ConsenPro Logo
Third-Party Risk Management · DPDP Act 2023 · Section 8(2) & 9

Your Vendors Handle Your Data. You Own the Liability.

Every vendor with access to personal data is a compliance obligation under the DPDP Act. ConsenPro TPRM gives you complete visibility across your vendor ecosystem, structured due diligence, contract and DPA management, continuous monitoring, and a tamper-proof audit trail so you can prove your vendor relationships are managed to the standard the law requires.

Sec 8(2)
Data Fiduciary obligations to Data Processors
Sec 9
Processing of children's data restrictions
4 Tiers
Critical, High, Medium, Low risk classification
100%
Audit-evidenced vendor lifecycle
ConsenPro: TPRM DashboardLIVE

148

Total Vendors

Active

23

Critical Tier

Require audit

31

Due Diligence

Overdue

12

Certificates

Expiring soon

Vendor Risk Register

AWS / Cloud Infra

Critical Tier

LOW

92/100

Salesforce CRM

High Tier

MEDIUM

71/100

BPO Partner Ltd

Critical Tier

HIGH

44/100

Analytics SaaS Co

Medium Tier

LOW

88/100

Recent Activity

BPO Partner Ltd: DPA amendment sent for signature

One View of Your Entire Vendor Ecosystem.

The TPRM dashboard aggregates vendor risk scores, contract expiry dates, due diligence statuses, certificate validity, and open action items into a single, real-time view. Your DPO sees what needs attention without digging through spreadsheets or email chains.

Vendor Risk Heatmap

Visual risk map showing all vendors by tier and current risk rating. High-risk vendors surface immediately, with one-click access to their full profile.

Live Activity Feed

Every vendor action (questionnaire submitted, certificate uploaded, DPA signed) streams into the dashboard in real time, with timestamps and actor attribution.

Action Centre

Overdue due diligence, expiring certificates, unsigned DPAs, and open audit findings presented as a prioritised action list with one-click resolution.

Risk Trend Reporting

Track how vendor risk levels have moved over time. Identify improving and deteriorating vendor relationships before they become compliance incidents.

ConsenPro: TPRM DashboardLIVE

148

Total Vendors

Active

23

Critical Tier

Require audit

31

Due Diligence

Overdue

12

Certificates

Expiring soon

Vendor Risk Register

AWS / Cloud Infra

Critical Tier

LOW

92/100

Salesforce CRM

High Tier

MEDIUM

71/100

BPO Partner Ltd

Critical Tier

HIGH

44/100

Analytics SaaS Co

Medium Tier

LOW

88/100

Recent Activity

BPO Partner Ltd: DPA amendment sent for signature

Every Vendor, Every Stage. Nothing Untracked.

ConsenPro tracks your vendors from first contact to final offboarding. Each stage of the lifecycle has defined inputs, outputs, accountability assignments, and evidence capture, so no vendor ever falls through the compliance gap between onboarding and renewal.

01

Intake

Self-registration portal, data access scope, initial risk category

02

Assessment

Structured due diligence, auto-scored questionnaires, document review

03

Contract

DPA generation, DPDP Act alignment, digital signature and version control

04

Monitoring

Certificate alerts, re-assessment triggers, periodic audit scheduling

05

Offboarding

Data deletion confirmation, access revocation, contract closure evidence

Stage 01: Intake

Vendor self-registration portal. Business justification, data access scope, and initial risk profiling captured on day one.

Vendor onboarding form
Data access scope defined
Initial risk category assigned

Not All Vendors Are the Same Risk. Treat Them Accordingly.

ConsenPro classifies vendors into four tiers based on data sensitivity, volume, processing purpose, and sub-processor risk. Each tier carries a different set of due diligence requirements, audit frequencies, and escalation thresholds, so your compliance effort is proportionate to actual risk.

Critical Tier

23

vendors

Vendors processing large volumes of sensitive personal data. Core system providers, BPO partners, cloud infrastructure.

Annual on-site audit
Quarterly re-assessment
Real-time monitoring
DPO sign-off required

High Tier

41

vendors

Vendors with access to meaningful personal data volumes. CRM platforms, marketing automation, analytics providers.

Bi-annual audit
Semi-annual re-assessment
Certificate tracking
Automated alerts

Medium Tier

58

vendors

Vendors with limited data access. SaaS tools, project management platforms, collaboration software.

Annual self-assessment
Document review
Certificate validation
Risk score tracking

Low Tier

26

vendors

Vendors with no or minimal personal data access. Infrastructure tools, physical services, ancillary providers.

Periodic questionnaire
Annual DPA review
Risk score maintained
Audit on escalation

Audits That Produce Evidence, Not Just Reports.

ConsenPro structures vendor audits as evidence-generating activities, not just document reviews. Every checklist item, finding, vendor response, and corrective action is captured in an immutable audit record that you can present to the Data Protection Board.

Structured Audit Checklists

Pre-built checklists aligned to DPDP Act obligations, ISO 27001, and SOC 2. Customisable to your specific vendor relationship and data processing activity.

Finding Management

Audit findings classified by severity. Each finding triggers a corrective action workflow assigned to the vendor with a response deadline and escalation path.

Audit Lifecycle Tracker

From audit scheduling to finding closure, every stage is tracked with timestamps and responsible parties. Nothing closes without evidence.

Tamper-Proof Audit Ledger

All audit records are anchored in ConsenPro's Merkle ledger. The audit trail cannot be altered after the fact, giving you a reliable evidence base for regulatory inquiry.

Audit: BPO Partner Ltd

Critical Tier · Annual Audit · 2025

Data Processing Agreement review
Sub-processor disclosure
Access control verification
Breach notification procedure
Data retention and deletion audit
Staff training records

1 Open Finding

Breach notification SLA exceeds DPDP requirement. Corrective action assigned to vendor, due in 14 days.

No Certificate Expires Without You Knowing.

An expired ISO 27001 certificate or lapsed SOC 2 report from a Critical Tier vendor is not just an administrative oversight. It is a live compliance gap. ConsenPro tracks every certificate across your vendor portfolio, sends automated renewal reminders, and escalates to your DPO when a certificate is approaching expiry or has lapsed.

Centralised Certificate Register

ISO 27001, SOC 2, GDPR DPA, PCI DSS, and custom certifications stored in one place per vendor, with expiry dates, issuing bodies, and document uploads.

Automated Expiry Alerts

Configurable alerts at 90, 60, and 30 days before expiry. Vendor portal tasks automatically assigned to request renewal documentation.

Validity Dashboards

Single-view of all certificates across your vendor portfolio, colour-coded by status. Critical Tier vendor certificates are highlighted with escalation flags.

Certificate Register

Auto-tracked

AWS / Cloud Infra

ISO 27001:2022

VALID
Exp: 2026-03-15

Salesforce CRM

SOC 2 Type II

78d left
Exp: 2025-08-01

BPO Partner Ltd

ISO 27001:2022

EXPIRED
Exp: 2025-06-10

Analytics SaaS Co

GDPR DPA

VALID
Exp: 2026-01-20

Give Vendors a Place to Do the Work. Give Your DPO a Place to See It.

The ConsenPro Vendor Portal is a shared workspace where your compliance team and your vendors operate on the same platform. Vendors complete questionnaires, upload certificates, review DPA drafts, and acknowledge obligations. Your DPO sees exactly what is done, what is pending, and what is overdue without chasing emails.

DPO View

Prioritised task list showing overdue actions, pending reviews, and urgent vendor items. Click through to any vendor profile, questionnaire response, or DPA for immediate action.

Vendor Task List

Each vendor logs in to a task list showing exactly what is required of them and by when. No ambiguity, no email attachments, no version confusion.

DPA Review and Sign

Data Processing Agreements drafted, reviewed, and digitally signed within the portal. Version history maintained. Signed documents automatically archived in the vendor record.

Sub-Processor Disclosures

Vendors declare their sub-processors within the portal. Changes trigger an approval workflow. You always know who has access to your data, two layers down.

Vendor Portal

DPO View

BPO Partner Ltd

DPA review pending

FinTech API Co

Assessment overdue

Analytics SaaS

Cert renewal due in 30d

Vendor View

Complete due diligence questionnaire

Upload ISO 27001 certificate

Review and sign DPA amendment

Submit sub-processor list

When a Vendor Relationship Ends, Your Data Comes Back.

Vendor relationships end. Contracts expire, services are migrated, vendors are replaced. ConsenPro's Escrow Management module ensures that your data obligations survive the end of a vendor relationship, with structured data retrieval, deletion confirmation, and evidence of compliant offboarding.

Data Retrieval Workflows

Structured process for retrieving personal data from outgoing vendors. Format requirements, transfer timelines, and verification steps all managed within ConsenPro.

Deletion Confirmation

Vendors are required to confirm deletion of personal data within the portal. Confirmation is timestamped and archived as evidence in the vendor's offboarding record.

DPA Termination Management

Data Processing Agreements are formally closed with a signed termination record. No vendor relationship ends without a documented compliance close-out.

Access Revocation Tracking

Access credentials and permissions revoked at offboarding are logged per vendor. Revocation evidence is stored in the audit ledger.

Offboarding Audit Report

Auto-generated offboarding report summarising data retrieved, data deleted, access revoked, and contractual obligations closed. Ready for DPB submission.

Immutable Offboarding Record

The complete offboarding record, including all evidence, is anchored in ConsenPro's Merkle ledger. The record cannot be altered after closure.

Know Your Vendor Risk Before the DPB Does.

Most organisations discover gaps in their third-party risk management during a regulatory inquiry or a vendor breach, when it is too late to remediate quietly. ConsenPro's team will assess your current vendor portfolio against DPDP Act Section 8(2) and Section 9 requirements and identify exactly where you are exposed.

What you receive from the assessment

Vendor Inventory Review

Your current vendor list mapped against DPDP Act obligations, with data access scope and processing purpose documented for each.

Risk Tiering Assessment

All vendors classified by risk tier based on data sensitivity, volume, and processing purpose, with recommended due diligence requirements per tier.

DPA Gap Analysis

Review of existing Data Processing Agreements against DPDP Act Section 8(2) and Section 9 requirements, with specific gaps identified.

Priority Remediation Register

Vendors with the highest compliance exposure ranked and prioritised, with specific remediation steps and recommended timelines.

ConsenPro TPRM · A Product of CAMS (Computer Age Management Services)

CAMSDPDP Act 2023Section 8(2) & Section 9ISO 27001:2022SOC 2 Type II