Third-party risk workflow, screening, and evidence in one place.
AI does the diligence. Your team owns the decision. ThirdParty+ screens your third parties, reads the documents, and drafts a sourced assessment — then hands your team a decision they can review, approve, and defend to an examiner.
Delivered inside the Ethico compliance suite. Founding-partner cohort now forming.
“Who approved this third party — and where's the record?”
It's the question an examiner, an auditor, or your own board will eventually ask about a vendor you approved months ago. In most organizations, answering it means digging through a screening tool, an inbox, a shared drive, a spreadsheet — and one analyst's memory. Not because the team is careless, but because third-party diligence lives in pieces that don't connect.
Who was screened?
What was checked, and what risk was found?
Who reviewed it?
Who approved or rejected the third party?
What documents were collected?
What third parties are overdue for reassessment?
What's being monitored — and what evidence can you show?
If any of those answers live in an inbox, this page is for you.
Diligence is manual, inconsistent, and hard to prove
You screen in one tool. You send questionnaires from another. You track status in a spreadsheet. The reasoning behind each decision lives in an email thread. The work is real — but it varies from analyst to analyst, most of your vendor population gets a lighter touch than your top tier, and when someone asks you to prove the process, the story has to be reconstructed by hand.
Screening hits pile up — and the decision trail disappears
Sanctions, exclusions, watchlists, adverse media: the screening runs, and then an analyst sorts true hits from same-name noise by hand. What happened after the hit? Who reviewed it, who cleared it, and on what basis? In a disconnected process, the hit lives in the screening tool and the decision lives somewhere else — if it was written down at all.
Ownership is fragmented across teams
Third-party risk touches compliance, risk, procurement, legal, IT/security, and finance — and the pain is usually the handoff. A vendor stalls between procurement and compliance. Legal signs a contract before the risk review lands. Without one connected workflow, no team has a complete view, and every handoff is a place where something slips.
The documents are long, and somebody has to read them
Contracts, BAAs, questionnaires, SOC reports, ownership records. Somebody on your team scans a 25-page PDF line by line to find the clause that matters — or doesn't, and the vendor gets approved on a skim. Global and regulated organizations feel this hardest: anti-bribery, sanctions, beneficial ownership, and high-risk jurisdictions make every document a potential landmine.
After approval, nothing happens
Most programs check a vendor once — at onboarding — and never look again. The world changes: ownership changes, sanctions lists change, adverse media appears. Ongoing monitoring and renewal reviews are the maturity gap compliance teams describe most candidly: “Honestly, after approval? Nothing.”
The diligence, done for you — across the whole lifecycle
ThirdParty+ is a single hub for third-party risk: intake, tiering, screening, analysis, action, renewal, and continuous monitoring. Each third party carries its review, its owner, and its evidence forward. AI does the labor at every step; your team reviews, overrides, or approves — and every finding traces back to its source. No black boxes.
Stage 1 · Intake & Tiering
Every third party enters one front door
Intake profiles the vendor and pre-fills the questionnaire from what's already known, so the vendor confirms instead of filling in a blank form. Tiering routes each third party to the right depth of review under rules you set — low-risk vendors don't wait behind high-risk ones, and high-risk vendors don't slip through on a light check.
- Structured intake that captures the vendor profile once
- Agent-assisted pre-fill of intake forms and questionnaires
- Risk tiering under rules you configure
- Dynamic questionnaire routing based on risk level
- Cross-team visibility from the first touch — compliance, risk, procurement, legal, and security see the same record
Stage 2 · Screening with hit validation
Screen everyone. Focus on the hits that matter.
ThirdParty+ screens third parties for sanctions, watchlists, exclusions, and adverse media — powered by our live ComplyAdvantage integration. Then it does the part that usually eats your analyst's day: hits are pre-reviewed so a true match is separated from same-name noise. Your team focuses judgment on the matches that matter, and every hit — cleared or escalated — leaves a record of who decided and why.
- Sanctions, watchlist, exclusion, and adverse-media screening
- ComplyAdvantage integration — live since April 2026
- AI hit validation: pre-reviewed matches, noise cut before it reaches your queue
- Every clearance and escalation documented with reviewer and basis
- Screening connected to the assessment, the approval, and the evidence trail — not stranded in a separate tool
Stage 3 · Document intelligence with citations
Nobody scans a 25-page PDF line by line
ThirdParty+ reads long vendor documents — contracts, BAAs, questionnaires, SOC reports — flags the risks, and pulls the relevant clause with a citation. Ask a question across the case file and get a cited answer. Every synthesis traces to its source, so your team verifies rather than trusts. Fact-checking the AI takes a click, not a re-read.
- Reads contracts, BAAs, questionnaires, and supporting documents
- Proactively flags risks across questionnaires and documents
- Pulls the relevant clause with a citation to the source
- Ask-the-case-file: natural-language questions, cited answers
- Documents tied to the review decision — status, risk, approval, expiration, renewal
Stage 4 · The single-pane sourced assessment
One pane. One sourced draft. Your call.
This is the core moment. ThirdParty+ assembles contract, questionnaire, screening results, and financials into a single view with a consolidated, sourced draft assessment. Every finding links back to where it came from. Your analyst reviews the draft instead of assembling it — and moves from hunting through tools to exercising judgment.
The core moment- Contract, questionnaire, sanctions, and financial picture in one pane
- Consolidated draft assessment, written by AI, sourced end to end
- Every finding traced to its origin — click through to verify
- Full screening data and source documents accessible from the assessment
- Built to flex: embedded best practices, customizable to your program
Stage 5 · Approval & auto-clear
Humans decide. Rules you set handle the rest.
Your analyst approves the assessment, overrides it, or escalates it — in the app, with the decision documented. Low-risk vendors can auto-clear under rules you define, so coverage extends past your top tier without extending your team. Cross-team routing moves the vendor from supply chain to compliance to finance with in-app approve/reject at every step, and each handoff leaves a record.
- In-app approve, reject, override, and escalate — every action logged
- Auto-clear for low-risk tiers under rules you configure
- Cross-team routing with clear ownership at every step
- Escalation paths for flagged and enhanced-review vendors
- Who reviewed, what was found, who approved, and the basis — captured as you work
Stage 6 · Continuous monitoring
From one-time screening to ongoing monitoring
Approval isn't the end of risk — it's the start of the relationship. ThirdParty+ is built to re-score vendors as the world changes: sanctions lists update, adverse media appears, documents expire, reviews come due. A change becomes an owned task with a deadline, not an alert nobody catches. Overdue reassessments surface before an auditor finds them.
- Continuous screening and re-scoring as external data changes
- Renewal and periodic-review cadences by tier
- Changes routed as owned tasks — with an owner and a due date
- Overdue-review views across the whole population
- Document expirations (certificates, BAAs, SOC reports) tracked against the vendor record
Stage 7 · Evidence export
The audit answer, already assembled
Because every step above leaves a record, the evidence exists before anyone asks for it. Who was screened, what was found, who reviewed it, who approved it, what documents were collected, what's overdue, what's being monitored — answerable on demand, from the system, with every answer traced to source. Export it for audit, leadership, or your regulator.
- Exportable evidence on demand — per vendor or across the population
- Decision records: reviewer, finding, approver, basis, timestamp
- Dashboards and overdue-review views for board and audit reporting
- Findings traced to source in the export, not just in the app
Four principles behind ThirdParty+
The diligence, done for you — not just tracked
AI does the work. Not the workflow chart — the work.
Most tools in this category manage the process: they route questionnaires and track status while your analyst still pulls the reports, reads the documents, and writes the assessment by hand. ThirdParty+ does the diligence itself — screening, document reading, drafting — and hands your team a sourced draft to review. Analysts move from assembling assessments to reviewing them.
- Automated entity ingestion, resolution, tiering, screening, and monitoring
- Documents read and clauses pulled with citations
- Draft assessments written, sourced, and ready for review
- Hits pre-reviewed to cut noise
- Auto-clear for low-risk vendors under your rules
One connected workflow, from ingestion to audit
A screening hit feeds the assessment. The assessment feeds the decision. The decision leaves a trail.
The durable problem isn't speed — it's disconnection. ThirdParty+ connects intake, screening, analysis, approval, monitoring, and evidence in one workflow, with cross-team routing so nothing vanishes in a handoff. Each third party carries its review, its owner, and its evidence forward.
- One hub across the full third-party lifecycle
- Cross-team routing with in-app approve/reject and escalation
- Monitoring that turns a change into an owned task
- Screening connected to diligence, approvals, monitoring, and evidence
Evidence that survives an examiner
Every decision documented. Every finding traced to source.
Compliance teams don't just need the work done — they need to prove it. ThirdParty+ keeps the record examiner-ready as you go: who reviewed, what was found, who approved, and on what basis, with each finding traced to its source. When audit asks, the answer is an export, not an archaeology project.
- Decision records captured at the moment of decision
- Findings traced to source — verify, don't trust
- Dashboards, overdue views, and exportable evidence
- The evidence questions, answerable on demand
Delivered through Ethico — trust you already have
Inside the compliance suite you already run
ThirdParty+ launches as part of the Ethico compliance suite — alongside hotline, case management, policy, conflicts, and disclosures. If Ethico is already part of your compliance program, third-party risk becomes an extension of a relationship you trust, not a bet on an unknown vendor. And it's built to work alongside your existing GRC stack.
- Part of the Ethico compliance suite
- White-glove onboarding with embedded best practices
- Highly customizable for complex enterprise needs
- Forward-deployed “done-for-you” delivery option available
White-glove by default. Done-for-you if you want it.
ThirdParty+ ships with embedded best practices and is highly customizable — built to flex with complex enterprise programs. Every implementation includes white-glove onboarding to tailor the platform to your tiers, rules, and workflows. And for teams that want the outcome more than the tooling, our forward-deployed option hands back completed assessments: we run the diligence in ThirdParty+, your team owns the decisions.
Embedded best practices
What it means
Sensible tiering, screening, and workflow defaults out of the box
Best for
Teams that want to start fast
White-glove onboarding
What it means
We configure ThirdParty+ to your program — tiers, rules, routing, evidence needs
Best for
Every customer — included
Forward-deployed delivery
What it means
We hand back completed, sourced assessments; your team reviews and decides
Best for
Teams with a backlog, a surge, or no spare headcount
Where ThirdParty+ fits in the third-party risk landscape
Most teams we talk to aren't replacing a dominant incumbent — they're connecting pieces that never talked to each other: a screening tool here, a questionnaire there, a spreadsheet holding it together. Here's an honest view of the categories, including where each one is genuinely useful.
| Capability | ThirdParty+ | Manual / consultants | Workflow tools | Security ratings | Data vendors | AI-native tools |
|---|---|---|---|---|---|---|
| Does the diligence work | Yes | People do | Tracks it | Scores cyber | Feeds data | Varies |
| Full-TPDD scope (regulatory, financial, sanctions, adverse media, cyber) | Yes | Partial | Partial | Cyber only | Raw inputs | Often single-lane |
| Covers the whole population | Built to | Sample | Headcount-bound | Continuous, cyber-only | n/a | Varies |
| Every finding traced to source | Yes | Rarely written down | Partial | Proprietary grade | Raw data | Summary |
| Examiner-ready evidence | Built to be | Partial | Partial | No | No | Partial |
| Human owns the decision | Yes | Yes | Yes | n/a | n/a | Varies |
Category-level comparison reflecting how these tool classes typically operate. Individual products vary — we're happy to walk through your specific stack in a demo.
Workflow platforms
Real, deployed, and useful for what they do — they digitize and track the process. The question to ask: inside that platform, who actually does the diligence — pulls the reports, reads the documents, writes the assessment? If the answer is “our analysts,” that's the gap ThirdParty+ closes. Keep the platform for what it's good at; ThirdParty+ owns the third-party diligence itself.
Security-ratings tools
Genuinely useful, and often already in your stack. Keep them. A cyber score is one input into a third-party decision — it won't answer sanctions, ownership, or financial-health diligence, and it won't document the call for an examiner. They grade the vendor; ThirdParty+ assesses and documents the call.
Data vendors
Ingredients, not competitors — and good ones. ThirdParty+ is the decisioning layer on top: it's built to run on authoritative sources, reconcile them, and land the evidence where the decision lives. If all you want is a cheaper data feed, a data provider is honestly the better buy.
Doing nothing
The most common alternative — a spreadsheet, a questionnaire inbox, and one analyst's memory. It works until an examiner asks for proof, or an unassessed vendor becomes the headline. If that's your current state, start with one question: pick a vendor you approved last year. Who approved it — and where's the record?
Third-party risk, inside the compliance suite you already trust
Ethico's vision is a connected compliance program: hotline, case management, policy, conflicts, disclosures, investigations — and now third-party risk — connected by evidence, workflow, and accountability. ThirdParty+ brings third-party due diligence into that picture. For existing Ethico customers, that means one vendor relationship, one trust decision, and a consolidation story your CFO will appreciate.
- Launches as part of the Ethico compliance suite
- One place for compliance workflow and evidence across programs
- Built to work alongside your existing GRC stack (statement of intent — see FAQ for our honest integration answer)
- Backed by Ethico's compliance expertise and support model
Built on what compliance teams told us
Before building ThirdParty+'s go-to-market, Ethico ran a voice-of-customer study across recorded conversations with its customer and prospect base. 360 conversations across 286 companies contained meaningful third-party risk signal, including 230 strong conversations where buyers discussed third-party due diligence, vendor risk, screening, onboarding, monitoring, assessments, or workflow.
The pattern was consistent: the pain isn't the absence of tools — it's that due diligence is manual, inconsistent, and hard to prove; screening is disconnected from decisions and evidence; ownership fragments across teams; and monitoring after approval is the maturity gap almost everyone admits to. Prospects respond most positively when third-party risk value is shown through specific use cases: screening third parties, collecting due diligence, automating follow-up, monitoring ongoing risk, and reporting on vendor status and evidence.
ThirdParty+ is our answer to exactly that list.
Don't take our word for it. Run it on your own past approvals.
The fastest way to evaluate ThirdParty+ isn't a slide deck — it's your own vendor population. In a Retroactive Proof of Concept, we run ThirdParty+ over third parties you've already approved and show you what a full, connected review finds: a screening hit that was never dispositioned, a missing BAA, an approval with no evidence behind it. If the run comes back clean, you'll know that too — a clean run is a real answer, and it still shows you coverage, citations, and evidence in action on your own data.
Ask about the Retroactive POC in your demoFrequently asked questions
Pick a vendor you approved last year. Who approved it — and where's the record?
If answering that takes more than a minute, come see what one connected workflow looks like. We'll tailor the demo to your industry, your third-party population, and your current process — and if you want the strongest possible proof, ask us to run the Retroactive POC on your own past approvals.
30-minute personalized demo. Screening with hit validation, document citations, and the single-pane sourced assessment — live.
About ThirdParty+
ThirdParty+ is Ethico's AI-native third-party due diligence platform, launching July 2026 as part of the Ethico compliance suite. It was built on first-party research with Ethico's compliance customer base — a voice-of-customer study in which 360 conversations across 286 companies contained meaningful third-party risk signal — and designed around the principle that AI should do the diligence work while compliance professionals own the decisions. Every AI finding in ThirdParty+ is cited to its source. Screening is powered by a live ComplyAdvantage integration (since April 2026).
Content reviewed by Ethico's Product Marketing and Compliance Advisory teams. All claims on this page are governed by the ThirdParty+ Master Fact Sheet.