Skip to content
#

vendor-risk-management

Here are 34 public repositories matching this topic...

Assessors Studio operationalizes CycloneDX Attestations (CDXA): perform assessments, collect evidence, make claims, and issue machine-readable CycloneDX attestations, optionally legally binding for B2B and B2G use cases.

  • Updated Aug 16, 2026
  • TypeScript

LT-VRM — a free & open-source Third-Party Risk Management (TPRM) / Vendor Risk Management platform: vendor risk assessments, security questionnaires, 0–1000 risk scoring & ratings, contract management, breach & dark-web monitoring, and a vendor portal. Self-hosted on stock XAMPP (PHP + MySQL). Free for the community by LearnTPRM.com.

  • Updated Jun 19, 2026
  • PHP

A complete third-party vendor security risk-assessment framework — questionnaire, live scoring engine, and worked vendor assessments with approve/conditions/reject recommendations. Two-axis inherent×control residual-risk model mapped to NIST 800-161, ISO 27001 & SOC 2.

  • Updated Aug 31, 2026
  • Python

AI-native Third-Party Risk Management platform — automate vendor security questionnaires, evidence review, and continuous monitoring with policy-as-code.

  • Updated Sep 28, 2026
  • Python

Seven GRC artifacts — risk register, SOC 2 readiness walkthrough, vendor risk assessment, NIST CSF 2.0 ↔ ISO 27001 ↔ SOC 2 crosswalk, policy set, and a program self-assessment report — built against a real client engagement, with 94 citations checked against primary sources.

  • Updated Jul 29, 2026

Add this topic to your repo

To associate your repository with the vendor-risk-management topic, visit your repo's landing page and select "manage topics."

Learn more