Fixed-fee engagement
Vendor Risk Sprint
Get a clean vendor inventory and a reviewed risk picture of the vendors that actually matter — in about a month, for a fixed fee, with no long-term commitment.
Start the conversationThe problem this solves
Most teams know they should be assessing their vendors, but the work stalls. The vendor list lives in three spreadsheets and an inbox, nobody has time to read the questionnaires that do come back, and when an auditor, customer, or board member asks how you manage third-party risk, there is no clean answer.
The Vendor Risk Sprint gives you that answer — quickly, and from a practice that does this for a living. We inventory your vendors, run assessments on the ones that carry real risk, and review the responses to produce findings you can put in front of leadership or an auditor.
What you get
Vendor inventory and ownership map
One clean source of truth, with a named internal owner against each vendor.
Risk-tiered shortlist
Your vendors ranked by materiality, so effort goes where it actually matters.
Assessments on your top vendors
Sent, collected, and centralized through the RidgePoint portal. No spreadsheets emailed around.
Reviewed findings
Practitioner analysis of each response and its evidence, in plain English: what is solid, what is a gap, what to do about it.
Vendor risk summary
A leadership- and audit-ready document that explains the risk picture and the rationale behind it.
Prioritized remediation shortlist
The handful of issues worth chasing first, with suggested next steps.
Three to four weeks
Week 1
1. Scope
Kickoff, vendor inventory, and materiality tiering.
Weeks 2–3
2. Assess
Assessments launched, evidence collected, responses reviewed.
Week 4
3. Report
Findings, risk summary, and a walkthrough call.
Investment
A fixed fee, set by the number of vendors and the depth of review, and quoted up front. No hourly surprises. Onboarding and setup are included.
Founding-client pricing is available for a limited number of early engagements. Ask about it on the first call.
What we need from you
- A point of contact who can confirm the vendor list and materiality.
- Introductions, or contact details, for the vendors being assessed.
- Any existing security or compliance documents you already hold on them.
That is it. We handle the rest.
Why RidgePoint
CTPRM-certified specialists
Third-party risk is the discipline this practice is built on, not a service bolted onto something else.
Principal-led work
Your engagement is run by the practitioner doing the analysis. No handoff to a junior running a template.
Purpose-built tooling, included
The work runs on the RidgePoint platform, so it stays fast, organized, and easy to continue later. You are buying the expertise; the software is how it gets delivered.
Many clients move from a Sprint into an ongoing managed vendor risk program, so issues keep moving from finding to closure. There is no obligation to.
Start the conversation
Tell us roughly how many vendors you have and what is driving the timing. We will come back with scope and a fixed quote.
Prefer email? hello@ridgepointrisk.com