Properly documenting each third party is essential for effective risk management, operational transparency and compliance. The details panel organises the record into tabs; most fields draw their options from your workspace catalogues, and tabs or fields your organisation has switched off in the framing settings do not appear.

1. Information

The Information tab holds the identity of the relationship:

  • Third Party Name and Third Party Description & Information: who the third party is and how it relates to your organisation. The description supports rich text.
  • Third Party Parent Company: if applicable.
  • Third Party Contact: your contact person at the third party.
  • Business Unit: the unit(s) the relationship belongs to.
  • Third Party Region and Third Party Country: where the third party operates.
  • Third Party Type: for example vendor and suppliers, client, partner, distributor, regulator.
  • Third Party IT Provider Type: for example IT software, IT services, network and telecom, payment processor.
  • Third Party Tier level: the criticality ranking (for example Tier 1 to Tier 4).

2. Data Classification

This tab describes the data shared with or accessed by the third party:

  • CIA Levels of Processed Data: a table with one row per information type involved in the relationship. For each row you select a Confidentiality, Integrity and Availability level from your workspace's CIA Levels catalogue. The table computes the Security Objectives (highest level per column) and the Overall Third Party Security Categorization.
  • Data Classification: the sensitivity of the data (for example Public, Internal, Confidential).
  • PII and PHI: switches indicating whether Personally Identifiable Information or Protected Health Information is involved.

Map the interconnections between the third party and your internal systems:

  1. Open the Related Systems tab.
  2. Click Add Related Systems and search for a system by its SYS reference.
  3. Select one or more systems and add them. A link can be removed later from the same tab.

Note: viewing and linking related systems requires read access to the Systems module.

4. Complementary Information

Free text for anything that improves the understanding of the relationship: roles and responsibilities, involvement in critical processes, contractual obligations, compliance requirements or performance considerations.

5. Ownership, Evidence and Risk Assessments

The rest of the documentation lives in the header actions of the details panel:

  • Owners & Contacts: assign the internal workspace members accountable for the relationship, so ownership is explicit.
  • Evidence: attach supporting documents or links (contracts, certifications, questionnaires). If your workspace restricts evidence storage (Settings, Evidences), the drawer accepts links only.
  • Comments: keep the discussion next to the record.
  • Risk assessments: click the assessment badge in the header to link the third party to completed risk assessment demands (searched by their RAD reference) and to set the review periodicity. When a new assessment is linked, the earlier one moves to Previous Assessments for historical tracking.
  • Share Forms: send forms (for example due-diligence questionnaires) and track the responses.

Edits made in the tabs are committed together through the save bar at the bottom of the page.