Ventry connects third-party relationships, the services they provide, the technology underneath them, the risk you inherit and the evidence your regulator will ask for — in one operating model. Today it runs your register and produces your regulatory returns. It is being built to cover the whole dependency lifecycle.
Free for 10 third parties · Hosted in the EU · Insert-only evidence log
| performed_at | event_type | subject | by |
|---|---|---|---|
| 2026-09-10 14:02 | third_party_created | Acme Cloud Ltd | compliance lead |
| 2026-09-10 14:31 | materiality_assessed | ARR-2026-014 | head of risk |
| 2026-09-10 16:20 | regulatory_export_generated | MTP register | compliance lead |
// insert-only — no UPDATE, no DELETE, for any role
Regulated firms are legally required to track and evidence the risk their suppliers pose. The tools that do it properly were built for enterprise GRC teams — so everyone else improvises.
One tab per vendor, last edited by someone who left. No history, no sign-off, no way to prove when a control was checked.
Questionnaires sent, chased, and answered in inboxes. When the auditor asks for evidence, you are searching for attachments.
OneTrust, ServiceNow, Archer, ProcessUnity — £12K to £500K a year, built for enterprise teams with implementation budgets.
Ventry is the register in the gap: what you hand an auditor is a record, not a reconstruction.
No implementation project. No consultants. The evidence log starts on your first action.
Sign up, name your org, and you are in your register. Your team shares one tenant — only members can see your records.
Third party, contractual arrangement, the services under it, the contract, the function it supports. Import what you already have.
Each change writes to an insert-only evidence log the moment it happens. No edits, no deletes — the record an auditor can trust.
Live in Ventry today
Traditional third-party risk management stops at questionnaire, approval, annual review. But a supplier can pass a security assessment while the software it provides is subsequently:
Traditional TPRM
questionnaire → approval → annual review
Ventry's direction
relationship → dependency → implementation → risk → evidence → monitoring → renewal or exit
Ventry is being developed to connect assurance to what happens after approval — so the question is not only whether the supplier was assessed, but whether what they gave you was implemented safely and still works the way you signed for.
Ventry is evolving from managing a third-party assessment into managing the entire lifecycle of a third-party dependency.
Know the organisations, arrangements, services and declared fourth parties your business relies on. Import the estate you already have.
Understand the third party, the arrangement and the risk you inherit by entering the relationship — as a dated, human determination.
Move beyond vendor approval. For technology suppliers, Ventry is being designed to coordinate secure implementation, ownership and go-live evidence.
Connect risks directly to the dependencies that create them — with an evidence-backed assessment history, controls, treatment and explicit, time-bound acceptance. A risk should not live as an isolated sentence in a spreadsheet.
Monitor changes in evidence, suppliers, dependencies, incidents, concentration and technology lifecycle.
Substitutability, transition dependencies, data extraction, contract termination — and whether the exit plan could actually work.
Selecting a third party introduces more than supplier risk. The relationship brings the provider's own dependencies with it — and those become yours the day you sign.
The question worth answering before engagement, and every time the relationship changes: what are we tying this organisation to?
Record the relationship properly once. Where another regulatory obligation genuinely requires the same fact, Ventry reuses it — and where the underlying decisions differ, it asks you to make them separately. Ventry never claims regulatory equivalence it cannot support.
FCA, PRA and Bank of England. Field-level readiness before you generate, then the official workbook filled from your own register — with every populated value traceable to the record it came from.
The 15 official EBA templates, produced as an inspectable Excel intermediate and the xBRL-CSV reporting package, from the same third parties, arrangements, services and functions you already maintain.
Every generated file ships with a manifest binding each populated cell to its source record and evidence entry, sealed with a SHA-256 hash. Exports are immutable: regenerating creates a new artefact, never a rewrite.
Ventry produces the files and shows you what is still missing. It does not submit on your behalf, and it does not tell you that you are compliant — that judgement stays with you and your regulator.
Ventry is evolving into a third-party and technology resilience operating system. These capabilities are being designed or actively researched — they are not available today, and this page will say so until they are.
Approval is not the same as secure implementation. A structured path from vendor approval through security requirements, implementation and validation to go-live evidence — SSO, MFA, SCIM, privileged access, logging, data flows, ownership, offboarding.
Ask once. Verify where possible. Reuse evidence. A reusable supplier profile so the hundredth customer questionnaire is answered as a delta, not another three hundred questions.
Understand what is becoming obsolete before it becomes a problem — end of sale, end of support and end of life in supplier technology, and component obsolescence in long-life products.
Security and resilience obligations get buried in documents after signature. Turn contractual commitments — SSO, UK-only processing, notification windows — into controls that can actually be evidenced.
During a major supplier incident, trace it: third party → arrangement → service → business function → regulatory impact, with the contacts and fourth parties attached.
An exit plan is only useful if it can work. Alternatives, migration complexity, termination rights, data extraction, skills, transition duration, tested exercises and unresolved blockers.
Third-party assurance does not end when the questionnaire is complete. It ends when the dependency is safely removed.
Simple pricing. No surprises.
Ten third parties and one user, free. Paid plans from £149 a month are on the way — and we built Ventry because nothing credible existed below £12,000 a year.