FAQ
Continuous Monitoring

What is continuous third-party monitoring?

Continuous third-party monitoring is the ongoing collection and review of evidence about external providers between scheduled risk assessments. It complements questionnaires and annual reviews by detecting changes that occur after approval, including new assets, exposed services, vulnerabilities, ownership changes or operational warning signs. Effective monitoring defines thresholds, ownership and response actions so alerts lead to decisions rather than noise. ThingsRecon adds relationship context to externally observed changes, helping organisations distinguish a widespread supplier issue from one that directly affects a critical system or service. In practice, teams should record the supporting evidence, confirm ownership and business criticality, and connect the finding to an accountable workflow. This prevents a useful observation from becoming another isolated score or dashboard alert. The strongest implementation combines external intelligence with internal knowledge, supplier engagement and documented risk decisions, creating a view that remains useful as the digital ecosystem changes.