Manage third-party and vendor compliance risk — due diligence, contracts, ongoing oversight, and exit — for regulatory and operational resilience. Use when onboarding vendors that process sensitive data or support regulated activities, or reviewing outsourcing arrangements.