KITE 2025 New Product Award โ€” Local IT | SACEEC
Third party risk

Vendor risk, tiered by consequence

Most organisations hold hundreds of vendors and assess them all the same way. The ones that could stop operations get the same scrutiny as the rest. Dimeri tiers by consequence and puts the effort where the exposure is.

Third party register148 vendors
Cloud hosting providerCritical82
Payroll bureauCritical74
Security contractorHigh58
Catering servicesLow91

Tiered by consequence

Why vendor risk gets missed

Every vendor treated alike

A uniform questionnaire goes to every supplier, which produces volume without a clear view of where the real exposure sits.

Assessed once, then never again

Onboarding due diligence is thorough and then nothing happens for four years, while the vendor's own risk profile moves.

No one owns the relationship

Procurement signed it, operations depend on it, and no one is accountable for whether the controls promised in the contract operate.

Concentration stays invisible

Four critical services run through one provider, which is obvious only in hindsight because nothing aggregates the dependency.

Run third party risk the steady way with Dimeri

Tiered by what they could cost you

Vendors are classified by the consequence of their failure, so critical suppliers get depth and low tier ones get a proportionate check.

Contract terms mapped to controls

The security, continuity and compliance obligations a contract imposes become tracked controls with evidence, not static contract terms.

A named owner per relationship

Each vendor has one accountable person in the business, with reassessment cycles and expiry dates that reach them before the date.

Concentration surfaced

Dependency across services, sites and entities is aggregated, so a single point of failure is visible before it proves itself.

A clear path to proportionate diligence

Four steps from a uniform checklist to assurance that matches the exposure.

Book a demo

Every third party is recorded with the service it provides and the consequence of its failure. Tiering by consequence rather than by spend is usually the step that changes the picture most.

Built for clarity, designed for control

The vendor register, the contract controls and the concentration view are one record seen from different angles.

Third party register148 vendors
Cloud hosting providerCritical82
Payroll bureauCritical74
Security contractorHigh58
Catering servicesLow91

Third party register

Every vendor with its tier, owner, service and current assessment score in one filterable view.

Exposure heatmapResidual
Likelihood
213114223512621431
LowImpactSevere
Critical 4High 10Medium 17Low 11

Concentration and exposure

Where dependency clusters across services and entities, so single points of failure surface early.

Control libraryISO 31000
Segregation of duties92%Preventive
Exception reporting74%Detective
Incident escalation61%Corrective

Contractual controls

The security, continuity and compliance obligations a contract imposes, tracked with test evidence.

Treatment planQ3
2 of 4 closed1 overdue
โœ“Dual supplier for critical sparesClosedT. Mokoena ยท 12 Aug20 โ†’ 9
โœ“Quarterly access recertificationClosedN. Adeyemi ยท 29 Aug16 โ†’ 8
Contractor induction refreshOn trackS. Naidoo ยท 04 Sep12 โ†’ 12
Pipeline integrity inspectionOverdueL. Dlamini ยท 22 Jul15 โ†’ 15

Remediation tracking

Findings from assessments become actions with owners and dates, carried until closed with proof.

Board packGenerated
Audit & risk committeeQ3 ยท 18 pp
12Above appetite โ†“ 387%Controls tested โ†‘ 9
01Risk appetite position3 pp02Movements since last meeting2 pp03Control effectiveness4 pp04Overdue treatment actions1 p

Committee reporting

Portfolio position, tier movement and overdue reassessments generated from live data.

When third party risk becomes a business advantage

Ready before you are asked

A due diligence questionnaire, a regulator query or a client's supply chain audit draws on assessments that already exist with their dates.

Fewer surprises from suppliers

Reassessment on a cycle catches a vendor's decline while there is still time to plan, rather than on the day the service stops.

Diligence effort in proportion

Tiering by consequence means critical vendors get real scrutiny and lower tiers get a proportionate check.

Ready to Transform Your GRC?

Join governance, risk, and compliance teams using AI to work smarter.

FAQ

Frequently Asked Questions

What is third-party risk management software?
Third-party risk management (TPRM) software helps organisations identify, assess, and monitor the risks that come from working with vendors, suppliers, and service providers. Instead of tracking vendor assessments in spreadsheets and email, teams use a centralised register with tiering, due diligence scoring, contract tracking, and automated alerts. Dimeri is TPRM software built specifically for African organisations.
Who needs third-party risk management?
Any organisation that relies on external vendors for critical operations benefits from TPRM. This includes financial services firms (required by SARB outsourcing directives), healthcare providers, public sector entities, and any company handling personal data under POPIA. If a vendor failure could disrupt your operations, expose customer data, or create regulatory liability, you need structured vendor risk management.
How does vendor tiering work in Dimeri?
Dimeri classifies vendors into three tiers: Critical (single-source dependencies, access to sensitive data, high revenue impact), Important (significant but not irreplaceable), and Standard (low-risk, easily substituted). The tier determines the depth of due diligence required, the frequency of reassessment, and the level of contractual protections needed. AI suggests tiers based on the vendor profile, but you make the final call.
What does a due diligence assessment cover?
Dimeri's due diligence assessments score vendors across five dimensions: financial stability, cybersecurity posture, regulatory compliance, operational resilience, and reputational standing. Each dimension has structured questionnaires and scoring criteria. AI analyses responses for inconsistencies and benchmarks scores against industry peers. Results feed into the vendor's overall risk rating.
Is Dimeri free to use?
Yes. Dimeri offers a free workspace that includes a full vendor register, due diligence assessments, contract tracking, and up to three users. You can upgrade when you need more users, additional modules like concentration risk analysis or SLA monitoring, or premium integrations. No credit card is required to start.

Still have questions? Talk to our team โ†’