The half you can price today · Verified 18 August 2026
Sign.Plus — Sign.Plus for the agreements that come out the far end
Free tier (3 requests) · Professional $19.99/mo unlimited · Enterprise $49.99/mo with HIPAA and a BAA
On the platform question our answer is short: for a research institution starting from scratch, shortlist Vanta Vendor Risk first, because its questionnaire automation and continuous evidence collection are the closest fit to a small research-security team with no dedicated GRC analyst — and we quote no price for it, because we publish only prices we have read off a vendor page ourselves. What we can price is the step every TPRM platform hands back to you unfinished. An assessment produces a decision; the decision has to become a signed data use agreement, business associate agreement or subaward security exhibit, with an audit trail an auditor will accept. Sign.Plus does that from a free tier of three requests, gives unlimited signature requests at $19.99/mo on Professional, and puts HIPAA coverage with a signed BAA on Enterprise at $49.99/mo — with eIDAS-grade audit trails on every tier including the free one, which is unusual and is the reason it is here rather than a bigger name. Verified 18 August 2026.
Try Sign.Plus free Opens on the vendor’s site · CASRAI referral link
The contractual half, in full → — What a BAA must contain when the vendor touches research data, and what no platform can assert on your behalf.
Editorial disclosure: CASRAI has commercial referral arrangements with some of the vendors named on this page, and may earn a commission if you subscribe to them. We name them here regardless of whether a link is present. We only recommend tools our editorial team has independently researched. Read our full disclosure policy.
In summary
- Product-aware shortlist: Vanta Vendor Risk for small research-security teams, OneTrust when privacy and vendor risk must share one register, Prevalent when you need deep assessment workflow, UpGuard when external attack-surface monitoring is the actual requirement.
- HECVAT is the deciding question in higher education. Most generic TPRM platforms support SIG and CAIQ and have no native HECVAT handling at all — ask for a demonstration, not a roadmap.
- Continuous monitoring scores what is visible from outside: certificates, exposed services, breach mentions, domain hygiene. It is a genuine improvement on an annual questionnaire and it is not evidence that a CRO protects participant data.
- The output of any TPRM platform is a decision that still has to become a signed DUA, BAA or security exhibit. Budget for that step separately.
- Sign.Plus: free tier (3 requests); Personal $9.99/mo (10/mo); Professional $19.99/mo unlimited; Business $29.99/mo; Enterprise $49.99/mo with HIPAA and a BAA. Audit trails and eIDAS on all tiers including free. Annual billing available. Verified 18 August 2026.
The four platforms you are about to google
Positioning only. We publish prices only where we have read them off a vendor pricing page — none of these are CASRAI partners, so no figures appear here. Assessed 19 August 2026.
| Dimension | What it is actually built for | Where it genuinely wins | What to test before you sign |
|---|---|---|---|
| Vanta Vendor Risk | Compliance automation first, with vendor risk as a module on the same evidence graph | Small teams with no GRC analyst. Vendor inventory discovered from your own stack, questionnaires sent and chased automatically, document parsing that reads a SOC 2 rather than filing it | Whether it handles HECVAT natively or expects you to upload it as a generic document; how vendor findings surface separately from your own compliance posture |
| OneTrust | Privacy and governance at enterprise scale, with third-party risk as one module among many | Institutions that already run their records of processing, DPIAs and data mapping in one place and want vendor risk on the same register rather than in a second system | Implementation weight. It is the heaviest option here and rewards an owner with time; ask what configuration is billed as professional services |
| Prevalent | Third-party risk as the whole product, not a module — assessment workflow, remediation tracking, managed services | Large vendor populations with real tiering, and offices that want the questionnaire chasing done for them rather than automated at them | Whether the depth is proportionate to your vendor count. Below roughly a hundred assessed vendors much of the machinery goes unused |
| UpGuard | Outside-in security ratings and attack-surface monitoring, with questionnaires added around them | Continuous visibility of exposed services, certificate hygiene and leaked credentials across a supplier list you did not assess and cannot re-assess | That a score is an external observation. It cannot see access control inside a CRO, and a good score is not a due-diligence conclusion |
| The spreadsheet you have now | Nothing. It accumulated | Honestly: it is free, and for under twenty low-risk vendors a well-kept register with diarised review dates outperforms a badly implemented platform | Whether anyone can answer “which vendors hold identifiable participant data” in under a minute. If not, that is your business case |
Every platform on this list will show you a dashboard of green. Judge them on the two questions that actually predict value: can it ingest the questionnaire standard your sector uses, and does it tell you when something changes between assessments.
What third party risk management software is automating in a research office
In most industries “third party risk” means suppliers. In a research institution it means something more specific and more consequential: the CRO running your trial, the subrecipient on your federal award, the biobank, the sequencing provider, the transcription service handling qualitative interviews, the survey platform, the analytics vendor with a pipe into the data warehouse, the cloud tenancy where a lab keeps imaging data, and the collaborating institution you are about to send a de-identified dataset to under a data use agreement.
Every one of those relationships already triggers a due-diligence obligation somewhere — IRB conditions, sponsor flowdowns, HIPAA when protected health information is involved, GDPR when a European cohort is, export controls when the data is controlled, and the institution’s own information-security policy. What almost no research office has is a single place recording which vendor is covered by which obligation, when it was last checked, and what the answer was. That is the gap the software fills: a vendor inventory, tiering by sensitivity, a standard questionnaire sent and tracked, the SOC 2 and certificates stored with expiry flagged, and a register that answers an auditor in a minute rather than a fortnight. It is genuine research administration work being automated — not a metaphor for it.
What it is not is a judgement. The platform will tell you the CRO returned a complete questionnaire and holds a current ISO 27001 certificate. Whether the CRO will actually protect participant data through a subcontractor change eighteen months from now is a question about contract terms, audit rights and the seriousness of the organisation, and no vendor score answers it.
Questionnaire automation, and why HECVAT decides the shortlist
Questionnaire automation is the feature that justifies the licence. In practice it means four things: a library of standard questionnaires you can send without rewriting them, automatic reminders so nobody is chasing a vendor by email, answer reuse so a vendor assessed last year is not starting from a blank form, and parsing of the evidence that comes back so a SOC 2 report is read rather than merely attached.
Three standards matter, and they are not interchangeable. SIG — the Shared Assessments Standardised Information Gathering questionnaire — is the broad commercial standard, published in core and lite forms, and is what most enterprise TPRM platforms assume. CAIQ, the Cloud Security Alliance’s Consensus Assessments Initiative Questionnaire, is the cloud-specific one; if a vendor has published a CAIQ to the CSA registry you may be able to skip the questionnaire step entirely. And HECVAT — the Higher Education Community Vendor Assessment Toolkit — is the standard that higher education actually uses, in full, lite and on-premise versions, with a community broker where completed assessments are shared between institutions so the same vendor is not assessed sixty times.
Here is the trap for a product-aware buyer. Almost every generic TPRM platform supports SIG and CAIQ out of the box. Most have no native HECVAT support at all — you can upload a completed HECVAT as a PDF attachment, but the platform cannot send it, cannot map its answers to controls, cannot reuse them, and cannot pull an existing completed assessment from the shared community source. If your institution is a university, that single gap can cancel most of the labour saving you bought the platform for.
Make it the first question in the demonstration, and insist on seeing it done rather than described: send a HECVAT Lite to a test vendor, receive it back, show the answers as structured data. “On the roadmap” is a no. If nothing on your shortlist can do it, the honest configuration is a platform for inventory, tiering, monitoring and evidence storage with HECVAT handled alongside it through the community exchange — defensible, but choose it knowingly rather than discover it in month three.
Continuous monitoring versus point-in-time assessment
The strongest argument for replacing a spreadsheet is not the questionnaire. It is that an annual assessment is a photograph of a moving object. A vendor assessed in March can be breached in July, let a certificate lapse in September, be acquired in November and move your data to a new subprocessor in January — and under a point-in-time regime you learn about all of it at the next annual review, if at all.
Continuous monitoring closes part of that gap by watching what is observable from outside: TLS and certificate hygiene, exposed services and open ports, DNS and email authentication records, credentials appearing in public breach corpora, and public disclosure of incidents. When something degrades, the platform raises it against the vendor record you already hold. For a research office tracking a long tail of small suppliers nobody has capacity to re-assess, that is a real and defensible improvement.
The honest trade-off, and the reason this page exists: an automated vendor score measures external attack surface. It is a proxy, and a partial one. It cannot see whether the CRO enforces least privilege on the study database, whether staff are trained, whether the subcontractor in another jurisdiction has the same controls, or whether anyone will actually notify you inside the window your contract specifies. A vendor with an immaculate external posture can still mishandle participant data, and a small academic collaborator with a shabby DNS configuration may run a tighter data operation than a listed company with a perfect rating.
Treat the score as a monitoring signal that prompts a conversation, never as a due-diligence conclusion, and never let it substitute for the contractual controls: defined permitted use, subcontractor consent, breach notification deadlines, audit rights, return-or-destroy obligations at the end of the study. The platform supplements those. It does not replace them, and any vendor implying otherwise is selling you a risk transfer that does not exist.
Vanta, OneTrust, Prevalent, UpGuard — which one, and why
You are going to search all four names, so here is the verdict rather than a survey. We hold no verified pricing for any of them — none is a CASRAI partner, and we publish only figures read directly off a vendor pricing page — so judge these on fit.
Vanta Vendor Risk is where most research institutions should start. It comes from compliance automation, so the vendor module sits on the same evidence base as your own SOC 2 or ISO 27001 work: vendors discovered from systems you already connect, questionnaires that chase themselves, returned documents parsed rather than filed. Where vendor risk is a fraction of one person’s role, that ratio of setup effort to output is the one that survives contact with reality. Check HECVAT before you commit.
OneTrust is better if you have a privacy office. Where records of processing, DPIAs and data mapping already live there, adding vendor risk to the same register beats a second system with a second vendor list that drifts out of agreement within a year. It is also the heaviest option here, and rewards an institution with someone whose actual job this is.
Prevalent is better if third-party risk is the whole job — deep assessment and remediation workflow, real tiering across a large vendor population, managed services if you would rather outsource the chasing than automate it. Below roughly a hundred assessed vendors much of that is licensed and unused. UpGuard is better if what you actually want is monitoring: a long supplier tail nobody has assessed and continuous outside-in visibility now. It is the weakest fit where the requirement is structured questionnaire workflow against a sector standard.
Do not buy any of them if you have fewer than about twenty vendors, none touches identifiable participant data, and the real problem is that nobody owns the register. A platform does not create an owner; it gives an absent owner a more expensive place to be absent, and you will renew for three years before anyone admits the questionnaires stopped going out in month four. Fix the ownership, keep the spreadsheet, revisit in a year.
The DUAs and BAAs that come out the far end
Follow the workflow to its end and the platform stops one step short every time. An assessment concludes; a risk is accepted, mitigated or refused; and then a human has to put the conclusion into an instrument that binds the other party. In research that instrument is a data use agreement, a business associate agreement where protected health information is involved, a material transfer agreement, a subaward with a security exhibit, or a clinical trial agreement schedule.
Good TPRM platforms track that these documents exist and when they expire. None of them drafts the terms, and none can assert on your behalf that a vendor is a business associate rather than a conduit — a determination with real consequences that belongs to your privacy officer and counsel. Our page on business associate agreements in research covers what those terms must contain and where institutions most often get the determination wrong.
What you can automate is execution and evidence. The signature has to be legally sound, the audit trail has to withstand a records request years later, and where PHI is involved the signature vendor itself becomes a vendor you must assess — which is exactly why the HIPAA and BAA question matters when you choose one. Our comparison of HIPAA-compliant e-signature software works through that determination in detail.
This is the reason our priced recommendation sits here rather than on the platform. Sign.Plus gives audit trails and eIDAS-grade evidence on every tier including the free one, unlimited signature requests at $19.99/mo, and HIPAA coverage with a signed BAA on Enterprise at $49.99/mo — so a research office can pilot the whole loop, from questionnaire to signed agreement, before committing budget to either half. Verified 18 August 2026.
How to run a pilot that tells you something
Vendor demonstrations are optimised to look good. Structure your own evaluation instead, using the same five vendors in every trial: one CRO or clinical partner, one cloud or analytics platform, one small academic collaborator with no security function, one laboratory supplier, and one vendor you already know is difficult. Run the whole loop in each platform and record four numbers — time to get each vendor inventoried and tiered, whether your sector’s questionnaire could be sent natively, how many chasing emails a human still wrote, and time from returned questionnaire to a recorded decision with evidence attached.
Then break something on purpose: let a certificate expire on a test domain, or ask what the platform did the last time one of your vendors disclosed an incident. A platform that only tells you what you told it is a database with a subscription.
Finally, price the whole workflow rather than the licence. A platform that saves forty hours of chasing and then leaves you executing agreements by scanned PDF has moved the bottleneck rather than removed it. The offices that get value from third party risk management software automated the assessment and the agreement together, and kept a named human accountable for the decision the software merely recorded.
Close the loop before you commit to a platform
Whichever TPRM platform you shortlist, the assessment still has to become a signed DUA, BAA or security exhibit with an audit trail that survives a records request. Sign.Plus starts free at three requests, goes to unlimited signature requests at $19.99/mo on Professional, and carries HIPAA with a signed BAA on Enterprise at $49.99/mo — with eIDAS-grade audit trails on every tier including the free one. Verified 18 August 2026.
From $9.99/mo · unlimited requests at $19.99/mo
Try Sign.Plus free Opens on the vendor’s site · CASRAI referral link
Frequently asked questions
What is third party risk management software, in a research context?
It maintains an inventory of every external organisation that touches your systems or data, tiers each by sensitivity, sends and chases standard security questionnaires, stores the evidence that comes back, and alerts you when something changes. In a research institution that population is CROs, subrecipients, biobanks, sequencing and transcription providers, survey and analytics platforms, cloud tenancies and collaborating institutions receiving data under a DUA. The value is not the questionnaire itself — it is being able to answer, in a minute rather than a fortnight, which vendors hold identifiable participant data and when each was last assessed.
Does the platform support HECVAT, or only SIG and CAIQ?
Ask this first, and insist on a live demonstration rather than a roadmap commitment. Nearly every generic TPRM platform handles SIG and CAIQ natively because those are the commercial and cloud standards. HECVAT — the higher education standard, in full, lite and on-premise versions — is frequently supported only as a PDF you can attach, which means no sending, no structured answers, no reuse and no pull from the shared community exchange where other institutions have already assessed the same vendor. For a university that gap removes most of the labour saving. If nothing on your shortlist can do it, use the platform for inventory, tiering, monitoring and evidence, and run HECVAT alongside it deliberately.
Is continuous monitoring worth paying for over an annual assessment?
Usually yes, with a clear-eyed view of what it measures. An annual questionnaire is a photograph of a moving object: a vendor can be breached, acquired, or move your data to a new subprocessor months before your next review. Continuous monitoring watches the externally observable signals — certificates, exposed services, email authentication, breached credentials, disclosed incidents — and raises them against the vendor record. What it cannot see is anything inside the vendor: access control on the study database, staff training, subcontractor arrangements, or whether they will notify you inside your contractual window.
Can a vendor risk score replace due diligence on a CRO?
No, and this is the failure mode worth guarding against. An automated score measures external attack surface — what an attacker could see from the internet. A CRO with an immaculate external posture can still mishandle participant data, and a small academic collaborator with untidy DNS may run a tighter data operation. Use the score to prompt a conversation and to catch degradation between assessments, never as a due-diligence conclusion. The controls that actually bind a CRO are contractual: defined permitted use, consent to subcontractors, breach notification deadlines, audit rights, and return-or-destroy obligations at study close.
How does third party risk management software handle the DUAs and BAAs at the end?
It tracks that they exist and when they expire; it does not draft them and it cannot make the determination that a vendor is a business associate rather than a conduit — that belongs to your privacy officer and counsel. Read our guide to business associate agreements in research for what those terms must contain. What you can automate is execution and evidence, and that is where our priced pick sits: Sign.Plus starts free at three requests, gives unlimited signature requests at $19.99/mo on Professional, and puts HIPAA with a signed BAA on Enterprise at $49.99/mo, with eIDAS-grade audit trails on every tier including the free one (verified 18 August 2026). Because the free tier needs no card, you can run one real assessment end to end — questionnaire to signed agreement — before you spend anything. If PHI is involved, work through the HIPAA e-signature comparison first, since your signature vendor becomes a vendor you must assess.
Vanta, OneTrust, Prevalent or UpGuard?
Start with Vanta Vendor Risk if you have no dedicated GRC analyst and want vendor risk sitting on the same evidence base as your own compliance work. Choose OneTrust if a privacy office already runs your records of processing and DPIAs and a second register would drift. Choose Prevalent if third-party risk is a full-time job across a large tiered vendor population, or if you would rather outsource the chasing than automate it. Choose UpGuard if the actual requirement is continuous outside-in monitoring of a supplier tail you cannot re-assess. We publish no prices for any of them — none is a CASRAI partner and we quote only figures read off a vendor pricing page.
When should we not buy a TPRM platform at all?
When you have fewer than about twenty vendors, none of them touches identifiable participant data, and the real problem is that nobody owns the register. Software does not create an owner. It gives an absent owner a more expensive place to be absent, and the usual outcome is a three-year subscription on which questionnaires stopped going out in month four. Name the owner, keep a well-kept spreadsheet with diarised review dates and a tier column, and revisit in a year with evidence of what the manual process actually costs — which is also the business case you will need to get funding approved.







