Compliance playbooks

Practical guides for the work you actually do.

Written by GRC operators and audit veterans who've lived these workflows, not by content marketers.

Third Party Risk Program Maturity Scorecard
Guide

Third Party Risk Program Maturity Scorecard

Twelve observable questions that score how your third party risk program actually operates today, not how the policy describes it. Each question maps to a five level maturity scale from Reactive to Continuous, with the specific practice that defines each level. The result gives you an overall maturity level, the three lowest scoring areas to fix first, and a worksheet to assign each one an owner and a date. Built to be completed in a working session with security, procurement, legal, privacy, and business owners.

Get the guide
Guide

Continuous Vendor Monitoring: How to See Risk Between Assessments

How to monitor vendors between annual assessments: signals to watch, alert thresholds, severity tiers, baseline discipline, and a tooling checklist.

Read the guide
Guide

The Vendor Risk Assessment Process: A Practitioner's Guide

A practical vendor risk assessment guide: tier-based scoping, SIG vs CAIQ vs custom questionnaires, evidence validation, scoring design, and cadence.

Read the guide
Guide

Building a Third-Party Risk Management Program That Survives Growth

Build a TPRM program that survives 50+ vendors: inventory consolidation, tiering, cadences, remediation SLAs, board metrics, and spreadsheet migration.

Read the guide
Guide

Fourth-Party Risk Management: Seeing the Vendors Behind Your Vendors

How to find and manage fourth-party risk: sub-processor discovery, dependency mapping, cloud concentration analysis, flow-down clauses, and monitoring.

Read the guide
Guide

Security Ratings vs TPRM: What Each Actually Measures, and How to Choose

A fair comparison of security rating tools and assessment-driven TPRM: what each measures, where each stops, why they disagree, and how to choose.

Read the guide