Know where provider risk stands
Review providers with their contracts, questionnaire responses and evidence in one place. See what has changed and keep a clear record of each decision.
Providers and contracts
Understand the dependency
Connect each contract to its provider and service. Review criticality, residual risk and concentration alongside contract terms, subcontractors and exit arrangements.
Provider portal
Collect answers and evidence together
Providers complete assigned questionnaires in a separate portal. They can attach documents, read your feedback and submit revisions without access to internal risk records.
Assessment review
See what changed between submissions
Compare revised answers with the previous version. Comments, requested changes and the authorized reviewer's decision remain in the review history.
Follow-up
Keep findings linked to corrective work
Review the evidence collected for a finding and the treatment it came from. Add further review notes with their dates so the history remains available for the next assessment.
Access and deployment
Your team makes the decision
Separate provider access
External users work in a dedicated portal. Internal reviews and risk records stay separate.
Accountable review
Indicators and evidence inform the assessment. An authorized reviewer accepts or rejects the submission.
Agreed operating responsibilities
Define identity management, data flows, notifications and support access for your environment.
Before you start
Common questions
Do providers access our internal application? +
No. Providers use a separate portal for assigned questionnaires and evidence. Internal risk records and review work remain separate.
Can we repeat provider assessments? +
Yes. Each assessment cycle keeps its own record, with previous responses and decisions available for review. Where scheduling is enabled, we agree the frequency, scope and responsible roles during implementation.
Can records include our required contract fields? +
We agree the fields during implementation, including service details, locations, subcontracting, business continuity, audit rights, service levels and exit arrangements.
How are deployment and integrations defined? +
We agree the deployment, identity management, data flows, notifications and support responsibilities with your team. Supported connections and any additional integration work are scoped before implementation.
See RiskDam in use
Walk through a provider review
Choose a sample provider or questionnaire. We will show you how to collect evidence, review responses and follow up on findings.
Please use sample data. Do not email confidential provider or contract information.



