Third-party risk management software
TPRM in SecBoard is the vendor file: who the supplier is, what risk level and status they have, which assessment and documents are attached, and which questionnaire they filled.
The vendor record
The module keeps a vendor registry with risk level and status, vendor assessments, and vendor documents. Questionnaires have templates, questions, and conditional logic. A vendor can fill the questionnaire through an external link. Results can be reported and exported.
How it sits next to the ISMS
Supplier review is one input to compliance evidence, especially where PCI DSS or ISO 27001 asks about service providers. The information-security risk register remains the risk module. TPRM does not score a payment transaction.