FAQ
Third-Party Risk Management

What is external vendor-risk monitoring?

External vendor-risk monitoring is the ongoing assessment of supplier signals that can be observed without access to the vendor’s internal systems. It may cover exposed assets, software, certificates, DNS, services, cyber hygiene, business events and publicly reported incidents. External monitoring is scalable and independent of self-reporting, but it cannot show every internal control. ThingsRecon combines external evidence with supplier relationships and Digital Proximity, allowing teams to use it alongside questionnaires, contractual assurance and internal business context. In practice, teams should record the supporting evidence, confirm ownership and business criticality, and connect the finding to an accountable workflow. This prevents a useful observation from becoming another isolated score or dashboard alert. The strongest implementation combines external intelligence with internal knowledge, supplier engagement and documented risk decisions, creating a view that remains useful as the digital ecosystem changes.