July 17th, 2026

Over the past couple of months, we've been working diligently (pun intended) to continue elevating the 3rdRisk platform with brand new features, the improvement of existing ones, and finetuning of the overall solution.
This means that we have a bigger batch of exciting updates to share with you. From AI enhancements to new integrations. So, grab a cup of coffee or tea and sit back as we have a look at the latest and greatest that our team has created.
Email templates: Every email your third parties and stakeholders receive from 3rdRisk, invitations, reminders, notifications, should sound and feel like you, not like us. That's why admins can now edit your organisation's email templates directly in the platform: update subject lines, tweak the wording, add your footer and legal disclaimers, all without waiting on our support team.
Preview your changes before they go out, revert to the default template any time, and rest easy knowing access is role-based, so only the people you trust can make edits. No more emailing us to change a line of copy. Now it's a couple of clicks, and the communication is entirely yours.
Teams & Slack notifications: The same level of customisation that we offer for emails is now also available for your Teams and Slack notifications, so that all your notification channels are configurable by you without needing any assistance from our team. Your admin can edit per language, per notification type. Whether you use Teams or Slack, they both receive the same content.
The platform just got smarter with a bunch of new AI enhancements, designed to make our existing features even better and easier to use.
AI third-party risk profiles: Prompting the AI now moves beyond the name, and includes all relevant third-party information such as the type, category, country, but also key contextual elements such as open action plans, risks in the register, documents and custom fields.
Furthermore, manual refreshes to update the profile with the latest info are no longer needed. Instead, you are able to schedule when you want the refresh to happen, and the owner of the schedule will also be notified once it's done.
Assessment populator: The assessment populator is smarter now! For suppliers: they will now see how much time they saved and how many questions the AI automatically filled in. To ensure humans are kept in the loop, the AI also shows the answer below the dropdowns along with reasoning, allowing your supplier to choose if they want to fill in the answer or not. The AI also suggests which file to connect to an answer, along with a list of already uploaded files.
If an upload takes over one minute, the populator automatically moves on to the next file. If a file is not a PDF, it is skipped.
For reviewers: Documents uploaded by your supplier to use the populator are now also accessible and available for review, allowing you to check documents that aren't attached to specific questions.
Assessment summariser: Users are now able to customise the template used by AI to create the assessment summary, ensuring that whatever is written complies with your organisation's standards.
Contextual AI: As an AI user, you can now provide custom guidance and context per third party. This allows features such as the predictive risk profile to focus on what matters most to you for that specific third party, rather than using a one-size-fits-all approach.
Contract analyser: Improved the speed of the analyser, added an indicator that shows how many fields have been auto-filled, and made it easier to spot which fields have been filled in by the AI.
Earlier this year we announced that we have now integrated with Diligent's Risk Intelligence Data for our Sanctions & Watchlist Monitoring capability. However, we continue to further improve this capability.
Notifications: Users now get alerted when a third party gets a match in the database, letting you review the alert, mark it as a true positive, and create an issue.
Inherent risk profile: The notification flow after a third party has been found in the database now includes a question on whether the inherent risk profile should be changed based on the alert.
Organisations who use Teams should not be the only ones who get to have all the fun and benefit from the notifications that we've built. That's why we are now integrated with Slack as well. This integration brings the system notifications that Teams users have come to expect to Slack, letting users choose between the 3rdRisk Slack app and configuring their own app credentials securely.
Fine-tune the platform to match how your organisation actually works. Access to third-party records can now be limited by user, so people only see the suppliers relevant to them, in dropdowns, search, linked assessments, issues and action plans, and in reporting and dashboards.
Admins can also configure which document types are allowed for upload tenant-wide, set their own assessment outcome labels, and restrict which file types are accepted per question.
A handful of changes to keep assessments and third-party data moving smoothly. Assessments can now be assigned per assessment rather than per questionnaire, and verification shows who's responsible, with the option to filter by verifier, so it's always clear who's doing what. The third-party cockpit also now shows the latest assessment's final score at a glance, and risk ambition has moved from a single point to a range, to better reflect your organisation's actual risk appetite.
Importing a large list of third parties? Bulk uploads now use chunking and batch processing, so files with 1,000+ records upload reliably. Registration forms can also update existing third-party records instead of creating duplicates, keeping your catalogue clean as it grows and changes.
Part of our commitment to the continued improvement of our platform lies in ensuring we update our content hub with best practices, created and verified by experienced third-party risk managers. Here's an overview of new content we've recently added:
Global: ISO/IEC 42001 for Artificial Intelligence Management Systems
Global: Cloud Security Alliance – CCM/CAIQ Third-Party Risk Management Assessment Questionnaire
Australia: Australia Signals Directorate Essential 8 Questionnaire
Australia & UK: Modern Slavery Act Questionnaire
Singapore: Monetary Authority of Singapore Technology Risk Management (TRM) Guidelines
Singapore: Cyber Security Agency of Singapore Cyber Trust Mark
USA: HIPAA – Business Associate Security & Privacy Compliance Questionnaire
In the next couple of months, we’re bringing new features that are built to make you and your suppliers’ lives easier. Assessments are getting smarter, with features like conditional logic and autofill that tailor each questionnaire to the supplier filling it out. At the same time, ecosystem monitoring is quietly expanding its reach, so a risk brewing somewhere you don't even have a vendor yet won't blindside you later. And that's just the tip of the iceberg; we got plenty more brewing.
So, stay tuned and we’ll see you next month!
– 3rdRisk Product Team