Supplier & third-party risk management

Third-party risk, tied to real relationships.

Questr assesses suppliers with weighted questionnaires and turns findings into owned remediation work. Risk stays on the supplier record next to its contracts, services and spend, so a risk decision is never made apart from the business it affects.

  • Weighted risk assessments
  • Continuous monitoring
  • Remediation with owners

Why it matters

A risk score you can explain.

Questr's risk score is a transparent weighted calculation from the answers given, not a black box, and it is labelled that way. Anyone reviewing a supplier can see how the score was reached and when the next assessment is due.

Assess

Questionnaires with a clear score.

Assess suppliers across areas such as compliance, finance, cyber security and concentration. Each answer carries a weight, the score runs from 0 to 100, and the result sets the supplier's risk level. A supplier's risk level can't be typed in by hand; it comes from an assessment.

  • Weighted questions grouped by risk area
  • A 0–100 score banded into low, medium and high
  • Service assessments can build on the supplier's assessment
Monitor

Monitoring that doesn't wait for the annual review.

Reassessment dates follow each supplier's risk level, on a schedule administrators set. Suppliers are screened against the OFAC sanctions list, expiring insurance certificates are flagged, and risk flags can be raised against any supplier at any time.

  • Reassessment cadence by risk level, set by administrators
  • Sanctions screening and insurance expiry alerts
  • Risk exemptions with rules and an audit trail
Remediate

Every finding has an owner and a date.

Turn assessment findings and risk flags into remediation plans with owners, actions and due dates. Overdue work is escalated, and progress is visible on the supplier, in Vendor Management and in the analytics.

  • Remediation plans linked to the finding that started them
  • Escalation of overdue remediation
  • Supplier risk visible on its contracts and in sourcing decisions

Capabilities

What's included.

Risk assessments

Weighted questionnaires with a transparent 0–100 score and risk level.

Reassessment cadence

Next due dates set by risk level, configurable by administrators.

Sanctions screening

Suppliers checked against the OFAC SDN list, which is refreshed regularly.

Insurance tracking

Alerts before a supplier's insurance certificate expires.

Risk register

Risk flags by type and severity, linked to the supplier and any related record.

Remediation

Plans with owners, due dates and escalation, visible across modules.

Questions

Frequently asked questions.

What is third-party risk management?

Third-party risk management (TPRM) is how an organisation identifies, assesses and reduces the risks that come from its suppliers and service providers, such as cyber security, financial, compliance and concentration risk. Questr links that work to the supplier's contracts, services and spend.

Is the risk score AI-generated?

No. The score is a weighted calculation from the assessment answers, and Questr labels it as computed. You can see exactly how a supplier reached its level.

How often are suppliers reassessed?

Administrators set how many days pass between assessments for each risk level, for example yearly for low risk and every six months for high risk. Each supplier's next due date and any overdue status follow from that.

See it working on your own process.

We'll walk through how Questr would fit the way your teams already work.

Request a working session