Getting Started with Third-Party Risk Management
Last updated: March 23, 2026
Third-Party Risk Management (TPRM) in Mycroft helps you assess and track security risks for software vendors and other third parties. Add vendors, collect evidence, complete a security questionnaire (with help from the TPRM AI Agent), and produce a risk assessment that can be reviewed, approved, and published for your security team and auditors.
Where to Find TPRM
In the main navigation, open Third-Party Risk Management.
You land on the TPRM list view showing all third parties (vendors) and their status.
Click the gear icon in the header to access Questionnaire settings when you need to configure your vendor security questionnaire.
Main Concepts
Third-party (vendor): An external organization you assess for risk (e.g. a SaaS provider, subprocessor).
Assessment: An evaluation of a third party. Assessments have a draft (in progress) and a published status.
Owners: General or business owners and Security owners are responsible for completing the risk assessment.
Reviewers: Optional users who must review and approve the assessment before it can be published.
AI-powered workflows: Mycroft’s agent collects publicly available data, analyzes evidence, suggests questionnaire answers, and helps produce draft assessments.