The fact that somebody else is taking care of the nitty-gritty work of TPRM, such as designing and mailing out questionnaires, ensuring follow-up, analysing replies, and detecting gaps Review collected by and hosted on G2.com.
The linkage of their security model to industry standards, such as the NIST cybersecurity framework or ISO 2700x, could be more direct. Comparing different assessments for the same third party throughout time is essentially not supported. The model reflecting "parent child relationships" (e.g. one third party owned by another) is immature. Overall though, these are secondary complaints about an excellent product. Review collected by and hosted on G2.com.



