Most third-party risk programs end the same way: a folder of completed questionnaires nobody has scored, filed against vendors nobody has re-assessed since onboarding.

The questionnaire got answered. The risk never got measured. When the auditor asks why a critical cloud provider is rated "acceptable," the honest answer is that a spreadsheet averaged 200 green cells against three red ones and called it a day.

That is not third-party risk management. It is a questionnaire graveyard with a compliance label on it.

Aigis was built to do the opposite: turn every vendor into a scored, evidenced record, bound to the specific third-party obligations that govern it. Not a static form. A live posture you can put in front of a regulator.

The supplier as a first-class record

The first structural fix is where vendor data lives.

In most programs, a supplier is scattered: the questionnaire is in one tool, the data-processing agreement is in a shared drive, the risk rating is in a spreadsheet, the evidence is in someone's inbox. Nothing reconciles. Nobody can answer "what is our exposure to this vendor" in one view.

In Aigis, the supplier is a first-class entity - a single source-of-truth record. Assessments, DPA state, the current score, and every piece of supporting evidence sit in one place, on one object. When the score moves, you can trace it to the answer and the evidence that moved it. When the DPA lapses, the record shows it.

This matters because DORA's ICT third-party risk provisions require financial entities to maintain a register of information covering all contractual arrangements for ICT services, distinguishing those that support critical or important functions from those that do not. A register is not a filing cabinet. It is a live, queryable record you hand to a competent authority on request. A supplier SSoT is what makes that register real instead of aspirational.

Weighted, gated scoring - so a critical gap can't be averaged away

The core defect in questionnaire-based TPRM is arithmetic. A simple average lets a vendor bury a critical failure under a pile of trivial passes. Encryption at rest is missing, but the vendor answered ninety other questions correctly, so the mean still reads "low risk."

An auditor sees through that in one question: "How is a missing critical control producing a passing score?"

Aigis scores vendors on a weighted, gated 0–100 model. Weighted, so a control's contribution reflects its actual importance, not one-question-one-vote. Gated, so a critical gap caps the score regardless of how many minor questions passed. A vendor missing a mandatory control cannot average its way to green. The gate holds it down until the gap is closed.

That is the difference between a number and a defensible number. When the score is gated, you can explain to an auditor exactly why a vendor is rated where it is: here is the critical control that failed, here is the gate it tripped, here is the evidence. The rating is reproducible, not a judgment call someone made in a spreadsheet and cannot reconstruct six months later.

This is the same discipline that runs through the rest of the platform. A score is only as trustworthy as the obligation it maps to. Scoring bound to source obligations is what makes third-party risk defensible - the gate isn't an opinion about severity, it's tied to a requirement that traces back to regulation text.

Tiered assessments scaled to vendor criticality

Sending every vendor the full assessment is how you get the graveyard. A cleaning contractor with no system access does not need the same 200-question battery as a provider running a critical or important function on your production data. Send them the same form and both come back late, badly, or not at all.

DORA builds proportionality directly into ICT third-party risk management: the depth of oversight scales with the nature, scale, complexity and criticality of the service. A provider supporting a critical or important function carries a heavier contractual and monitoring burden than a peripheral one.

Aigis mirrors that. Assessments are tiered to vendor criticality. A low-impact contractor answers a handful of questions. A critical cloud provider gets the full set - data location, sub-processing, access and audit rights, exit and continuity, the elements that matter when the function is one you cannot afford to lose.

The tier is not cosmetic. It determines which obligations attach, how the score is gated, and how often the vendor is re-assessed. Criticality drives the workload, so the workload lands where the risk actually is.

A guest portal vendors actually finish

None of this works if the vendor never completes the assessment. And the single biggest reason vendors stall is the login wall - create an account, verify an email, set a password, recover the password they set and forgot, for a system they will use once.

Aigis uses an email-OTP guest portal. The vendor gets a link, receives a one-time code at their work email, and answers. No account to create. No credential to manage. The guest session is disjoint from your tenant, so a vendor contact never touches your internal environment.

Completion rate is the hidden variable in every TPRM program. An assessment nobody finishes produces no score, and a vendor with no score is an unmeasured risk sitting in your register. Removing the account-creation friction is not a convenience feature. It is what turns a sent assessment into a scored one.

DPA state, unified and bound to processor duties

Where a vendor processes personal data, the data-processing agreement is not paperwork you file and forget. Under GDPR, a controller may only use processors that provide sufficient guarantees, under a binding written contract that governs the processing. The DPA is a live obligation, and its state - in place, pending, expired, missing - is part of the vendor's risk, not a separate track.

DORA reinforces this on the ICT side. Contractual arrangements for ICT services have to address the protection of data including personal data, data location and processing regions, and access, recovery and return of data on termination or provider insolvency.

Aigis unifies DPA state onto the supplier record and binds it to those processor duties. The DPA is not a PDF in a drawer. It is a state on the vendor object, feeding the score and the obligation map. A missing or expired DPA on a vendor processing personal data is a gap the gate can act on, not a footnote someone notices during the next audit.

Every supplier mapped to the obligations that govern it

Here is what ties it together. A vendor's risk is not a free-floating number. It is measured against the specific third-party obligations that apply to that vendor, in your regulatory context.

For a financial entity, that means DORA's ICT third-party oversight - the register, the pre-contract risk assessment and due diligence, concentration-risk analysis, the key contractual provisions, exit strategies for critical or important functions. For entities in scope of NIS2, supply-chain security obligations apply in parallel. Where personal data is involved, GDPR processor duties attach. One vendor, several overlapping regimes.

Aigis maps each supplier to the obligations that govern it and scores against those obligations, with each one traceable back to the source regulation text. That is the launch thread running through the whole platform: your agents do the work, our engine keeps it honest. You - or your own agents over MCP - can gather vendor evidence, tick controls, and update posture, and every submission lands on a source-cited record. Bring your own agent, Claude Code or any MCP client, and the scoring stays grounded in the obligation, not generated from a model's memory.

That is the line between a vendor rating you hope holds up and one you can defend in front of a regulator, a board, or a plaintiff.

See it on your own vendors

Third-party risk is defensible when the score is gated, the evidence is attached, and every obligation traces to the regulation that imposed it.

See how Aigis scores and evidences vendor risk against DORA, NIS2 and GDPR at agrc.ai. Inside 60 minutes you will see a supplier mapped to the obligations that actually govern it, scored on a model an auditor can follow.

FAQ

How is a gated 0–100 score different from a normal risk rating? A normal rating usually averages questionnaire answers, which lets a vendor offset a critical failure with many minor passes. A gated score caps the result when a mandatory control is missing, so a critical gap cannot be averaged away. The number stays low until the gap is closed, and you can trace the cap to the specific control and evidence that triggered it.

Does the vendor need an account to complete an assessment? No. Aigis uses an email-OTP guest portal. The vendor receives a link, gets a one-time code at their work email, and answers. There is no account to create and no password to manage, which is the main reason assessments get finished rather than abandoned. The guest session is separate from your tenant.

How does Aigis handle a vendor that falls under DORA, NIS2 and GDPR at once? Each supplier is mapped to the obligations that govern it across every applicable regime, and overlapping requirements are resolved rather than duplicated. A single vendor can carry DORA ICT third-party obligations, NIS2 supply-chain obligations, and GDPR processor duties on one record, each traceable to its source text.

Where does the DPA fit into vendor scoring? DPA state is unified onto the supplier record and bound to GDPR processor duties, not tracked separately. An in-place, expired, or missing DPA is part of the vendor's measured posture and can trip the score gate where personal data is involved, so the agreement stays a live obligation instead of a filed document.