A trusty platform if you provide the logic
Use Cases and Deployment Scope
We utilize OneTrust for 3rd party risk management and to dictate the frequency of review. Using a risk matrix new vendors brought into the platform are assigned a risk level based on data sensitivity and the inherent risk of the vendor. We then use OneTrust to automate information gathering and to schedule reassessments based on risk category.
Pros
- Centralized repository for documentation of vendor risk.
- Allows for customizable risk metrics to define inherent risk.
- Repeatable, defined process for vendor assessments.
Cons
- Documentation chasing for assessments is not as automated or hands-off as demos made it seem.
- Getting custom risk matrix set up required professional onboarding.
- Platform is less than intuitive.
- Pricing is module dependent and demos do not highlight which module is included in which workflow.
Likelihood to Recommend
OneTrust provides a repeatable and defined process for vendor assessments but should be adapted to your organization. OneTrust functions well for a centralized document repository. The pricing of modules and what modules are required for workflows to function fully should be better defined. Automated assessments can wind up in spam filters and should be communicated outside of the platform prior to sending to the vendor.