Criticality scored before questions
Five weighted dimensions, operational, data sensitivity, regulatory, financial and lock-in, produce an inherent tier that sizes everything downstream. A payment processor and a font CDN are not assessed the same way.
Right-sized questionnaires
The tier sets a question budget, so a vendor answers what matters for its risk rather than a fixed spreadsheet. Certifications skip the domains they attest, each skip carrying a written rationale.
An 11-framework, 3,896-question bank
PCI DSS, ISO 27001, SOC 2, the cloud and AI ISO standards, GDPR, HIPAA, and the RBI, SEBI and MAS financial-sector frameworks, one bank behind every questionnaire.
One answer, every framework
Answer a control once and it satisfies every framework that references it, with the confidence shown per framework. Anything below 85 percent is routed to human review rather than silently accepted.
Evidence mapped, then judged
Each file is mapped to exactly one control and reviewed only against that control’s checks, never “the file exists”. A signed attestation that is fifteen months out of date is marked non-compliant, with the reason.
Maturity with a coverage gate
Answers are tier-weighted into a 0-100 maturity score, but maturity only counts once 70 percent of scoped controls are answered. Below that it is gated, because a strong score from three answers evidences nothing.
Residual risk you can read
Residual is inherent criticality shifted by maturity band, recomputed on every save, and every residual carries a sentence of rationale rather than a bare coloured pill.
A graded portfolio
An A-to-F portfolio grade computed live from residual risk, a residual-tier distribution, a trend line, and the vendor book ranked by exposure, with concentration and outstanding assessments surfaced.
A copilot over the whole book
Ask which critical vendors have a stale attestation, or where risk concentrates, and get an answer reasoned across every vendor, role-scoped so a vendor contact sees only their own record, and audit-logged.