# Rescana > Rescana provides autonomous AI agents that execute third-party risk management (TPRM) securely at scale: continuous vendor monitoring, evidence-based risk scoring, and automated incident response. ## TPRM Knowledge Base - [What is TPRM?](https://www.rescana.com/learn/third-party-risk-management/): A practical definition of third-party risk management: the TPRM lifecycle, the difference between inherent and residual risk, and why programs built on questionnaires and spreadsheets struggle to keep up. - [Why manual vendor risk assessment doesn't scale](https://www.rescana.com/learn/manual-vendor-risk-assessment/): Spreadsheet- and questionnaire-driven vendor risk assessment breaks down as portfolios grow. Here is exactly where the time goes, why the output is unreliable, and what changes when assessment is automated. - [Continuous vendor monitoring](https://www.rescana.com/learn/continuous-vendor-monitoring/): Continuous vendor monitoring replaces annual point-in-time assessments with always-on signal. Learn what it watches, how it differs from a one-time questionnaire, and how to operationalize it without drowning teams in alerts. - [How to compare TPRM platforms](https://www.rescana.com/learn/how-to-compare-tprm-platforms/): A vendor-neutral framework for evaluating TPRM platforms: the ten criteria that matter, how to weight them, and how automation, evidence-based scoring, and SOAR-style response separate tools that scale from tools that don't. - [End-to-end TPRM automation](https://www.rescana.com/learn/tprm-automation/): What it really means to automate third-party risk management end to end - from vendor discovery and assessment through monitoring, remediation, and offboarding - and where human judgment still belongs. - [Evidence-based vendor risk scoring](https://www.rescana.com/learn/evidence-based-risk-scoring/): Evidence-based scoring ties a vendor's risk rating to observable facts rather than self-reported questionnaires. Learn how it works, why explainability matters, and how it compares to security-rating black boxes. - [Incident response & SOAR in TPRM](https://www.rescana.com/learn/tprm-incident-response-soar/): When a vendor is breached, speed depends on what happens automatically. Learn how SOAR-style automation applies to third-party risk - playbooks, ticketing, and response that close the gap between detection and action. - [TPRM for large enterprises](https://www.rescana.com/learn/enterprise-tprm/): Large, regulated organizations have TPRM requirements smaller companies don't: thousands of vendors, fourth-party exposure, and hard regulatory deadlines. Here is what changes at enterprise scale and what to demand from a platform. - [Vendor collaboration in TPRM](https://www.rescana.com/learn/vendor-collaboration/): Third-party risk is a two-sided process. Platforms that let vendors respond, share evidence, and remediate directly cut cycle time for everyone. Here is what good vendor collaboration looks like - and what to watch for. - [TPRM platform comparisons](https://www.rescana.com/learn/compare/): A hub for vendor-neutral TPRM platform comparison content - how to evaluate candidates, what criteria separate tools in production, and how the leading platforms differ by category and emphasis. - [Best TPRM platforms](https://www.rescana.com/learn/compare/best-tprm-platforms/): A vendor-neutral overview of the leading third-party risk management platforms, grouped by what each is known for - and why the right choice comes from weighted evaluation criteria rather than a generic ranking. - [Security ratings vs evidence-based TPRM](https://www.rescana.com/learn/compare/security-ratings-vs-evidence-based-tprm/): Security ratings give you a fast, outside-in signal. Evidence-based TPRM gives you a defensible, auditable answer. Understanding what each approach measures - and where each falls short - is the key to combining them intelligently. - [TPRM glossary](https://www.rescana.com/learn/glossary/): A working glossary of third-party risk management terms - TPRM, VRM, C-SCRM, inherent and residual risk, fourth-party risk, SIG, CAIQ, SOC 2, ISO 27036, DORA, and more - each defined precisely and linked to its primary source. - [Inherent vs residual risk](https://www.rescana.com/learn/inherent-vs-residual-risk/): Inherent risk and residual risk are not the same number, and scoring only one is the most common classification error in TPRM. A practical guide to defining each, scoring them independently, and using both to drive vendor tiering. - [Vendor tiering](https://www.rescana.com/learn/vendor-tiering/): How to tier vendors in a third-party risk management program: the criteria that actually predict risk, a practical three-tier model mapped to assessment depth and monitoring cadence, what regulators expect, and the mistakes that make tiering indefensible. - [Fourth-party risk](https://www.rescana.com/learn/fourth-party-risk/): Fourth-party risk is the exposure created by your vendors' own subcontractors and cloud dependencies - the parties you have no contract with and usually can't see. What OCC, DORA, and EBA guidance now expect, and a practical way to get visibility without trying to map every vendor's entire supply chain. - [Concentration risk](https://www.rescana.com/learn/concentration-risk/): Concentration risk is what happens when many of your vendors quietly depend on the same cloud, identity provider, or subprocessor. How to identify it across a portfolio, why DORA and UK regulators now require assessing it directly, and how to manage exposure you usually can't eliminate. - [Vendor offboarding](https://www.rescana.com/learn/vendor-offboarding/): Vendor offboarding is the end-of-relationship stage of TPRM: revoking access and confirming data is returned or destroyed. A practical checklist, what regulators require, and why this stage fails silently more than any other. - [Agentic AI in TPRM](https://www.rescana.com/learn/agentic-ai-tprm/): AI-native (agentic) TPRM runs the vendor risk lifecycle with AI agents - discovery, assessment, continuous monitoring, and remediation workflows - instead of bolting a chatbot onto a questionnaire tool. Here is what agentic actually means, what automated vendor remediation can and cannot do, and how it fits dynamic cloud environments. - [Vendor attack surface monitoring](https://www.rescana.com/learn/vendor-attack-surface-monitoring/): Vendor attack surface monitoring continuously discovers and watches a vendor's internet-facing footprint without needing the vendor's cooperation. What it actually detects, how the discovery is done, what it structurally cannot see, and where it fits alongside evidence-based assessment. - [Automated evidence collection](https://www.rescana.com/learn/automated-evidence-collection/): Automated evidence collection replaces the manual chase for a vendor's SOC 2 report, ISO 27001 certificate, and questionnaire responses with continuous ingestion and validation against observable facts. What actually gets automated, what it structurally cannot do, and how it differs from a questionnaire. - [DORA and third-party risk](https://www.rescana.com/learn/frameworks/dora-third-party-risk/): What DORA (Regulation (EU) 2022/2554) requires for ICT third-party risk: the Register of Information, key contractual provisions, concentration-risk assessment, subcontracting rules, and oversight of critical providers - mapped to concrete TPRM actions. - [NIS2 and supply-chain security](https://www.rescana.com/learn/compliance/nis2-supply-chain/): What NIS2 (Directive (EU) 2022/2555) requires for supply-chain and third-party security: who is in scope, the Article 21 supply-chain duty, management accountability, incident-reporting timelines, and penalties - turned into concrete TPRM actions. ## More - [TPRM Knowledge Base hub](https://www.rescana.com/learn/): vendor-neutral guides to third-party risk management. - [Rescana blog](https://www.rescana.com/blog): daily threat-intelligence and breach analysis from the Rescana research team.