Skip to content
Solution · Third party risk and corporate areas

eTPRM: the same risk criterion for each supplier,service and corporate area.

SaaS platform to assess the risk of privacy, cybersecurity and other compliance domains in third parties and corporate areas: risk proportional questionnaires, evidence with full traceability and AI-assisted preliminary review (MIA).

At a glance
eTPRM Platform
QuestionnairesEvidenceScorecards
may be combined with
ECIX Expert Team
ValidationInterpretationExecutive reports
Two independent layers. The organization decides which combination to operate with.

Third-party due diligence has become a central control point in operational resilience and cybersecurity, in a regulatory environment that requires organizations to accredit control of their supply chain.

%

of reported gaps originate in the supply chain

+

regulations and standards with demands on third parties

Operation Model

A platform that works autonomously, with an expert team that can reinforce its operation

eTPRM is a complete platform on its own: the organization's team can launch questionnaires, ask for evidence, review it and approve results without relying on ECIX. The most critical review and validation can also be provided by the ECIX expert team, with a defined scope and conditions of service together with the organization.

The eTPRM platform
SaaS Platform
  • Configuration of questionnaires, domains and scoring criteria.
  • Launch, follow-up and notifications of each evaluation.
  • Review and approval of evidence for the roles you define.
  • Automatic calculation of results, dashboards and reports.
  • AI-assisted preliminary review (MIA) across the platform.
Fully manageable by your organization's compliance, privacy, cybersecurity, or procurement team.
ECIX Expert Team
Lent by ECIX
  • Expert validation of critical or doubtful evidence.
  • Interpretation of results and prioritization of risks.
  • Preparation of executive reports ready for management.
  • Regulatory support in privacy, cybersecurity and auditing.
  • Equipment sized according to the volume of third parties to be evaluated, with the capacity to absorb demand peaks.
Provided by ECIX specialists in privacy, cybersecurity and auditing, with a defined scope and SLA together with the organization.
Context

Why third-party management has become a matter of governance, not just operational

Third-party management often encounters the same obstacles, regardless of industry or organization size. eTPRM is designed to respond to each of them.

Governance
A cross-cutting process, with different interests at stake
Purchasing, privacy, cybersecurity, and business all participate in the same process. eTPRM defines roles, statuses, and approval flows so that each profile knows what belongs to them.
Volume and scalability
An increasing number of third parties and interactions
The homologation, monitoring and closure of each relationship multiply the interactions to be managed. The platform scales without redesigning the model.
Classification
Not all third parties pose the same risk
A previous triage makes it possible to distinguish which third parties require a short questionnaire and which need a complete evaluation with evidence.
Homogeneous criterion
Disparity of criteria between those who evaluate
When different people apply different criteria, the results are no longer comparable. eTPRM applies the same scoring methodology and evidence throughout the organization.
History and evolution
Losing traceability between evaluation cycles
The history of each third party allows for more precise and rigorous decisions. The platform preserves the evolution of each evaluation, review and evidence between cycles.
What changes with eTPRM
Spreadsheets and scattered emailsA single assessment environment
"the supplier" is evaluated in generalEach service line is evaluated
Same effort for all casesEffort proportional to risk
The review depends on the person requesting itDefined roles, statuses, and approvals
How it works

One evaluation cycle with six steps, not six mail exchanges

Applicable to both external suppliers and corporate areas. The review and approval steps can be carried out by the organization's team from the platform; they can also be carried out by the ECIX expert team.

  1. 1
    Discharge and assignment
    The third party, the corporate area or the service line is registered and assigned the questionnaire that corresponds to its type and criticality.
    Platform
  2. 2
    Short or complete questionnaire
    Short forms for agility and cases of lower criticality; complete questionnaires with evidence for those with the greatest impact.
    Platform
  3. 3
    Preliminary review with AI
    MIA identifies inconsistencies, expired or incomplete evidence before it reaches a reviewer.
    Assisted by MIA
  4. 4
    Revision and approval
    A manager reviews the indicated evidence and approves the result before closing it.
    Platform
    It can be done by the organization team, or the ECIX expert team.
  5. 5
    Risk Result
    The rating obtained is combined with the level of impact of the service to determine the actual level of risk.
    Platform
  6. 6
    Reporting and Follow-Up
    Scorecards, executive and technical reports, and gap tracking until closing.
    Platform
Available on the platform, for your team
Automated by ECIX AI (MIA), with supervision
It can be provided by the ECIX expert team
Features

What the platform manages for you

eTPRM centralizes the entire evaluation process, preventing information from being distributed among documents, emails and spreadsheets.

Service Line Assessment
The supplier is not evaluated in general, but the specific risk of each service provided. Avoid inaccurate aggregate conclusions.
Risk proportional questionnaires
Short forms, designed to be completed in less than an hour, and complete questionnaires with evidence for the cases of greatest impact.
Evidence with traceability and reuse
Loading, versioning, expiration control and reuse of evidence between cycles, service lines or equivalent regulatory frameworks.
Roles, Statuses, and Approval Flows
Each profile - internal, of the third party or reviewer - sees only what corresponds to it. The statuses of each assessment are always visible.
Global and local dashboards
Aggregate program vision and views segmented by region, corporate area, domain, or impact level.
Multi-language and multi-country
Equivalent questionnaires, aids and reports between languages, with centralised governance of translations to avoid divergences.
Domains and frames of reference

Beyond Privacy and Cybersecurity: A Model by Risk Domains

eTPRM organizes assessments by domains and subdomains, not by vendor in a generic way. Privacy and cybersecurity are the two domains with the greatest functional development, and each translates into controls aligned with the regulatory frameworks that apply according to the sector and the country.

Privacy and data protection
  • Governance of privacy and internal responsibilities.
  • Registration, legal basis and purpose of the processing.
  • Information, transparency and rights of data subjects.
  • Impact assessments (DPIA) and privacy by design.
  • International transfers and relationship with processors.
  • Breach management and treatment security measures.
Cybersecurity and information security:
  • Security governance and asset classification.
  • Access control, identities and network security.
  • Management of vulnerabilities and security incidents.
  • Business continuity and disaster recovery.
  • Security in the cloud and in outsourced services.
  • Supply chain security and OT/IoT environments.
Applicable frameworks and standardsThe same control can accredit requirements of several frameworks at the same time, without duplicating questionnaires or evidence.
GDPR / LOPDGDDPrivacy
Legal basis, rights of data subjects, transfers and gap management.
NIS2cybersecurity
Risk, continuity and incident management in the supply chain.
ISO/IEC 27001cybersecurity
Comparable information security controls across organizations.
NISTcybersecurity
Maturity by functions: identification, protection, detection and response.
ENSPublic sector
Categorization and measures for relations with public administrations.
DORA
United Financial sector 11.32
Digital resilience and ICT risk in financial sector providers.
AI RegulationArtificial Intelligence
Obligations applicable to the use of AI systems by third parties.
ISO/IEC 42001Artificial Intelligence
Responsible management of artificial intelligence systems.
CS3DSustainability
Due diligence on human rights and the environment in the value chain.
SOC 2Cloud services
Security, availability and confidentiality in outsourced services.

The results can also be added and consulted by other risk axes, so that each area of the organization gets the reading it needs:

Other Legal & Compliance RisksThird Parties and Supply ChainOperational Continuity and ResilienceGovernance and internal policiesHuman and organizational risks
MIA · supervised artificial intelligence

AI accelerates review.The risk decision is always made by an expert.

MIA is the artificial intelligence layer included in the platform. Supports preliminary review of questionnaires and evidence; does not substitute for risk decision.

The questionnaire and its evidence are received
MIA reviews and groups the findings
An expert manager or team decides

Preliminarily reviews the answers and evidence of each questionnaire: detects inconsistencies, expired or incomplete documents, groups the findings by domain and prepares a draft summary for those who must review it.

Reporting and Data Exploitation

From completed questionnaires to information ready to decide

The platform automatically generates these reports and dashboards based on the results of each cycle, with a different level of detail depending on who they are aimed at.

  • Segmentation by supplier, corporate area, region, domain or level of risk.
  • Complete traceability of evidence, reviews and approvals.
  • Export to the organization's analysis and reporting systems, assessing in each case the most appropriate format and integration.
The interpretation of these reports and their preparation for management, risk committee or audit can also be provided by the ECIX expert team.
ReportWhat it's for
ExecutiveSummary of results, main risks and priorities for management.
TechnicianDetail of responses, controls, evidence and recommendations.
By supplier /corporate areaConsolidated view of the risk associated with a third party or corporate area.
By DomainSpecific analysis of privacy, cybersecurity or other evaluated domains.
MonitoringStatus of improvement and evolution actions compared to previous cycles.
What each layer brings

Benefits of the platform and benefits of the ECIX expert team

We separate what the platform brings from what the ECIX expert team brings, so that the organization decides who executes each part of the process.

Included in the eTPRM platformSaaS Platform
Methodological homogeneity
The same evaluation criteria, scoring and evidences are applied in all regions, corporate areas and suppliers.
Advocate Evidence
Complete traceability of actions, reviews and decisions, ready for an audit, inspection or internal review.
Less operating load
Notifications, reuse of evidence and AI-assisted preliminary review for the most repetitive tasks.
Scalable to multinational contexts
Expand the number of third parties, corporate areas, countries and languages without having to redefine the model from scratch.
ECIX Expert TeamLent by ECIX
Expert supervision
Specialists in privacy, cybersecurity and auditing validate the most critical or doubtful evidence and answers.
Interpretation of the results
Expert reading of gaps and risks, and help to prioritize what to remedy first.
Address Ready Reports
Preparation of executive and technical reports, and support in their presentation to committees or councils.
Regulatory accompaniment
Expert criteria in the face of regulatory changes and preparation of information for audit or supervision.
Equipment sized according to demand
In comparable projects, it allows the same result to be obtained with significantly less internal dedication, adjusting the team to peaks and valleys of activity.

Area managers

Platform, ECIX expert team, or both?

Please tell us how many third parties, corporate areas or service lines you evaluate and who would perform the review. In a short conversation, we assess whether the platform is enough for you or whether the review should be provided by the ECIX expert team.