Help Center

Your Central Hub for
Third-Party Risk Intelligence

Access curated guidance on vendor risk, compliance, and controls — backed by real-world use cases and best practices from risk professionals.

FAQ

TPRM FAQs for Risk, Audit & Compliance Teams

Clear answers to support adoption, governance, and scale in Third-Party Risk Management.

Questions
about Crest?

Browse by topic or read all answers below. Can't find what you're looking for? Our team is happy to help.

All Questions
Deployment
Integrations
Security
Modules
★ Still have questions?
Talk to a Crest risk expert — we'll help you find the right model for your team.
Contact Us
How is the platform deployed and licensed?
Crest TPRM is offered as a modular, multi-tenant SaaS platform, with flexible licensing based on TPRM modules and vendor usage. Organisations can start with core TPRM capabilities and scale as needed — without committing to unused modules upfront.
💻 SaaS · Modular · Flexible licensing
Can we deploy Crest TPRM on our own infrastructure?
Yes. Crest TPRM supports three deployment models to fit your infrastructure strategy:

☁ SaaS (Cloud) — Hosted on a secure AWS-based Privacy Cloud with multi-tenant isolation, automatic updates, and 99.9% uptime SLA. Ideal for fast deployment and minimal IT overhead.

🏠 On-Premise — Full on-site deployment within your own data centre for organisations with strict data residency, air-gap, or sovereign cloud requirements.

⚙ Hybrid — A split model where the core platform and processing engine run on-premise while non-sensitive capabilities (monitoring feeds, alerts, dashboards) run on SaaS infrastructure. Best for enterprises that need data sovereignty without sacrificing real-time intelligence.
☁ SaaS · On-premise · Hybrid · Private cloud
Which TPRM modules can we enable?
Organisations can activate plug-and-play TPRM modules including vendor authentication, verification, questionnaire management, remediation tracking, and continuous monitoring — based on their risk maturity and programme scope.
⚙ Plug-and-play · Modular · Scalable
How does the platform integrate with existing systems?
Crest TPRM supports API-based integrations with leading ERPs and enterprise systems such as SAP, Oracle, and other vendor or identity platforms — allowing seamless data exchange and workflow alignment without disrupting existing processes.
🔗 API · SAP · Oracle · Enterprise systems
How is access controlled for internal teams and vendors?
The platform offers role-based access control, granular permissions, and tiered access for internal users, external vendors, and reviewers — ensuring strong segregation of duties across the entire TPRM lifecycle.
🔒 RBAC · Granular permissions · Segregation of duties
Is the platform audit-ready and compliant with security standards?
Yes. Crest is SOC 2 and ISO 27001 ready. The platform includes audit-ready access logs, session tracking, end-to-end data encryption, and role-based access controls — making it inspection-ready for audits, regulators, and enterprise security reviews.
✅ SOC 2 · ISO 27001 · Audit-ready · Encrypted · Enterprise-grade
Move Beyond Manual

Move Beyond Manual
Third-Party Risk Management.

Bring structure, automation, and clarity to your third-party risk lifecycle. Adopt evidence-backed, regulatory-aligned workflows that improve control, reduce cycle time, and support continuous monitoring.

Evidence-Backed
Regulatory-Aligned
365-Day Monitoring
Built by GRC Experts
SOC2 Focused