eTPRM: the same risk criterion for each supplier,service and corporate area.
SaaS platform to assess the risk of privacy, cybersecurity and other compliance domains in third parties and corporate areas: risk proportional questionnaires, evidence with full traceability and AI-assisted preliminary review (MIA).
Third-party due diligence has become a central control point in operational resilience and cybersecurity, in a regulatory environment that requires organizations to accredit control of their supply chain.
–%
of reported gaps originate in the supply chain
+
regulations and standards with demands on third parties
A platform that works autonomously, with an expert team that can reinforce its operation
eTPRM is a complete platform on its own: the organization's team can launch questionnaires, ask for evidence, review it and approve results without relying on ECIX. The most critical review and validation can also be provided by the ECIX expert team, with a defined scope and conditions of service together with the organization.
- Configuration of questionnaires, domains and scoring criteria.
- Launch, follow-up and notifications of each evaluation.
- Review and approval of evidence for the roles you define.
- Automatic calculation of results, dashboards and reports.
- AI-assisted preliminary review (MIA) across the platform.
- Expert validation of critical or doubtful evidence.
- Interpretation of results and prioritization of risks.
- Preparation of executive reports ready for management.
- Regulatory support in privacy, cybersecurity and auditing.
- Equipment sized according to the volume of third parties to be evaluated, with the capacity to absorb demand peaks.
Why third-party management has become a matter of governance, not just operational
Third-party management often encounters the same obstacles, regardless of industry or organization size. eTPRM is designed to respond to each of them.
One evaluation cycle with six steps, not six mail exchanges
Applicable to both external suppliers and corporate areas. The review and approval steps can be carried out by the organization's team from the platform; they can also be carried out by the ECIX expert team.
- 1Discharge and assignmentThe third party, the corporate area or the service line is registered and assigned the questionnaire that corresponds to its type and criticality.Platform
- 2Short or complete questionnaireShort forms for agility and cases of lower criticality; complete questionnaires with evidence for those with the greatest impact.Platform
- 3Preliminary review with AIMIA identifies inconsistencies, expired or incomplete evidence before it reaches a reviewer.Assisted by MIA
- 4Revision and approvalA manager reviews the indicated evidence and approves the result before closing it.PlatformIt can be done by the organization team, or the ECIX expert team.
- 5Risk ResultThe rating obtained is combined with the level of impact of the service to determine the actual level of risk.Platform
- 6Reporting and Follow-UpScorecards, executive and technical reports, and gap tracking until closing.Platform
What the platform manages for you
eTPRM centralizes the entire evaluation process, preventing information from being distributed among documents, emails and spreadsheets.
Beyond Privacy and Cybersecurity: A Model by Risk Domains
eTPRM organizes assessments by domains and subdomains, not by vendor in a generic way. Privacy and cybersecurity are the two domains with the greatest functional development, and each translates into controls aligned with the regulatory frameworks that apply according to the sector and the country.
- Governance of privacy and internal responsibilities.
- Registration, legal basis and purpose of the processing.
- Information, transparency and rights of data subjects.
- Impact assessments (DPIA) and privacy by design.
- International transfers and relationship with processors.
- Breach management and treatment security measures.
- Security governance and asset classification.
- Access control, identities and network security.
- Management of vulnerabilities and security incidents.
- Business continuity and disaster recovery.
- Security in the cloud and in outsourced services.
- Supply chain security and OT/IoT environments.
The results can also be added and consulted by other risk axes, so that each area of the organization gets the reading it needs:
AI accelerates review.The risk decision is always made by an expert.
MIA is the artificial intelligence layer included in the platform. Supports preliminary review of questionnaires and evidence; does not substitute for risk decision.
Preliminarily reviews the answers and evidence of each questionnaire: detects inconsistencies, expired or incomplete documents, groups the findings by domain and prepares a draft summary for those who must review it.
The validation of critical evidence, the final qualification and the issuance of the report are always decided by an expert manager or team: the organization's team, or the ECIX expert team. MIA does not approve of evidence or substitute for that decision.
The TÉN (Technological, Ethical and Regulatory) Framework of ECIX defines what information MIA uses, what traceability is recorded and at what points in the process expert supervision is maintained. The AI model is developed by ECIX itself, and has been developed within the framework of an innovation project in public procurement promoted by INCIBE.
From completed questionnaires to information ready to decide
The platform automatically generates these reports and dashboards based on the results of each cycle, with a different level of detail depending on who they are aimed at.
- Segmentation by supplier, corporate area, region, domain or level of risk.
- Complete traceability of evidence, reviews and approvals.
- Export to the organization's analysis and reporting systems, assessing in each case the most appropriate format and integration.
| Report | What it's for |
|---|---|
| Executive | Summary of results, main risks and priorities for management. |
| Technician | Detail of responses, controls, evidence and recommendations. |
| By supplier /corporate area | Consolidated view of the risk associated with a third party or corporate area. |
| By Domain | Specific analysis of privacy, cybersecurity or other evaluated domains. |
| Monitoring | Status of improvement and evolution actions compared to previous cycles. |
Benefits of the platform and benefits of the ECIX expert team
We separate what the platform brings from what the ECIX expert team brings, so that the organization decides who executes each part of the process.
Area managers
Platform, ECIX expert team, or both?
Please tell us how many third parties, corporate areas or service lines you evaluate and who would perform the review. In a short conversation, we assess whether the platform is enough for you or whether the review should be provided by the ECIX expert team.




