Know where provider risk stands

Review providers with their contracts, questionnaire responses and evidence in one place. See what has changed and keep a clear record of each decision.

Provider assessment showing review progress, revised answers and options to approve or reject the submission.
Product interface shown in Bosnian.

Providers and contracts

Understand the dependency

Connect each contract to its provider and service. Review criticality, residual risk and concentration alongside contract terms, subcontractors and exit arrangements.

Cloud-service contract with provider details, contract term, residual risk and concentration risk.
Product interface shown in Bosnian.

Provider portal

Collect answers and evidence together

Providers complete assigned questionnaires in a separate portal. They can attach documents, read your feedback and submit revisions without access to internal risk records.

Provider questionnaire with attachments, feedback from the previous review and save and submit options.
Product interface shown in Bosnian.

Assessment review

See what changed between submissions

Compare revised answers with the previous version. Comments, requested changes and the authorized reviewer's decision remain in the review history.

Comparison of two questionnaire versions with changed answers expanded.
Product interface shown in Bosnian.

Follow-up

Keep findings linked to corrective work

Review the evidence collected for a finding and the treatment it came from. Add further review notes with their dates so the history remains available for the next assessment.

Evidence log for a provider finding, with dated review notes and a link to the treatment plan.
Product interface shown in Bosnian.

Access and deployment

Your team makes the decision

Providers supply the answers and evidence. Your authorized reviewers decide whether to accept them. We agree access, deployment and integrations with your team before implementation.

Separate provider access

External users work in a dedicated portal. Internal reviews and risk records stay separate.

Accountable review

Indicators and evidence inform the assessment. An authorized reviewer accepts or rejects the submission.

Agreed operating responsibilities

Define identity management, data flows, notifications and support access for your environment.

Before you start

Common questions

What to expect when you bring provider reviews into RiskDam.
Do providers access our internal application?

No. Providers use a separate portal for assigned questionnaires and evidence. Internal risk records and review work remain separate.

Can we repeat provider assessments?

Yes. Each assessment cycle keeps its own record, with previous responses and decisions available for review. Where scheduling is enabled, we agree the frequency, scope and responsible roles during implementation.

Can records include our required contract fields?

We agree the fields during implementation, including service details, locations, subcontracting, business continuity, audit rights, service levels and exit arrangements.

How are deployment and integrations defined?

We agree the deployment, identity management, data flows, notifications and support responsibilities with your team. Supported connections and any additional integration work are scoped before implementation.

See RiskDam in use

Walk through a provider review

Choose a sample provider or questionnaire. We will show you how to collect evidence, review responses and follow up on findings.

Please use sample data. Do not email confidential provider or contract information.
Book a demo