Third-Party Risk

Modern third-party risk management for ICT providers.

Replace scattered spreadsheets and mailboxes with a connected lifecycle: inventory, criticality, assessments, evidence, risks, remediation and continuous review.

relynt.io/providers

ICT Providers

96 providers · 18 critical

Add ICT Provider
AllCriticalHigh RiskAssessment OverdueMissing Evidence
ProviderICT ServiceCriticalityCountryRisk
Halcyon Cloud ServicesCloud InfrastructureCriticalIrelandHigh
Northwind Cloud IrelandCloud & ProductivityCriticalIrelandMedium
Payflux Payments EuropePayment ProcessingCriticalIrelandHigh
Lumendata NetherlandsData PlatformImportantNetherlandsMedium
Edgeway GermanyNetwork & SecurityImportantGermanyLow
ValteraCore BankingCriticalSwitzerlandMedium

Lifecycle

Seven stages, one record.

Inventory

Every ICT provider and the services they deliver.

Criticality

Critical, important or standard, and whether a critical function depends on it.

Assessments

Structured questionnaires with a vendor portal.

Evidence

Certifications and reports with expiry tracking.

Risks

Findings become owned, scored risks.

Remediation

Mitigation plans with due dates and progress.

Continuous review

Reassessment cycles triggered by criticality and change.

Reporting

Board and audit reporting from the same data.

Assessments

Assessments that produce decisions, not PDFs.

  • Section-level progress across every vendor
  • Evidence requested inside the questionnaire
  • Reviewer decisions recorded per response
  • Findings convert to risks in one click
relynt.io/assessments/ASM-2041

ASM-2041 · Halcyon Annual ICT Assessment

Under Review

117 questions · 12 sections · vendor submitted 4 August 2026

Section progress

  • Governance & Oversight100%
  • Information Security92%
  • Business Continuity64%
  • Incident Management88%
  • Subcontracting45%

Q 4.3 · Business Continuity

Describe the frequency and scope of your disaster recovery testing.

“DR testing is performed periodically across production regions.”

AI Finding

78% confidence

Disaster recovery testing evidence is missing.

The response describes testing but no test report was attached for the current period. Requires human review before any compliance decision.

Accept & create riskDismissRequest clarification

Reviewed by Sarah Martin · AI suggestions never change compliance status automatically.

Evidence

Documentation that never silently expires.

  • Valid, Expiring, Expired and Missing statuses
  • Automated requests to vendor contacts
  • Coverage by provider and criticality
  • Documents linked to the risks they support
relynt.io/evidence

Evidence Library

418 documents · 23 missing · 11 expiring within 60 days

Request Evidence
  • SOC 2 Type II

    Halcyon Cloud Services

    Valid
  • ISO 27001

    Northwind Cloud Ireland

    Valid
  • Penetration Test

    Payflux Payments Europe

    Expiring
  • Business Continuity Plan

    Lumendata Netherlands

    Expired
  • Disaster Recovery Test

    Halcyon Cloud Services

    Missing

Remediation

One register for outstanding third-party risk.

  • Severity scoring against your risk appetite
  • Named owner and due date on every risk
  • Acceptance with documented rationale
  • Full history for audit
relynt.io/risks

Risk Register

7 high risks · 18 open · linked to assessments, evidence and contracts

IDRiskProviderSeverityStatusOwner
RSK-311DR testing evidence not providedHalcyonHighMitigation PlannedS. Martin
RSK-318Exit strategy absent from contractNorthwind CloudHighOpenT. Weber
RSK-324Subcontractor countries incompletePayfluxMediumIn ReviewL. Dubois
RSK-327Pen test older than 12 monthsLumendataMediumOpenS. Martin
RSK-330No documented incident SLAValteraLowAcceptedM. Rossi

Workflow

The continuous review loop.

Inventory
Criticality
Assessment
Evidence
Risk
Remediation
Review

Get your ICT third-party risk under control.

See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.

Third-Party Risk Management for ICT Providers | Relynt