Skip to main content
v2026.11,772 entries · CC-BY 4.0

Vendor risk

Third party risk management software for research institutions

Third party risk management software automates the part of vendor due diligence that is genuinely mechanical — sending the questionnaire, chasing it, parsing the SOC 2, watching the certificate expire. It does not tell you whether the CRO holding your participant data will behave well. That distinction decides which platform you should shortlist, and how much of your budget should stay with the contract instead.

Written and maintained by CASRAI Editorial Board

Last updated

The half you can price todayVerified 18 August 2026

Sign.PlusSign.Plus for the agreements that come out the far end

Free tier (3 requests) · Professional $19.99/mo unlimited · Enterprise $49.99/mo with HIPAA and a BAA

On the platform question our answer is short: for a research institution starting from scratch, shortlist Vanta Vendor Risk first, because its questionnaire automation and continuous evidence collection are the closest fit to a small research-security team with no dedicated GRC analyst — and we quote no price for it, because we publish only prices we have read off a vendor page ourselves. What we can price is the step every TPRM platform hands back to you unfinished. An assessment produces a decision; the decision has to become a signed data use agreement, business associate agreement or subaward security exhibit, with an audit trail an auditor will accept. Sign.Plus does that from a free tier of three requests, gives unlimited signature requests at $19.99/mo on Professional, and puts HIPAA coverage with a signed BAA on Enterprise at $49.99/mo — with eIDAS-grade audit trails on every tier including the free one, which is unusual and is the reason it is here rather than a bigger name. Verified 18 August 2026.

What a BAA must contain when the vendor touches research data, and what no platform can assert on your behalf.

Editorial disclosure: Some links on this page are CASRAI referral links. If you sign up through one, CASRAI may earn a commission at no extra cost to you — this helps fund our nonprofit mission. We only recommend tools our editorial team has independently researched. Read our full disclosure policy →

At a glance

The four platforms you are about to google

Positioning only. We publish prices only where we have read them off a vendor pricing page — none of these are CASRAI partners, so no figures appear here. Assessed 19 August 2026.

DimensionWhat it is actually built forWhere it genuinely winsWhat to test before you sign
Vanta Vendor RiskCompliance automation first, with vendor risk as a module on the same evidence graphSmall teams with no GRC analyst. Vendor inventory discovered from your own stack, questionnaires sent and chased automatically, document parsing that reads a SOC 2 rather than filing itWhether it handles HECVAT natively or expects you to upload it as a generic document; how vendor findings surface separately from your own compliance posture
OneTrustPrivacy and governance at enterprise scale, with third-party risk as one module among manyInstitutions that already run their records of processing, DPIAs and data mapping in one place and want vendor risk on the same register rather than in a second systemImplementation weight. It is the heaviest option here and rewards an owner with time; ask what configuration is billed as professional services
PrevalentThird-party risk as the whole product, not a module — assessment workflow, remediation tracking, managed servicesLarge vendor populations with real tiering, and offices that want the questionnaire chasing done for them rather than automated at themWhether the depth is proportionate to your vendor count. Below roughly a hundred assessed vendors much of the machinery goes unused
UpGuardOutside-in security ratings and attack-surface monitoring, with questionnaires added around themContinuous visibility of exposed services, certificate hygiene and leaked credentials across a supplier list you did not assess and cannot re-assessThat a score is an external observation. It cannot see access control inside a CRO, and a good score is not a due-diligence conclusion
The spreadsheet you have nowNothing. It accumulatedHonestly: it is free, and for under twenty low-risk vendors a well-kept register with diarised review dates outperforms a badly implemented platformWhether anyone can answer "which vendors hold identifiable participant data" in under a minute. If not, that is your business case

Every platform on this list will show you a dashboard of green. Judge them on the two questions that actually predict value: can it ingest the questionnaire standard your sector uses, and does it tell you when something changes between assessments.

The real workflow

What third party risk management software is automating in a research office

In most industries "third party risk" means suppliers. In a research institution it means something more consequential: the CRO running your trial, the subrecipient on your federal award, the biobank, the sequencing provider, the transcription service handling qualitative interviews, the analytics vendor with a pipe into the data warehouse, the cloud tenancy where a lab keeps imaging data, and the collaborating institution you are about to send a dataset to under a data use agreement.

Every one of those relationships already triggers a due-diligence obligation somewhere — IRB conditions, sponsor flowdowns, HIPAA when protected health information is involved, GDPR when a European cohort is, export controls when the data is controlled, and the institution's own information-security policy. What almost no research office has is a single place recording which vendor is covered by which obligation, when it was last checked, and what the answer was. That is the gap the software fills: a vendor inventory, tiering by sensitivity, a standard questionnaire sent and tracked, the SOC 2 and certificates stored with expiry flagged, and a register that answers an auditor in a minute rather than a fortnight. It is genuine research administration work being automated — not a metaphor for it.

What it is not is a judgement. The platform will tell you the CRO returned a complete questionnaire and holds a current ISO 27001 certificate. Whether the CRO will actually protect participant data through a subcontractor change eighteen months from now is a question about contract terms, audit rights and the seriousness of the organisation, and no vendor score answers it.

The deciding feature

Questionnaire automation, and why HECVAT decides the shortlist

Questionnaire automation is the feature that justifies the licence. In practice it means four things: a library of standard questionnaires you can send without rewriting them, automatic reminders so nobody is chasing a vendor by email, answer reuse so a vendor assessed last year is not starting from a blank form, and parsing of the evidence that comes back so a SOC 2 report is read rather than merely attached.

Three standards matter, and they are not interchangeable. SIG — the Shared Assessments Standardised Information Gathering questionnaire — is the broad commercial standard, published in core and lite forms, and is what most enterprise TPRM platforms assume. CAIQ, the Cloud Security Alliance's Consensus Assessments Initiative Questionnaire, is the cloud-specific one; if a vendor has published a CAIQ to the CSA registry you may be able to skip the questionnaire step entirely. And HECVAT — the Higher Education Community Vendor Assessment Toolkit — is the standard that higher education actually uses, in full, lite and on-premise versions, with a community broker where completed assessments are shared between institutions so the same vendor is not assessed sixty times.

Here is the trap for a product-aware buyer. Almost every generic TPRM platform supports SIG and CAIQ out of the box. Most have no native HECVAT support at all — you can upload a completed HECVAT as a PDF attachment, but the platform cannot send it, cannot map its answers to controls, cannot reuse them, and cannot pull an existing completed assessment from the shared community source. If your institution is a university, that single gap can cancel most of the labour saving you bought the platform for.

Make it the first question in the demonstration, and insist on seeing it done rather than described: send a HECVAT Lite to a test vendor, receive it back, show the answers as structured data. "On the roadmap" is a no. If nothing on your shortlist can do it, the honest configuration is a platform for inventory, tiering, monitoring and evidence storage with HECVAT handled alongside it through the community exchange — defensible, but choose it knowingly rather than discover it in month three.

The genuine upgrade

Continuous monitoring versus point-in-time assessment

The strongest argument for replacing a spreadsheet is not the questionnaire. It is that an annual assessment is a photograph of a moving object. A vendor assessed in March can be breached in July, let a certificate lapse in September, be acquired in November and move your data to a new subprocessor in January — and under a point-in-time regime you learn about all of it at the next annual review, if at all.

Continuous monitoring closes part of that gap by watching what is observable from outside: TLS and certificate hygiene, exposed services and open ports, DNS and email authentication records, credentials appearing in public breach corpora, and public disclosure of incidents. When something degrades, the platform raises it against the vendor record you already hold. For a research office tracking a long tail of small suppliers nobody has capacity to re-assess, that is a real and defensible improvement.

The honest trade-off: an automated vendor score measures external attack surface — a partial proxy. It cannot see whether the CRO enforces least privilege on the study database, whether staff are trained, whether a subcontractor in another jurisdiction has the same controls, or whether anyone will notify you inside the window your contract specifies. A vendor with an immaculate external posture can still mishandle participant data, and a small academic collaborator with shabby DNS may run a tighter data operation than a listed company with a perfect rating.

Treat the score as a signal that prompts a conversation, never as a due-diligence conclusion, and never as a substitute for contractual controls: defined permitted use, subcontractor consent, breach notification deadlines, audit rights, return-or-destroy at study close. The platform supplements those. Any vendor implying otherwise is selling a risk transfer that does not exist.

The verdict

Vanta, OneTrust, Prevalent, UpGuard — which one, and why

You are going to search all four names, so here is the verdict rather than a survey. We hold no verified pricing for any of them — none is a CASRAI partner, and we publish only figures read directly off a vendor pricing page — so judge these on fit.

Vanta Vendor Risk is where most research institutions should start. It comes from compliance automation, so the vendor module sits on the same evidence base as your own SOC 2 or ISO 27001 work: vendors discovered from systems you already connect, questionnaires that chase themselves, returned documents parsed rather than filed. Where vendor risk is a fraction of one person's role, that ratio of setup effort to output is the one that survives contact with reality. Check HECVAT before you commit.

OneTrust is better if you have a privacy office. Where records of processing, DPIAs and data mapping already live there, adding vendor risk to the same register beats a second system with a second vendor list that drifts out of agreement within a year. It is also the heaviest option here, and rewards an institution with someone whose actual job this is.

Prevalent is better if third-party risk is the whole job — deep assessment and remediation workflow, real tiering across a large vendor population, managed services if you would rather outsource the chasing than automate it. Below roughly a hundred assessed vendors much of that is licensed and unused. UpGuard is better if what you actually want is monitoring: a long supplier tail nobody has assessed and continuous outside-in visibility now. It is the weakest fit where the requirement is structured questionnaire workflow against a sector standard.

Do not buy any of them if you have fewer than about twenty vendors, none touches identifiable participant data, and the real problem is that nobody owns the register. A platform does not create an owner; it gives an absent owner a more expensive place to be absent, and you will renew for three years before anyone admits the questionnaires stopped going out in month four. Fix the ownership, keep the spreadsheet, revisit in a year.

Where the software stops

The DUAs and BAAs that come out the far end

Follow the workflow to its end and the platform stops one step short every time. An assessment concludes; a risk is accepted, mitigated or refused; and then a human has to put the conclusion into an instrument that binds the other party. In research that instrument is a data use agreement, a business associate agreement where protected health information is involved, a material transfer agreement, a subaward with a security exhibit, or a clinical trial agreement schedule.

Good TPRM platforms track that these documents exist and when they expire. None drafts the terms, and none can assert on your behalf that a vendor is a business associate rather than a conduit — a determination that belongs to your privacy officer and counsel. Our page on business associate agreements in research covers what those terms must contain and where institutions most often get the determination wrong.

What you can automate is execution and evidence. The signature must be legally sound, the audit trail must withstand a records request years later, and where PHI is involved the signature vendor itself becomes a vendor you must assess — which is why the HIPAA and BAA question matters when choosing one. Our comparison of HIPAA-compliant e-signature software works through that in detail.

This is the reason our priced recommendation sits here rather than on the platform. Sign.Plus gives audit trails and eIDAS-grade evidence on every tier including the free one, unlimited signature requests at $19.99/mo, and HIPAA coverage with a signed BAA on Enterprise at $49.99/mo — so a research office can pilot the whole loop, from questionnaire to signed agreement, before committing budget to either half. Verified 18 August 2026.

Before you buy

How to run a pilot that tells you something

Vendor demonstrations are optimised to look good. Structure your own evaluation instead, using the same five vendors in every trial: one CRO or clinical partner, one cloud or analytics platform, one small academic collaborator with no security function, one laboratory supplier, and one vendor you already know is difficult. Run the whole loop in each platform and record four numbers — time to get each vendor inventoried and tiered, whether your sector's questionnaire could be sent natively, how many chasing emails a human still wrote, and time from returned questionnaire to a recorded decision with evidence attached.

Then break something on purpose: let a certificate expire on a test domain, or ask what the platform did the last time one of your vendors disclosed an incident. A platform that only tells you what you told it is a database with a subscription.

Finally, price the whole workflow rather than the licence. A platform that saves forty hours of chasing and then leaves you executing agreements by scanned PDF has moved the bottleneck rather than removed it. The offices that get value from third party risk management software automated the assessment and the agreement together, and kept a named human accountable for the decision the software merely recorded.

Ready to move

Close the loop before you commit to a platform

Whichever TPRM platform you shortlist, the assessment still has to become a signed DUA, BAA or security exhibit with an audit trail that survives a records request. Sign.Plus starts free at three requests, goes to unlimited signature requests at $19.99/mo on Professional, and carries HIPAA with a signed BAA on Enterprise at $49.99/mo — with eIDAS-grade audit trails on every tier including the free one. Verified 18 August 2026.

From $9.99/mo · unlimited requests at $19.99/mo

Try Sign.Plus freeOpens on the vendor's site · CASRAI referral link

Frequently asked questions

Common questions

What is third party risk management software, in a research context?
It maintains an inventory of every external organisation that touches your systems or data, tiers each by sensitivity, sends and chases standard security questionnaires, stores the evidence that comes back, and alerts you when something changes. In a research institution that population is CROs, subrecipients, biobanks, sequencing and transcription providers, survey and analytics platforms, cloud tenancies and collaborating institutions receiving data under a DUA. The value is not the questionnaire itself — it is being able to answer, in a minute rather than a fortnight, which vendors hold identifiable participant data and when each was last assessed.
Does the platform support HECVAT, or only SIG and CAIQ?
Ask this first, and insist on a live demonstration rather than a roadmap commitment. Nearly every generic TPRM platform handles SIG and CAIQ natively because those are the commercial and cloud standards. HECVAT — the higher education standard, in full, lite and on-premise versions — is frequently supported only as a PDF attachment: no sending, no structured answers, no reuse, and no pull from the shared community exchange where another institution has already assessed the same vendor. For a university that gap removes most of the labour saving.
Is continuous monitoring worth paying for over an annual assessment?
Usually yes, with a clear-eyed view of what it measures. An annual questionnaire is a photograph of a moving object: a vendor can be breached, acquired, or move your data to a new subprocessor months before your next review. Continuous monitoring watches the externally observable signals — certificates, exposed services, email authentication, breached credentials, disclosed incidents — and raises them against the vendor record. What it cannot see is anything inside the vendor: access control on the study database, staff training, subcontractor arrangements, or whether they will notify you inside your contractual window.
Can a vendor risk score replace due diligence on a CRO?
No, and this is the failure mode worth guarding against. An automated score measures external attack surface — what an attacker could see from the internet. A CRO with an immaculate external posture can still mishandle participant data, and a small academic collaborator with untidy DNS may run a tighter data operation. Use the score to prompt a conversation and to catch degradation between assessments, never as a due-diligence conclusion. The controls that actually bind a CRO are contractual: defined permitted use, consent to subcontractors, breach notification deadlines, audit rights, and return-or-destroy obligations at study close.
How does third party risk management software handle the DUAs and BAAs at the end?
It tracks that they exist and when they expire; it does not draft them and it cannot make the determination that a vendor is a business associate rather than a conduit — that belongs to your privacy officer and counsel. Read our guide to business associate agreements in research for what those terms must contain. What you can automate is execution and evidence, and that is where our priced pick sits: Sign.Plus starts free at three requests, gives unlimited signature requests at $19.99/mo on Professional, and puts HIPAA with a signed BAA on Enterprise at $49.99/mo, with eIDAS-grade audit trails on every tier including the free one (verified 18 August 2026). Because the free tier needs no card, you can run one real assessment end to end — questionnaire to signed agreement — before you spend anything. If PHI is involved, work through the HIPAA e-signature comparison first, since your signature vendor becomes a vendor you must assess.
Vanta, OneTrust, Prevalent or UpGuard?
Vanta Vendor Risk if you have no dedicated GRC analyst and want vendor risk on the same evidence base as your own compliance work. OneTrust if a privacy office already runs your records of processing and DPIAs and a second register would drift. Prevalent if third-party risk is a full-time job across a large tiered vendor population, or you would rather outsource the chasing than automate it. UpGuard if the requirement is continuous outside-in monitoring of a supplier tail you cannot re-assess. We publish no prices for any of them — none is a CASRAI partner and we quote only figures read off a vendor pricing page.
When should we not buy a TPRM platform at all?
When you have fewer than about twenty vendors, none touches identifiable participant data, and the real problem is that nobody owns the register. Software does not create an owner; it gives an absent owner a more expensive place to be absent, and the usual outcome is a three-year subscription on which questionnaires stopped going out in month four. Name the owner, keep a spreadsheet with diarised review dates and a tier column, and revisit in a year with evidence of what the manual process actually costs — which is also the business case you will need to get funding approved.

Follow CASRAI

We publish research-administration guidance, standards updates and independent tool reviews. Follow along wherever you already read.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 72,264 indexed passages, and every answer cites the ones it drew on.