Continuous Assessments
Automated control assessments via questionnaires, audit reports, and external scanning. Compliance status refreshes monthly without manual chase-ups.
Monitor suppliers, dependencies, control evidence and remediation actions without relying on annual questionnaires alone.

Third-party vendor risk is assessed once per contract, then forgotten. Supplier compliance drifts. Breaches at critical partners go undetected until they impact you.
Automated control assessments via questionnaires, audit reports, and external scanning. Compliance status refreshes monthly without manual chase-ups.
Suppliers scored by controls coverage, remediation responsiveness, and breach history. Portfolio risk visualised by criticality and risk tier. Integrates with SecurityScorecard, BitSight, and EcoVadis for external risk signals.
Supplier breaches, CVEs, and compliance lapses trigger automatic risk recalculation and escalation workflows for dependent systems.
Complete vendor risk history documented for regulatory oversight. Assessment responses and remediation evidence pre-packaged for auditors. Includes data processing agreement (DPA) lifecycle management and sub-processor cascade tracking.
Fig Group brings supplier assessments, risk context and follow-up actions into one workflow. Start with the service a supplier delivers, the information it can access and the business impact of failure, then use evidence to decide the review and treatment required.
Record the supplier owner, service, data access, dependencies and contract context before assessing controls. Review questionnaire answers alongside supporting documents and available external signals. Keep inherent criticality, evidence gaps and residual risk distinguishable; missing evidence is unknown, not proof that a control passed.
Agree a review cadence based on criticality, contractual obligations and evidence expiry. Reassess when a service changes, a material incident occurs or remediation is overdue. Confirm the refresh frequency of each connected source during onboarding; an annual questionnaire and a frequently updated external signal provide different coverage.
External signals can identify issues that warrant investigation, but they do not establish the effectiveness of every internal control or guarantee that a supplier is safe. Confirm the supported feeds and assessment paths in your scope. Assign an owner to investigate material changes, request evidence and escalate unresolved risk to the authorised decision-maker.
A fictional payroll supplier holds employee information but supplies an expired assurance report. Record the evidence gap, request a current report and assign a review deadline. The owner decides whether temporary acceptance is justified, with conditions and a review date; the expired report is not counted as current assurance.
Ask to see the supplier assessment, its supporting evidence, the resulting action and the approval history together. Confirm how an overdue response is surfaced.
Discuss this workflow with FigExplore the supplier governance view within the Fig platform.
A tailored walkthrough lets you review the relevant workflows, supported connections and reporting before deciding whether Fig is right for your team.
See it in a demo

Bring delivery, oversight and assurance together without losing sight of who owns the next action.

Third-party risk management for your entire client base. White-label vendor assessments and risk reporting strengthen your MSP compliance story.
Explore Fig for MSPs
Board and risk committee visibility into supplier compliance. Automate vendor audits and reduce due diligence workload for procurement and legal teams.
Explore Fig for organisations
Documented vendor risk assessments, remediation tracking, and breach impact analysis for third-party risk control audits.
Discuss your requirementsStart with the outcomes you need. We will discuss scope, delivery and commercial terms with you before you commit.
Agree the first supplier group, service owners, data access and dependency records. Identify the evidence needed for approval.
Choose relevant questions and available sources, document the scoring approach and agree how unknown or expired evidence will be handled.
Follow an unresolved finding through an assigned action and approval decision. Set the next review and material-change triggers before expanding coverage.
Platform functionality and automation depend on the agreed scope, configuration and connected systems. Software supports your compliance programme; it does not replace an independent assessment or guarantee certification.
Need to discuss a specific requirement or client scenario?
Speak to FigFig Group offers multiple assessment paths: automated external scans (no supplier action), questionnaires (email-based), and integration with vendor risk platforms. Choose the path that suits your supplier relationships.
You define supplier criticality based on data access, system dependencies, or regulatory scope. Risk scores then emphasise critical suppliers, ensuring your team focuses remediation efforts where impact is highest.
There is no limit. Fig Group scales from a handful of critical suppliers to hundreds of vendors. Risk scoring and alerting apply consistently regardless of portfolio size.
Fig Group flags non-responsive suppliers and escalates them through your defined workflow. You can also assess non-responsive suppliers using external scanning data alone, which gives you a partial risk score without requiring any supplier action.
Yes. MSPs can generate white-labelled supplier risk summaries for their clients. Reports show assessment status, risk scores, and remediation progress without exposing your internal methodology or scoring logic.
A useful supplier-risk assessment links the service you depend on to data access, disruption impact, control evidence and a documented decision. This example shows how to record uncertainty and actions before onboarding a supplier.
Use the guide and templateTell us what you would like to achieve. We will arrange a relevant conversation about the platform, your requirements and the right next step.
Continue exploring the protect capabilities, or return to the full platform overview.