Praeferre/Platform/Third-Party Risk Management
Third-Party Risk Management

Stop chasing vendors for spreadsheets. Start making decisions.

Praeferre sends your questionnaires, chases your suppliers, reads their answers and their policies, and tells you exactly where they fall outside your risk appetite — so your DPO or compliance team spends their time validating decisions, not hunting for evidence. No vendor limits. No manual re-keying. No more six-week onboarding delays.

UnlimitedVendors held on the platform
15–20 hrsSaved per vendor review, typically
1,000sOf documents reviewed in minutes
Assessed against: CAF 4.0 UK CYBER SECURITY & RESILIENCE BILL NIS2 ISO 27001 SOC 2 + YOUR OWN RISK THRESHOLDS
Why it matters

Your risk doesn't stop at your own perimeter

Nearly half of breaches in 2026 involve a third party, and regulators know it. New legislation is making supplier due diligence a legal duty, not just good practice — and the organisations that treat vendor assurance as a box-ticking exercise are the ones left explaining themselves after the fact.

UK · In Parliament

Cyber Security & Resilience Bill

Introduced November 2025, the Bill makes supply chain risk management a statutory duty for essential and digital service providers — with new powers to designate "critical suppliers" who must meet the same obligations as the organisations that rely on them.

Fines up to £17M or 4% of global turnover
UK · NCSC

Cyber Assessment Framework 4.0

CAF 4.0's Principle A4 now expects organisations to evidence — not just claim — how supplier access, platforms and software are assessed, monitored and incorporated into security operations. Spreadsheets no longer count as evidence.

108 new indicators of good practice added
EU · In force

NIS2 & DORA

Both regimes push due diligence obligations down the supply chain, requiring in-scope organisations to demonstrate ongoing — not one-off — assurance over the vendors and sub-processors they depend on.

Aligns with your GDPR & DPDP obligations
What happens without it

The supply chain is where the biggest incidents start

These aren't hypothetical risks — they're recent, real, and each one started with a vendor relationship nobody was watching closely enough.

6M+ people
Capita · UK, 2023

A ransomware attack on the outsourcing provider exposed data affecting multiple clients — a single supplier compromise that cascaded across an entire customer base.

£1.6–2.1BN
Jaguar Land Rover · UK, 2025

Cited in Parliament as the costliest cyber incident in UK history, with the financial damage shared between JLR directly and its supply chain.

Thousands of orgs
MOVEit · Global, 2023

A single vulnerability in one widely-used third-party file transfer tool was exploited at scale, affecting organisations worldwide who had never assessed that dependency directly.

Sources: Clifford Chance, on supply chain incidents referenced in the Cyber Security & Resilience Bill · Hansard, UK Parliament debate, June 2026.

15–20 hrs

Average time a manual vendor security review takes per supplier — time your compliance team could spend on judgement calls instead of data entry.

60%

Of total assessment cycle time consumed purely by chasing evidence and reconciling vendor responses — before any actual risk evaluation begins.

27%

Of organisations monitor supplier security beyond the initial onboarding check — the rest lose visibility the moment the contract is signed.

Sources: Gartner, via Atlas Systems, 2026 · Safe Security, 2026 · World Economic Forum Global Cybersecurity Outlook, 2026.

How it works

From questionnaire to decision, without the manual middle

Praeferre handles everything between "we need to assess this vendor" and "here's what our compliance team needs to sign off on."

STEP 1

Send

Questionnaires go out automatically, matched to the vendor's risk tier and the frameworks that apply — no drafting, no chasing emails.

STEP 2

Collect

Responses, policies and supporting documents come back into one place — reminders sent automatically until every vendor is complete.

STEP 3

Analyse

Praeferre's models read thousands of pages in minutes, comparing every answer and policy clause against your own predefined standards.

STEP 4

Decide

Anything outside your risk thresholds is flagged for your DPO or compliance team — with a recommendation ready, and a DPIA one click away.

Automated questionnaires

Offload the chasing, not the accountability

The single biggest time sink in vendor risk management isn't the analysis — it's the chasing. Praeferre sends the right questionnaire to the right vendor automatically, follows up without anyone having to remember to, and brings every response back into one place the moment it lands, ready for review.

  • Questionnaires scoped automatically to vendor risk tier and applicable frameworks
  • Automatic reminders — no analyst has to chase a single email
  • Unlimited vendors held on the platform, at every stage, at once
See the workflow in action
Vendor Assessment Queue
Meridian Cloud ServicesFLAGGED4 days ago
Horizon Payroll LtdIN REVIEW1 day ago
Vantage Data SystemsRESPONSE IN6 hrs ago
Solstice LogisticsSENT2 days ago
Northbridge AnalyticsSENT2 days ago
Amberline IT SupportIN REVIEW3 days ago
Document review at scale

Thousands of pages, read in minutes — not delegated to a Friday afternoon

Vendor policies, sub-processor lists, certifications, DPAs — every one of them matters, and none of them get read properly under deadline pressure. Praeferre's models read them all, extract what's relevant, and surface insight and recommendations your team can act on immediately, or send straight back to the vendor.

  • Full document review — not sampling, not summaries of summaries
  • Recommendations generated per document, ready to send to the vendor directly
  • Every finding traceable back to the exact clause it came from
See document review in action
Batch Review · Q3 Vendor Refresh
2,847DOCUMENTS PROCESSED
Policies fully aligned with your standards2,214
Minor gaps — recommendation drafted498
Outside risk threshold — escalated135
Your thresholds, your decisions

Praeferre flags it. Your team decides.

You define what "acceptable" means for your organisation — not a generic industry benchmark. When a vendor's answers or policies fall outside that line, it's routed straight to your DPO or compliance team with the context they need, and a DPIA can be raised in a single click when deeper assessment is warranted.

  • Risk thresholds configured by you, not fixed by Praeferre
  • One-click DPIA escalation with the evidence already attached
  • Full decision trail — who reviewed it, what was decided, and why
Configure your thresholds
Risk Threshold Results
Meridian Cloud Services — encryption & access94WITHIN LIMITS
Horizon Payroll — sub-processor disclosure71REVIEW ADVISED
Vantage Data Systems — cross-border transfer42DPIA RAISED
Where it fits

Built for more than the annual review

Vendor risk isn't a once-a-year event, and neither is Praeferre.

Pre-onboarding due diligence

Run a full risk assessment before a new vendor ever touches your data — so procurement decisions are made with evidence, not a signed SOC 2 cover page taken on faith.

Scheduled reassessment

Set your own cadence per vendor tier — critical suppliers reviewed quarterly, lower-risk vendors annually — without anyone needing to remember to trigger it.

Direct vendor feedback

Send the gaps Praeferre finds straight back to the vendor with clear recommendations — turning a compliance check into a working relationship that improves posture over time.

Regulator-ready evidence

Every assessment, decision and DPIA is logged — so when the Cyber Security & Resilience Bill or your next audit asks for proof of supply chain due diligence, it's already there.

M&A and integration due diligence

Assess an acquired company's entire vendor estate in days rather than months — critical when integration timelines are already tight.

Fourth-party visibility

Understand the sub-processors your critical vendors rely on — the dependency MOVEit-style incidents exploit, and the one most programmes still can't see.

No internal team? No problem

Don't have a DPO to validate the findings? We are one.

Praeferre flags what's outside your risk threshold — but someone still needs to make the judgement call. If you don't have an in-house DPO or compliance function, our DPO as a Service team reviews the findings, makes the call, and stands behind the decision as your named Data Protection Officer.

Explore DPO as a Service
A named, accredited DPO reviews every flagged vendor — not a generic support queue.
Recommendations and DPIA sign-off delivered in plain language your board can act on.
Full regulator liaison if a vendor-related issue ever needs to go further.
What it saves

Time is the real cost of manual vendor risk

Rough numbers for a compliance team running 50 active vendor relationships on a manual, spreadsheet-based process today.

Manual review time, per vendor (typical)15–20 hrs
Time spent chasing evidence vs. evaluating risk~60%
Typical manual onboarding cycle45–60 days
Automated onboarding cycle (comparable programmes)~10 days
Net effectFaster onboarding, more vendors covered, same headcount

Figures reflect published industry benchmarks (Gartner, ComplyScore, Safe Security, 2026) for manual versus automated vendor risk programmes, not a Praeferre-specific guarantee. Your results depend on vendor count, questionnaire complexity and current process maturity.

Start your compliance journey

Bring us your vendor list. We'll show you what's hiding in it.

A short discovery call is enough to see what a live assessment would surface across your current supplier base — no limit on how many you bring.