21 days ago
Roadmap 2026
Sorting & Filtering Consistency
To make lists behave predictably wherever a user happens to be working, sorting and filtering will be standardised across every module in the platform. Today each list carries its own subset of sortable columns and its own incomplete filter set, so knowledge gained on one page does not transfer to the next and finding records depends on which page you are on. Key Enhancements full column sorting: every column where sorting is meaningful becomes sortable ascending and descending, across third parties, contracts, ecosystem assessments, questionnaires, schedules, risks, frameworks, controls, issues, action plans and control assessments. custom field filtering: custom fields can be marked as filterable and then used to narrow third party and contract lists on empty, not empty, or matching values, with multiple conditions combined. complete filter sets: filters missing today are added per module, including treatment, contract, risk officer, reporter and specific measures on the risk register, framework section, manager and risk officer on frameworks, and frequency, tags and scheduled items on the schedule page. presence filters: quick checks for records that have action plans, issues, controls or measures, so coverage gaps are visible without opening records. aligned internal control filters: one consistent set across the controls page, all four assessment stages and the dashboard, including correction of two filters that are currently mislabelled or broken. case-insensitive matching: filter searches return the same results regardless of capitalisation, so "erp" finds "ERP". This update will reduce the time users spend locating records, make list behaviour predictable from one module to the next, and remove a source of silently incorrect exports.

Kamilla Dajani 21 days ago
Roadmap 2026
Value Intelligence Framework - Gamification
To enhance engagement and compliance, gamification elements will be introduced in third-party risk management (TPRM) and internal control processes. This will encourage user participation, improve adherence to risk policies, and create a more interactive experience. Key Enhancements achievement tracking: users earn badges or points for completing assessments, mitigating risks, or improving control effectiveness. leaderboards & progress indicators: visibility into team and individual performance to drive engagement. streaks & rewards: incentives for maintaining consistent compliance and timely risk management actions. interactive challenges: scenario-based quizzes or simulated risk events to reinforce best practices. This update will increase user motivation, improve risk awareness, and drive more proactive risk and control management

Kamilla Dajani 21 days ago
Roadmap 2026
Value Intelligence Framework - Gamification
To enhance engagement and compliance, gamification elements will be introduced in third-party risk management (TPRM) and internal control processes. This will encourage user participation, improve adherence to risk policies, and create a more interactive experience. Key Enhancements achievement tracking: users earn badges or points for completing assessments, mitigating risks, or improving control effectiveness. leaderboards & progress indicators: visibility into team and individual performance to drive engagement. streaks & rewards: incentives for maintaining consistent compliance and timely risk management actions. interactive challenges: scenario-based quizzes or simulated risk events to reinforce best practices. This update will increase user motivation, improve risk awareness, and drive more proactive risk and control management

Kamilla Dajani 21 days ago
Roadmap 2026
Risk domains configuration
To let organisations express risk in their own terms, risk domains will become configurable per domain rather than fixed by the platform. Today every domain uses the same four level names and the same four colours, drawn from the platform instead of the customer's own risk taxonomy. In addition, the lowest score an answer can carry is 1, so no answer can take a domain out of scope and suppliers end up scored on domains that do not apply to them. Key Enhancements per-domain level naming: Low, Medium, High and Critical can be renamed to an organisation's own terminology, independently for each risk domain. configurable colours: each level's colour is set from a colour picker and applied wherever that domain's score appears, including PDF reports and exports. translatable names: level names are held per language, so each language carries its own wording, with uniqueness checked per language within a domain. independent domains: two domains can label the same level differently, and editing one never affects another. Existing domains keep current names and colours until edited, and nothing is applied until saved. calculation safety: renaming or recolouring a level never alters a score or a risk calculation. expanded answer scoring: answer scores become a searchable list running from Not applicable through 0 to 100, replacing a free number field with a minimum of 1. zero scoring: an answer scored 0 keeps its question in the calculation and contributes nothing to the total. not applicable scoping: an answer marked Not applicable removes its question from the calculation entirely, so a single answer, such as confirming a supplier processes no personal data, can take a whole domain out of scope for that supplier. clear empty state: a domain with nothing left to score shows greyed out in the catalogue rather than as a low score. unchanged for assessors: answers are still chosen by their wording, with changes confined to configuration. This update will let each customer align risk domains with their own taxonomy and language, and stop suppliers being scored against domains that do not apply to them.

Kamilla Dajani 21 days ago
Roadmap 2026
Risk domains configuration
To let organisations express risk in their own terms, risk domains will become configurable per domain rather than fixed by the platform. Today every domain uses the same four level names and the same four colours, drawn from the platform instead of the customer's own risk taxonomy. In addition, the lowest score an answer can carry is 1, so no answer can take a domain out of scope and suppliers end up scored on domains that do not apply to them. Key Enhancements per-domain level naming: Low, Medium, High and Critical can be renamed to an organisation's own terminology, independently for each risk domain. configurable colours: each level's colour is set from a colour picker and applied wherever that domain's score appears, including PDF reports and exports. translatable names: level names are held per language, so each language carries its own wording, with uniqueness checked per language within a domain. independent domains: two domains can label the same level differently, and editing one never affects another. Existing domains keep current names and colours until edited, and nothing is applied until saved. calculation safety: renaming or recolouring a level never alters a score or a risk calculation. expanded answer scoring: answer scores become a searchable list running from Not applicable through 0 to 100, replacing a free number field with a minimum of 1. zero scoring: an answer scored 0 keeps its question in the calculation and contributes nothing to the total. not applicable scoping: an answer marked Not applicable removes its question from the calculation entirely, so a single answer, such as confirming a supplier processes no personal data, can take a whole domain out of scope for that supplier. clear empty state: a domain with nothing left to score shows greyed out in the catalogue rather than as a low score. unchanged for assessors: answers are still chosen by their wording, with changes confined to configuration. This update will let each customer align risk domains with their own taxonomy and language, and stop suppliers being scored against domains that do not apply to them.

Kamilla Dajani 21 days ago
Roadmap 2026
Ecosystem News Monitoring
To widen what the platform watches and cut down how much users have to read, news monitoring will cover countries and industries as well as individual suppliers, with AI summaries and closer links to daily work. Today news arrives one supplier at a time in a pop-up, a large supplier can produce items hourly, and risk tied to a country or a sector is not watched at all. Key Enhancements country risk map: a world map on the Ecosystem page, each country coloured by its risk level. Click a country to see its risk profile and recent news. industry view: a list of each sector with its risk level, how many of your third parties sit in it, its latest news, and how many different sources reported it. act on a country or sector: raise a risk or an issue for a whole country or sector, or send an assessment to every third party in an industry in one go. daily summaries: a summary of the past 24 hours of news for a third party, written overnight so it is ready when you open the record. You can ask for a new one, and countries get the same summary. dashboard overview: one widget showing the whole news picture. news on the record: news moves out of its pop-up and onto the third party itself, with its column nearer the front of the catalogue. issues from news: create an issue from a news item with type, deadline, location and criticality already filled in, or link the item to an issue you already have. tags and filters: tag news items and filter by tag, both in the news list and in the catalogue. notes on news: keep notes against a news item, with the author and date saved. news behind an issue: see the news that led to an issue from the issue itself. two sources, one list: news from RID shown alongside your existing Business Radar feed. Country and industry views need AI enabled. This update will show risk tied to countries and sectors that is invisible today, reduce how much news each person reads, and keep news, decisions and follow-up on the same record.

Kamilla Dajani 21 days ago
Roadmap 2026
Ecosystem News Monitoring
To widen what the platform watches and cut down how much users have to read, news monitoring will cover countries and industries as well as individual suppliers, with AI summaries and closer links to daily work. Today news arrives one supplier at a time in a pop-up, a large supplier can produce items hourly, and risk tied to a country or a sector is not watched at all. Key Enhancements country risk map: a world map on the Ecosystem page, each country coloured by its risk level. Click a country to see its risk profile and recent news. industry view: a list of each sector with its risk level, how many of your third parties sit in it, its latest news, and how many different sources reported it. act on a country or sector: raise a risk or an issue for a whole country or sector, or send an assessment to every third party in an industry in one go. daily summaries: a summary of the past 24 hours of news for a third party, written overnight so it is ready when you open the record. You can ask for a new one, and countries get the same summary. dashboard overview: one widget showing the whole news picture. news on the record: news moves out of its pop-up and onto the third party itself, with its column nearer the front of the catalogue. issues from news: create an issue from a news item with type, deadline, location and criticality already filled in, or link the item to an issue you already have. tags and filters: tag news items and filter by tag, both in the news list and in the catalogue. notes on news: keep notes against a news item, with the author and date saved. news behind an issue: see the news that led to an issue from the issue itself. two sources, one list: news from RID shown alongside your existing Business Radar feed. Country and industry views need AI enabled. This update will show risk tied to countries and sectors that is invisible today, reduce how much news each person reads, and keep news, decisions and follow-up on the same record.

Kamilla Dajani 21 days ago
Roadmap 2026
Mass Operations
To cut down repeated manual editing, bulk actions will expand from starting assessments and generating risk profiles to updating fields across many records at once. Today you can act on a selection in a few ways, but any actual edit is made one record at a time. Key Enhancements bulk field updates: available on third parties, contracts, ecosystem assessments and controls. Select the records, choose Update fields, and set the new values once. stepped flow: confirm the records you picked, choose which fields to change, then enter the values. Records can be added or removed inside the flow, so a mis-click on the overview does not send you back to the start. sensible field list: only fields that make sense across several records are offered. Names, addresses, contact details and financial values stay per record. Your custom fields are included. checked before writing: values are validated before anything is saved, so a mistake changes nothing. runs in the background: work happens in batches so you can carry on, and you are told in the platform and by email when it finishes. failures you can retry: if some records fail you are told how many, and can reopen the flow with only those. full audit trail: every record changed is written to the audit log exactly as a single edit would be. LEI lookup for DORA: find and fill LEI numbers for DORA third parties, looked up by name and filled only where the registered name matches. more bulk actions: archive internal control assessments, cancel or archive external form submissions, create a default contract for third parties without one, and invite users from a spreadsheet rather than one at a time. Permission to update is checked for each record, not once for the whole selection. This update will remove hours of repeated editing for teams managing large portfolios, and make routine changes safe to apply at scale.

Kamilla Dajani 21 days ago
Roadmap 2026
Mass Operations
To cut down repeated manual editing, bulk actions will expand from starting assessments and generating risk profiles to updating fields across many records at once. Today you can act on a selection in a few ways, but any actual edit is made one record at a time. Key Enhancements bulk field updates: available on third parties, contracts, ecosystem assessments and controls. Select the records, choose Update fields, and set the new values once. stepped flow: confirm the records you picked, choose which fields to change, then enter the values. Records can be added or removed inside the flow, so a mis-click on the overview does not send you back to the start. sensible field list: only fields that make sense across several records are offered. Names, addresses, contact details and financial values stay per record. Your custom fields are included. checked before writing: values are validated before anything is saved, so a mistake changes nothing. runs in the background: work happens in batches so you can carry on, and you are told in the platform and by email when it finishes. failures you can retry: if some records fail you are told how many, and can reopen the flow with only those. full audit trail: every record changed is written to the audit log exactly as a single edit would be. LEI lookup for DORA: find and fill LEI numbers for DORA third parties, looked up by name and filled only where the registered name matches. more bulk actions: archive internal control assessments, cancel or archive external form submissions, create a default contract for third parties without one, and invite users from a spreadsheet rather than one at a time. Permission to update is checked for each record, not once for the whole selection. This update will remove hours of repeated editing for teams managing large portfolios, and make routine changes safe to apply at scale.

Kamilla Dajani 21 days ago
Roadmap 2026
Tag Management
To keep labels consistent across the platform, tags will move into Configuration and extend to documents. Today tags can only be created while editing a record, so the same idea ends up spelled three different ways and nobody can tidy it up afterwards. Key Enhancements one page for every tag: a single list in Configuration showing all tags, filtered by where they are used: third parties, contracts, controls, issues, risk register and frameworks. create without a record: add a new tag directly, without opening a record first. safe renaming: rename a tag and every record carrying it follows, so nothing loses its label. archiving with a guard: archive tags you have finished with. A tag still in use cannot be archived, and you are told how many records are holding it. nothing deleted outright: archived tags stop appearing in pickers and filters, but are never removed. permission controlled: access to tag management is governed by its own permission. tags on documents: tag a document as you upload it or later, with as many tags as it needs. document filtering: tags appear in document lists and can be filtered on, useful where the list of document types has grown unwieldy, since a tag carries your own terminology without adding another type. This update will cut duplicate and inconsistent tags, give administrators one place to tidy up safely, and make documents easier to find without expanding the list of document types.

Kamilla Dajani 21 days ago
Roadmap 2026
Tag Management
To keep labels consistent across the platform, tags will move into Configuration and extend to documents. Today tags can only be created while editing a record, so the same idea ends up spelled three different ways and nobody can tidy it up afterwards. Key Enhancements one page for every tag: a single list in Configuration showing all tags, filtered by where they are used: third parties, contracts, controls, issues, risk register and frameworks. create without a record: add a new tag directly, without opening a record first. safe renaming: rename a tag and every record carrying it follows, so nothing loses its label. archiving with a guard: archive tags you have finished with. A tag still in use cannot be archived, and you are told how many records are holding it. nothing deleted outright: archived tags stop appearing in pickers and filters, but are never removed. permission controlled: access to tag management is governed by its own permission. tags on documents: tag a document as you upload it or later, with as many tags as it needs. document filtering: tags appear in document lists and can be filtered on, useful where the list of document types has grown unwieldy, since a tag carries your own terminology without adding another type. This update will cut duplicate and inconsistent tags, give administrators one place to tidy up safely, and make documents easier to find without expanding the list of document types.

Kamilla Dajani 21 days ago
Roadmap 2026
AI-Powered Tier Discovery
To make risk beyond your direct suppliers visible, the catalogue will show supply chain relationships as a hierarchy and AI will propose the suppliers your third parties are likely to depend on. Today the catalogue lists the companies you contract with but says much less about who they in turn depend on, so risk sitting one step further out stays invisible until something breaks. Key Enhancements hierarchy in the catalogue: direct suppliers are listed on their own, each showing how many sub-suppliers sit beneath it. expandable rows: expand a supplier to see its sub-suppliers nested underneath, rather than flattened into one long list. shared suppliers shown in each place: a supplier serving more than one of your third parties appears under each of them. AI-proposed suppliers: AI suggests the suppliers your third parties are likely to depend on, giving a reason and a source for each. contained until reviewed: proposals arrive in the catalogue marked Identified and stay out of assessment recipients, dropdowns and every other list until you decide on them. accept or dismiss: accept a proposal and it becomes a third party you can monitor, taking its stakeholders from the supplier above it. Dismiss it and it disappears. Requires AI enabled for your tenant. This update will extend visibility one tier beyond your direct suppliers, and turn tier mapping from a manual research task into a review of what AI has already found.

Kamilla Dajani 21 days ago
Roadmap 2026
AI-Powered Tier Discovery
To make risk beyond your direct suppliers visible, the catalogue will show supply chain relationships as a hierarchy and AI will propose the suppliers your third parties are likely to depend on. Today the catalogue lists the companies you contract with but says much less about who they in turn depend on, so risk sitting one step further out stays invisible until something breaks. Key Enhancements hierarchy in the catalogue: direct suppliers are listed on their own, each showing how many sub-suppliers sit beneath it. expandable rows: expand a supplier to see its sub-suppliers nested underneath, rather than flattened into one long list. shared suppliers shown in each place: a supplier serving more than one of your third parties appears under each of them. AI-proposed suppliers: AI suggests the suppliers your third parties are likely to depend on, giving a reason and a source for each. contained until reviewed: proposals arrive in the catalogue marked Identified and stay out of assessment recipients, dropdowns and every other list until you decide on them. accept or dismiss: accept a proposal and it becomes a third party you can monitor, taking its stakeholders from the supplier above it. Dismiss it and it disappears. Requires AI enabled for your tenant. This update will extend visibility one tier beyond your direct suppliers, and turn tier mapping from a manual research task into a review of what AI has already found.

Kamilla Dajani 21 days ago
Roadmap 2026
DocuSign Integration
Documents that need signing have to leave 3rdRisk: you download the PDF, send it from somewhere else, then upload the signed copy and hope the record stays tidy. This closes that loop. Key Enhancements send from the document: choose "Sign with DocuSign" from a PDF's action menu and add your signers by name and email, as many as the document needs. no new permissions: available to anyone who can already edit the document. status you can see: the document shows where the request stands and where each signer stands. kept informed: an email as each person signs and another when the last one is done, both editable in Content β Communication like any other notification. signed copy comes back: the completed document is fetched and stored against the record automatically, with no manual upload. quick setup: an administrator connects your DocuSign account on the Integrations page.

Kamilla Dajani 21 days ago
Roadmap 2026
DocuSign Integration
Documents that need signing have to leave 3rdRisk: you download the PDF, send it from somewhere else, then upload the signed copy and hope the record stays tidy. This closes that loop. Key Enhancements send from the document: choose "Sign with DocuSign" from a PDF's action menu and add your signers by name and email, as many as the document needs. no new permissions: available to anyone who can already edit the document. status you can see: the document shows where the request stands and where each signer stands. kept informed: an email as each person signs and another when the last one is done, both editable in Content β Communication like any other notification. signed copy comes back: the completed document is fetched and stored against the record automatically, with no manual upload. quick setup: an administrator connects your DocuSign account on the Integrations page.

Kamilla Dajani 21 days ago
Roadmap 2026
Pre-view submitted external registration form
Once the external registration form is approved by assigned approvers, the next step is registering the third-party in the third-party catalogue. However, certain data (for example, the nature of the relationship based on which the location of the third party within the organisation can be determined) is not visible since the external form (once submitted) cannot be viewed by the coordinator. Having the possibility to view the pre-submitted data or having the βcustom fieldsβ tab visible with the data pre-filled from the external form when creating a third party would help a lot.

Laurynas Petraitis 2 months ago
Feature Request
Pre-view submitted external registration form
Once the external registration form is approved by assigned approvers, the next step is registering the third-party in the third-party catalogue. However, certain data (for example, the nature of the relationship based on which the location of the third party within the organisation can be determined) is not visible since the external form (once submitted) cannot be viewed by the coordinator. Having the possibility to view the pre-submitted data or having the βcustom fieldsβ tab visible with the data pre-filled from the external form when creating a third party would help a lot.

Laurynas Petraitis 2 months ago
Feature Request
Enable direct navigation from Messages to related Issues and Action Plans
From the Messages tab (see attachment), I would like to be able to directly click through to the referenced issue or action plan. This would allow users to open the related item immediately, without having to search for or open it manually.

Angela Bimmel 5 months ago
High Priority
Feature Request
Enable direct navigation from Messages to related Issues and Action Plans
From the Messages tab (see attachment), I would like to be able to directly click through to the referenced issue or action plan. This would allow users to open the related item immediately, without having to search for or open it manually.

Angela Bimmel 5 months ago
High Priority
Feature Request
Request for External Questionnaires' exportability
We kindly request that you consider implementing a functionality allowing EQ submitters to export their completed answers. This feature would significantly support our intermediaries in reviewing their submissions and ensure greater efficiency and transparency during the due diligence process. This feature has been requested by a number of our intermediaries. Many thanks!

Laurynas Petraitis 5 months ago
Feature Request
Request for External Questionnaires' exportability
We kindly request that you consider implementing a functionality allowing EQ submitters to export their completed answers. This feature would significantly support our intermediaries in reviewing their submissions and ensure greater efficiency and transparency during the due diligence process. This feature has been requested by a number of our intermediaries. Many thanks!

Laurynas Petraitis 5 months ago
Feature Request
Request: Enable shared filters (filter sets) that can be saved and reused by all users.
Users should be able to create and save predefined filter sets with standard settings (e.g. period, type, status). When creating a filter set, a user can select an option to share it with others, so everyone can apply the same filters with one click. Value: Consistent reporting and analysis Less manual work and fewer errors Faster insights and better collaboration

Angela Bimmel 5 months ago
Feature Request
Request: Enable shared filters (filter sets) that can be saved and reused by all users.
Users should be able to create and save predefined filter sets with standard settings (e.g. period, type, status). When creating a filter set, a user can select an option to share it with others, so everyone can apply the same filters with one click. Value: Consistent reporting and analysis Less manual work and fewer errors Faster insights and better collaboration

Angela Bimmel 5 months ago
Feature Request