Changelog

Follow new updates and improvements to 3rdRisk.

August 28th, 2026

New

Improved

We are hosting our annual Summer Meet-Up on the 10th of September in Amsterdam, RSVP today!

Another month another update!

Back in July we teased that assessments were getting conditional logic and autofill. Both are here, along with plenty of other exciting changes. Our team has been hard at work, so, without further ado, let’s dive into the latest batch of changes.

Key changes

Assessments

Questionnaire builder: If you have ever opened a four-sheet Excel template and hoped the row references still lined up, this one is for you. Questionnaires are now built in the platform. Set your domains, questions, weights and scoring, preview the whole thing exactly as a supplier will see it, then publish.

Existing and in-use questionnaires can easily be duplicated it and edited. Everything currently running carries on undisturbed.

Conditional questions: Not every question applies to every supplier. Asking anyway wastes their time and gives you answers that aren’t actually useful. But not including the question altogether means you might miss out on answers from relevant suppliers.

Questions can now stay hidden until an earlier answer makes them relevant. For example, asking whether a supplier processes personal data brings up the follow-ups only when the answer is yes. Hidden questions are not scored and never reach your exports, so nobody is marked down for a question that was never theirs.

Ensure questions only show up to relevant suppliers with conditional quesstions.

Answers carried over: Your suppliers may be the only group of people that dislike reassessment season more than you. Responding to the same questions with the same answers gets tiresome after a while.

Which is why from now on when a questionnaire they have completed before comes round again on the same contract, the supplier portal now offers to fill it in from their last finished assessment.

They get a prompt on each questionnaire, answers carry across while comments and attachments do not, and every field that was filled in is marked with a blue border so they know exactly what to check before submitting.

A copy for the supplier: Until now, a third party filled in an assessment and kept nothing. From now on when they are done, they get to take their answers with them, either downloading a PDF straight away or having one emailed to the address the invite went to. Emailed copies are password protected, with the password sent separately.

The PDF follows your branding and lists every questionnaire, domain, question, answer and comment, so they have something to work from next time round. Consider it a useful souvenir for your vendors.

A few smaller things: Questionnaire details are now visible from inside an assessment, you can set the next assessment date while you are finalising the current one, and exports have been extended to cover questionnaires you have since archived.

Business impact analysis

A risk profile for your own organisation: Within our platform, it is easy to see which of your suppliers are critical. Knowing the same about your own processes is a harder question, and far too often the answer ends up living in a spreadsheet that stopped being accurate a week after it was built.

Every organisation element with an active CIA domain now sits in one table: confidentiality, integrity and availability scored side by side, who assessed and reviewed it, what is linked to it, and when the next review is due. Overdue ones tell you how late they are.

Assessments on any element: Each element in your organisation model has its own assessments now, with an assessor, a reviewer, dates, and a notification when it is the reviewer's turn. More than one template can run against the same element, so a facility can carry a business impact analysis alongside whatever else it needs.

A template to start from: Building a BIA from a blank page can be a pain, and hardly anybody's idea of a good week. That’s why we provide you with a ready-made one covering confidentiality, integrity and availability across 13 scored questions, available to everyone from the start.

Assess each element of your organisation model

Wider coverage: Multi-domain assessments now run against far more of your organisation: assets, processes, key services, facilities, departments, value chains, factories and warehouses.

Third-party catalogue

Link a risk where you are: Adding a risk used to send you off to the risk register, and linking an existing one was not possible at all. Both can now happen from the third party itself.

See what is due next: The next review date is a column you can sort on, so finding everything due this month takes a click rather than opening records one at a time.

Easily sort your third parties in the catalogue based on the latest or next review date.

Find what is missing: Filter the catalogue by whether a document type is there or not. Finding the twelve suppliers without a current certificate stops being an afternoon's work.

And two more: Documents can now carry tags, the same way third parties do, and every column in the catalogue can be clicked for sorting.

Contracts

Duration types: Tacit renewal is easy to miss, right up to the point where it is too late to do anything about it. Contracts can now be indefinite, fixed-term with tacit renewal, or fixed-term without.

A tacitly renewed contract extends its own end date and nudges you 90 days before the notice deadline, while there is still something you can do about it.

Changes in duration types are easily managed within the platform.

Prompts that follow your notice period: The renew-or-exit prompt works back from the notice deadline rather than the contract end date. If you owe three months' notice, you hear about it with three months to go.

EBA fields in imports: Contract imports now include the EBA compliance fields, matching what DORA already supported, so your register can go out and come back without being rebuilt by hand.

News monitoring

Issues that arrive pre-written: Raise an issue from a news item and the type, deadline, location and criticality are already filled in. A note tells you what was pre-filled, so you can change anything that does not fit.

Link news to work already underway: A news item can be attached to an issue you have open rather than starting a new one, which keeps a developing story in one place.

Easier to spot: The news monitoring column has moved to the front of the third-party table, where you will actually see it.

You can now easily spot any updates to the news sentiment.

Admin self-service

Control assessment emails can now be edited in “Communication” alongside your other templates, custom fields can be deleted or archived without asking us, and scheduled assessments can be deleted when plans change.

Quality of life changes

  • Audit trail: Exports are now recorded in the audit log, showing who ran the export, what they exported, how many records it covered and when. Useful when someone needs to account for data leaving the platform.

  • Document analyser: The AI document analyser now works in the Internal Control module as well, so you can pull details out of an uploaded document without leaving the control you are working on.

Looking ahead

Next up: a public API and developer portal so you can build on the platform directly, work on mapping the third parties behind your third parties, archiving and restoring so finished records can be put away without disappearing, a DocuSign integration, and a single view of screening results for individuals and entities. Plenty more brewing.

Stay tuned, and we will see you soon.

- 3rdRisk Product Team

July 17th, 2026

Over the past couple of months, we've been working diligently (pun intended) to continue elevating the 3rdRisk platform with brand new features, the improvement of existing ones, and finetuning of the overall solution.

This means that we have a bigger batch of exciting updates to share with you. From AI enhancements to new integrations. So, grab a cup of coffee or tea and sit back as we have a look at the latest and greatest that our team has created.

Key changes

Email & notification customisation

Email templates: Every email your third parties and stakeholders receive from 3rdRisk, invitations, reminders, notifications, should sound and feel like you, not like us. That's why admins can now edit your organisation's email templates directly in the platform: update subject lines, tweak the wording, add your footer and legal disclaimers, all without waiting on our support team.

Preview your changes before they go out, revert to the default template any time, and rest easy knowing access is role-based, so only the people you trust can make edits. No more emailing us to change a line of copy. Now it's a couple of clicks, and the communication is entirely yours.

Teams & Slack notifications: The same level of customisation that we offer for emails is now also available for your Teams and Slack notifications, so that all your notification channels are configurable by you without needing any assistance from our team. Your admin can edit per language, per notification type. Whether you use Teams or Slack, they both receive the same content.

Lexi (AI) enhancements

The platform just got smarter with a bunch of new AI enhancements, designed to make our existing features even better and easier to use.

AI third-party risk profiles: Prompting the AI now moves beyond the name, and includes all relevant third-party information such as the type, category, country, but also key contextual elements such as open action plans, risks in the register, documents and custom fields.

Furthermore, manual refreshes to update the profile with the latest info are no longer needed. Instead, you are able to schedule when you want the refresh to happen, and the owner of the schedule will also be notified once it's done.

Assessment populator: The assessment populator is smarter now! For suppliers: they will now see how much time they saved and how many questions the AI automatically filled in. To ensure humans are kept in the loop, the AI also shows the answer below the dropdowns along with reasoning, allowing your supplier to choose if they want to fill in the answer or not. The AI also suggests which file to connect to an answer, along with a list of already uploaded files.

If an upload takes over one minute, the populator automatically moves on to the next file. If a file is not a PDF, it is skipped.

For reviewers: Documents uploaded by your supplier to use the populator are now also accessible and available for review, allowing you to check documents that aren't attached to specific questions.

Assessment summariser: Users are now able to customise the template used by AI to create the assessment summary, ensuring that whatever is written complies with your organisation's standards.

Contextual AI: As an AI user, you can now provide custom guidance and context per third party. This allows features such as the predictive risk profile to focus on what matters most to you for that specific third party, rather than using a one-size-fits-all approach.

Contract analyser: Improved the speed of the analyser, added an indicator that shows how many fields have been auto-filled, and made it easier to spot which fields have been filled in by the AI.

Sanctions monitoring

Earlier this year we announced that we have now integrated with Diligent's Risk Intelligence Data for our Sanctions & Watchlist Monitoring capability. However, we continue to further improve this capability.

Notifications: Users now get alerted when a third party gets a match in the database, letting you review the alert, mark it as a true positive, and create an issue.

Inherent risk profile: The notification flow after a third party has been found in the database now includes a question on whether the inherent risk profile should be changed based on the alert.

Slack integration

Organisations who use Teams should not be the only ones who get to have all the fun and benefit from the notifications that we've built. That's why we are now integrated with Slack as well. This integration brings the system notifications that Teams users have come to expect to Slack, letting users choose between the 3rdRisk Slack app and configuring their own app credentials securely.

Additional changes

Configuration

Fine-tune the platform to match how your organisation actually works. Access to third-party records can now be limited by user, so people only see the suppliers relevant to them, in dropdowns, search, linked assessments, issues and action plans, and in reporting and dashboards.

Admins can also configure which document types are allowed for upload tenant-wide, set their own assessment outcome labels, and restrict which file types are accepted per question.

Workflow improvements

A handful of changes to keep assessments and third-party data moving smoothly. Assessments can now be assigned per assessment rather than per questionnaire, and verification shows who's responsible, with the option to filter by verifier, so it's always clear who's doing what. The third-party cockpit also now shows the latest assessment's final score at a glance, and risk ambition has moved from a single point to a range, to better reflect your organisation's actual risk appetite.

Importing a large list of third parties? Bulk uploads now use chunking and batch processing, so files with 1,000+ records upload reliably. Registration forms can also update existing third-party records instead of creating duplicates, keeping your catalogue clean as it grows and changes.

Content Hub

Part of our commitment to the continued improvement of our platform lies in ensuring we update our content hub with best practices, created and verified by experienced third-party risk managers. Here's an overview of new content we've recently added:

  • Global: ISO/IEC 42001 for Artificial Intelligence Management Systems

  • Global: Cloud Security Alliance – CCM/CAIQ Third-Party Risk Management Assessment Questionnaire

  • Australia: Australia Signals Directorate Essential 8 Questionnaire

  • Australia & UK: Modern Slavery Act Questionnaire

  • Singapore: Monetary Authority of Singapore Technology Risk Management (TRM) Guidelines

  • Singapore: Cyber Security Agency of Singapore Cyber Trust Mark

  • USA: HIPAA – Business Associate Security & Privacy Compliance Questionnaire

Looking ahead

In the next couple of months, we’re bringing new features that are built to make you and your suppliers’ lives easier. Assessments are getting smarter, with features like conditional logic and autofill that tailor each questionnaire to the supplier filling it out. At the same time, ecosystem monitoring is quietly expanding its reach, so a risk brewing somewhere you don't even have a vendor yet won't blindside you later. And that's just the tip of the iceberg; we got plenty more brewing.

So, stay tuned and we’ll see you next month!

– 3rdRisk Product Team

April 29th, 2026

New

We've got a big one for you. The virtual officer, Lexi, acquired a agentic new skill: Sanctions & Watchlist Monitoring. This is also our first integration with the broader Diligent ecosystem. 🚀

Keeping track of sanctions across your entire third-party portfolio is one of those things that sounds simple until you're actually doing it. Checking lists, cross-referencing entities, figuring out what a match actually means for your organisation... it adds up fast.

We wanted to take that weight off your shoulders. 😌

How it works

Sanctions data lives right next to the overall risk profile. One view, full context. You see your third party's risk posture and sanctions status side by side, no tab-switching needed.

AI-generated reports do the heavy lifting. We pull screening data from Risk Intelligence Data (Diligent) and turn it into a full Sanction Monitoring Report. Executive summary, watchlist matches, ownership context, jurisdiction-specific guidance, and clear next steps. All put together for you, not by you.

Two report versions exist: one for when a match is found, and one for when the screening comes back clean. Each tailored to give you the right level of detail for the situation.

Continuous monitoring runs in the background. The moment you add a third party, they're automatically enrolled in sanctions screening. Nothing to configure. And if you ever need a fresh result on the spot, you can trigger a manual search.

Built into your existing workflow. You can move any sanction report to False Positive, create an Issue, or set it to No Action. Simple, familiar, no learning curve.

Good to know

The AI reports run on a self-service prompt that can be tweaked to fit your preferences. Your CX contact can adjust the output via the AI settings page on your tenant, so the reports match your internal compliance language.

This is live for all customers today. Have a look at the walkthrough below to see it in action. 👇

February 25th, 2026

New

Have you met our latest feature? 👀

February brings a key addition to the platform. We are proud to officially introduce you to our AI Document Analyzer. 🤩

Picture this: It’s time for your periodic review of your vendors, so you’re checking up on one of your most critical ones. You’re not just going to blindly believe an answer without proof, so you request a SOC 2 report as part of the assessment. And your vendor? They happily send it.

But then, the horror, more than seventy pages for you to read through and analyse. Now multiply that by each vendor that you requested this from… 🫠

If this scenario is all too familiar to you, then our AI Document Analyzer will be your new favorite tool on the 3rdRisk platform. This tool will enable your document analysis to go from a long, exhausting process you procrastinate, to a quick and easy review.

Instead, you can use that time for reducing risk, walking the dog, and catching up with colleagues over a cup of coffee. Yes, it really does save that much time. 😌

How it works:

When you’re at the assessment review stage, you have requested specific documents to serve as proof, such as a SOC 2 report, policy, or pen-test document. When you open this document, you can then make the Virtual Officer analyze the document based on a question set of your choosing.

The Virtual Officer then goes to work on your behalf and fills in the answers, while providing the pages on which it bases the answer. Satisfied? Simply approve the answer. But you can also edit, reject, or even create an action plan.

For more information on how it works, you can visit our support page.

January 28th, 2026

Improved

Welcome to the first changelog of 2026!

The brand new year brings a fresh batch of improvements to the 3rdRisk platform. Naturally, we are as dedicated as ever to continuously improving our platform. So, let’s get started.

Key changes

Contracts

  • Bulk imports: Contract bulk import is now possible.

  • Import template: Custom fields are now included in the import template along with DORA-required fields if enabled.

  • Registration forms: Sending contract registration forms to external users is now possible. Allowing others to fill out and upload the contract while automatically attaching it to the right third party.

  • Reviews: You can now review contract records using the same process as the third-party reviews you’ve done before.

Quality of life changes

  • Custom fields: You can now add descriptions under custom fields.

  • Password requirements: First-time users will now see the exact password requirements to prevent invalid passwords.

  • Reminders

    • Log: The platform now keeps a log of the sent reminders, who sent them, and which email address received them.

    • Pop-up: We added a pop-up that either confirms a reminder has been sent out after clicking “send a reminder” or tells you that a reminder has already been sent.

  • Residual risk reasoning: Good news, you can now write a reasoning for up to 5000 characters in the “reasoning on residual risk” box.

  • Signed documents: Signed PDFs, such as assurance reports, can now be uploaded and saved without triggering a security error.

  • Third-party cockpit: You can now access a third party directly from the communications panel

  • Third-party reviews:

    • Audit log: You can now see when a review happened in the audit log.

    • Notifications: Assigned reviewers will now receive notifications for manually scheduled reviews.

  • TPRM assessment progress: The progress bar now shows the assessment as incomplete if additional clarification has been requested.

ICYMI: Diligent has acquired 3rdRisk

In case you missed our LinkedIn announcement or customer email, 3rdRisk is now a Diligent brand. You can read the full press statement on our website by clicking this link: Diligent acquires 3rdRisk.

Do you have an interesting idea for a feature that your fellow risk professionals could really benefit from as well? Be sure to request it on Featurebase and vote on the feature requests you think our platform should have!

December 1st, 2025

Improved

It’s the last month of the year, but we are not done with our platform improvements. After all, we are still working on ways to make your experience using our platform even better.

So, without further ado, let’s discuss this month’s improvements.

Key changes

Overdue assessments

  • Due dates: Due dates are no longer automatically changed or extended when you leave an assessment open for a third party.

  • Marking as overdue: Assessments can now be marked as overdue without closing them for the third party.

  • Reminders: Choose whether to send a default one-time reminder to a third party once an assessment is overdue, send weekly reminders, or send no reminders at all.

Quality of life changes

  • Assessment help: We’ve added an info button in the assessment portal that opens our support page, so that your third parties can more easily access it for more info and documentation.

  • Residual risk: You can now fill in the “reasoning on residual risk” text box before starting the acceptance flow.

  • Third-party form: Country field is now positioned at the top to improve field hierarchy and support integrations.

  • Self-service SSO setup: Your admin can now set up and configure the SSO your organisation uses for logins via our guided self-service setup.

Be sure to contact us if you have any questions or suggestions. If you’re curious about what else is going on at 3rdRisk, you can follow us on LinkedIn.

Do you think we’re missing any key features? Then create a feature request here.

November 27th, 2025

New

As promised, here is a follow-up on our previous teaser. In this update, we dive deeper into our new feature: Country Risk Profiles.

A few months ago, we introduced a feature that handles some of your vendor onboarding legwork. The Predictive Risk Profiles, aimed at analysing your suppliers, so that you have a solid basis as you begin working with a new vendor.

But the risks of working with other organisations go beyond how a supplier is organised or which controls they have in place. They are also shaped by the country in which that supplier operates.

What if your next opportunity lies in a new region, or you want to understand the country-level risks behind your vendors?

After all, country-wide risks such as geopolitical instability, extreme weather and weak labour protections can all influence the reliability and ethics of a business relationship. From a flood halting production for weeks to a region with a record of human rights violations, creating reputational and compliance exposure.

That’s where our Country Risk Profiles come in to help you.

It helps you see the bigger picture behind your suppliers. From geopolitics and law enforcement to labour practices and ESG controversies. Using AI, the feature gives you a snapshot of the contextual, regional, and national risks that really matter.

In short, here’s what you get:
✅ Real insights on the operating context for more informed decisionmaking
✅ Risk-based onboarding
✅ A handy ally for NIS2, CSDDD, and cross-border compliance

We built this to make life easier for all the procurement, risk, and compliance professionals assessing their off- and nearshore partners. Have you used it yet?

Want to know more about our Country Risk Profiles? Then visit our support page for more information.

November 3rd, 2025

Improved

A new month brings a new batch of platform improvements. Our team has been hard at work to make the platform even better, and we’re ready to share what we cooked up this month.

Here’s a look at our latest improvements 👇

Quality of life changes

  • Assessment reports: You can now specify a conclusion and result when generating a draft report, allowing you to already access this information before finishing the report.

  • Company logos: We now automatically fetch company logos of your third parties, based on the website URL you filled in. Making it easier to recognise which company is which. If no logo is found, the first letter of the third party’s name is used as a placeholder.

  • Custom third-party types: You can now customise the third-party “type” field, so you can add the custom type that fits your specific workflow.

  • Expiring document notifications: We’ve brought notifications for expiring documents to all modules! It does not matter where or how the document was uploaded; you will always be notified seven days in advance when a document is about to expire.

  • Export risk profiles per domain: It’s now possible to export risk profiles per domain, making it easier for you to analyse your detailed data per risk domain. You can access this through the third-party catalogue.

Preview of what’s coming

Country Risk Profiles: Our brand new AI-powered country risk profiles are live, but we’ll share a more in-depth overview for this feature in a separate update, coming soon... 👀

Overdue Assessments: It’s almost there! We’re actively tweaking what happens when an assessment is “overdue” to give you, as the user, more autonomy. Expect more on this in our next platform update.

Be sure to contact us if you have any questions or suggestions. If you’re curious about what else is going on at 3rdRisk, you can follow us on LinkedIn.

October 2nd, 2025

A new month brings fresh updates to the 3rdRisk platform. We’re always working behind the scenes to make things better, and we’re excited to share what’s just gone live.

Here’s a look at our latest improvements 👇

SecurityScorecard Integration

We’ve added a new integration to the collection: SecurityScorecard. This integration automatically imports cybersecurity ratings and insights from SSC into your 3rdRisk environment, helping you monitor, assess, and respond to third-party cyber risks without switching between tools.

What you can do with this new integration

  • Cyber scores: You can now directly see & access your cyber scores within the third-party catalogue and get an overview of the underlying factors.

  • Notifications: Receive real-time notifications, for instance, when a rating changes below a certain threshold.

  • Action plans: Create action plans that get automatically filled in by SSC data, allowing you to insert external ratings into your workflow.

  • Automation: Want to dig deeper? You can now automate assessments to be sent based on SSC scoring.

Here’s a preview of how the SecurityScorecard integration looks on our platform.

Quality of life changes

  • SCIM provisioning: You are now able to use SCIM provisioning for Okta and Microsoft Entra ID. Allowing for users and groups to be automatically created, updated, and deactivated.

  • Bulk clarification: Need a vendor to clarify multiple or all answers on an assessment? You can now select multiple (or all) questions for additional clarification at once.

  • File uploads: When accidentally uploading with embedded scripts/macros you will now get an error message with this link added:

    https://support.3rdrisk.com/en/article/cannot-upload-file-due-to-security-reasons allowing you to fix the issue.

  • Deleted framework sections: Your deleted framework sections will now be hidden, and only active sections will be shown.

  • Bulk matching LEI numbers: The platform can now automatically find and add LEI numbers when bulk importing DORA third parties.

  • Risk appetite: Your residual risk is now compared to your risk appetite to show you whether it is actually in line with your desired appetite.

September 1st, 2025

Improved

A new month means highlighting some of the latest improvements that are now available. We continually work on making our platform better, and are excited to discuss what is live.

So, let’s have a look at some of the changes we’ve made.

Key changes:

  • Issues module

    • Custom issue types: We added the ability to customise the list of issue types.

    • Subtype field added: Along with the new customisation, you can now also create your own subtypes. Allowing you to align with your existing workflows.

  • Ambition levels: You can now set your own “ambition levels” in your risk register. Thus allowing you to track whether your active measures help you be in line with your risk appetite and desired posture.

  • Personalisation: We added the ability to upload your own profile picture, after all it is your profile, so it should feel that way.

  • Document metadata: You can now reopen the metadata of an uploaded document to change the upload and expiry date of a document as well as type.

Quality of life changes:

  • Third party

    • Website field for third parties: The website field is no longer required, so you won’t need to fill in a placeholder when you have no link for a third party.

    • Documents: You can now see the risks, issues, and action plans that a document is attached to in the cockpits, as well as in the documents tab. Giving you an overview of the documents related to a third party and its assessments.

    • Third-party review: You are now able to export all reviews of a third party to get an overview in one spreadsheet.

    • Third-party activities: You can see which third-party an assessment review belongs to, so you can more easily prioritise your review tasks.

  • Longer questions on risk profiles: We increased the character limit for questions from 255 to 2000.

  • Internal control filter: You are now able to filter for “subcontrol” and “main control” as an internal control user.

  • Frameworks sections: Archived framework sections are now hidden.

We want to thank you all for your continued feedback and suggestions. Without you, the platform wouldn’t be what it is today. And as usual, if you have any questions, feel free to reach out. We’re always happy to help.