Vendor risk has moved from a spreadsheet next to the compliance platform to a product inside it. For a team switching platforms, that matters in two ways: you may gain a TPRM tool you did not have, and you may need to move vendor assessments you already keep. This post lists what each platform describes, from pages read on 21 September 2026, and covers one dated announcement from September 2026.
What changed in September 2026?
Scytale's news list shows an AI Third-Party Risk Management launch dated 15 September 2026. We report the launch date and name from its news list; the product page itself was not in our source set.
Source: Scytale security page and news list · read 2026-09-21
What does each platform list for vendor risk?
- Scytale: AI Third-Party Risk Management, launched 15 September 2026.
Source: Scytale security page and news list · read 2026-09-21
- Vanta: a TPRM agent among its products, and vendor risk monitoring by Vanta AI Agent.
Source: Vanta homepage · read 2026-09-21
- Drata: a new Third-Party Risk product on its homepage, and Agentic TPRM Assessment on GRC Enterprise.
Source: Drata homepage · read 2026-09-21
- Sprinto: Autonomous TPRM on its homepage, and vendor risk on Foundation.
Source: Sprinto homepage · read 2026-09-21
- Secureframe: advanced TPRM on the quoted Complete plan.
Source: Secureframe pricing · read 2026-09-21
- Scrut: a Vendor Risk Analyst AI Teammate.
Source: Scrut homepage · read 2026-09-21
- Thoropass and Comp AI: not described on the pages we read.
Source: Thoropass homepage · read 2026-09-21
Why does this matter for a switch?
Vendor assessments are evidence too. SOC 2 and ISO 27001 both expect you to manage the risks from suppliers, and auditors will ask for your vendor list, your assessments and your reviews. If your current platform holds them, export them with the rest of your evidence. If they live in a spreadsheet today, a switch is a natural time to move them into a tool.
Which plan includes it?
This varies, and most vendors do not publish it in detail. Drata places Agentic TPRM Assessment on GRC Enterprise. Secureframe places advanced TPRM on Complete. Sprinto lists vendor risk on Foundation. Vanta, Scytale and Scrut do not tie their TPRM features to a named plan on the pages we read; ask which plan includes them.
What should you ask?
- Can we import our existing vendor list and past assessments?
- Who sends and chases vendor questionnaires: the tool, your team or ours?
- Which plan includes TPRM, and is there a limit on vendors assessed?
How do you move existing vendor assessments?
Treat them like any other evidence. Export the vendor list with owners, risk ratings and review dates, and the completed assessments with the date each was finished. Import the list into the new tool, attach the past assessments as records, and set the next review dates from the original ones rather than from the import day. That keeps the review cycle your auditor has already seen.
TPRM is not one of our seven scored criteria, so it does not change the rankings. It is worth a line in your shortlist if you manage many suppliers.
Who owns vendor risk after the switch?
Name one owner for the vendor list and the review calendar before changeover day. Vendor reviews tend to be the first task dropped during a platform move, because they sit between security, procurement and legal. A named owner and a date for the first review in the new tool keep the cycle unbroken.