Learn to Build a Real-Time Data Foundation for AI | Join Webinar

Third-Party Risk Assessments | How Confluent Helps You Move Faster with Confidence

Written By

Every organization that adopts a cloud platform takes on a shared responsibility: the assurance that its vendors are secure, compliant, and resilient. This is where third-party risk assessments (TPRAs) come in with a systematic evaluation of a vendor's security posture, operational resilience, and compliance standards. TPRAs are a cornerstone of modern security and procurement programs because they provide structured, verifiable evidence of a vendor's security posture. They replace assumption with verifiable proof.

Third-party assessments deliver real benefits across the business:

  • Faster procurement cycles: Replacing ad-hoc questionnaires with standardized, pre-completed reports

  • Regulatory compliance support: Helping organizations meet obligations under DORA, GDPR, APRA and other frameworks

  • Mutual efficiency: Vendors complete an assessment once, and customers access it many times

For Confluent customers, this means less time searching for  documentation and more time moving forward with your data streaming strategy. Our Trust Center lists the various assessment reports for your team's needs, whether you are a procurement analyst needing a quick overview or a CISO requiring independently validated evidence.

Confluent's Third-Party Assessment Portfolio: Assurance as an Accelerator

Our approach to third-party risk management is rooted in our core commitment to security transparency

We proactively do the heavy lifting so that our customers’ risk and compliance teams don’t have to start from scratch. Rather than responding to each evaluation individually, Confluent maintains current, independently validated assessments across the industry's most widely recognized platforms. When a customer begins due diligence, the relevant evidence is already available—reviewed, up to date, and structured to map directly to the customer's own control framework.

Confluent has completed multiple industry-recognized assessments, each designed for a different use case and level of rigor, so that risk teams can obtain evidence in the format they prefer. The following summarizes what is available today.

ProcessUnity Global Risk Exchange (formerly CyberGRX)

ProcessUnity Global Risk Exchange goes beyond self-attestation by combining vendor-completed assessments with automated validation. Controls are covered via domains like Identity & Access Management, Data protection, and vulnerability management. Confluent's CyberGRX profile is available on the CyberGRX Exchange, where customers can access and map controls against their own frameworks–such as NIST, ISO 27001, PCI-DSS, and HIPAA–without re-requesting the report each year. Higher-tier assessments include evidence review for additional assurance.

CyberVadis

CyberVadis combines questionnaire responses with mandatory supporting documentation, which is typically reviewed remotely by a team of three security analysts using a rigorous six-eyes process to ensure the highest level of accuracy and reliability. This evidence-based approach produces a detailed scorecard covering 20 cybersecurity topics aligned to ISO 27001, NIST CSF, GDPR, and DORA. Confluent's CyberVadis scorecard is available to customers (upon request) seeking a higher confidence level than pure self-reporting, without requiring an on-site audit.

TruSight / S&P Global KY3P

TruSight, now integrated into S&P Global's KY3P platform, represents the gold standard for financial services vendor due diligence. Originally built by a consortium of leading banks, including JPMorgan Chase, Bank of America, and Wells Fargo,  it delivers fully independent, validated assessments from trained third-party assessors who examine actual control evidence, not just vendor self-attestation. Assessors inspect policies and procedures, review supporting documentation, and in some cases observe controls operating on-site. The assessment covers 200+ controls across  about 26 categories. Confluent's KY3P assessment has been mapped directly to major internal control frameworks by leading financial institutions, making it the go-to report for highly regulated customers in banking, capital markets, and insurance.

Standardized Information Gathering (SIG)

The SIG, developed by Shared Assessments, is the industry's most widely adopted vendor risk questionnaire. Confluent's completed SIG covers 19+ risk domains including cybersecurity, privacy, IT operations, supply chain security, AI, and business resiliency, providing pre-vetted answers to over 850 standard security questions. The questionnaire's built-in framework mapping extends to numerous regulatory requirements, including CMMC, DORA, APRA, and others, and was updated in 2026 to reflect modern risks such as software supply chain compromise and AI-specific security risks. It is ideal for customers whose TPRM programs accept self-reported, standardized questionnaires as a basis for vendor approval.

Consensus Assessments Initiative Questionnaire (CAIQ)

The CAIQ, published by the Cloud Security Alliance (CSA), focuses specifically on cloud-native security controls. Confluent's completed CAIQ provides immediate visibility into how Confluent Cloud aligns with the CSA Cloud Controls Matrix, a standardized framework that helps assess the security capabilities of cloud service providers. While CAIQ serves as baseline assessment,  Confluent has also achieved CSA’s Security Trust Assurance and Risk (STAR) Level 2 Certification, marking a commitment to a globally recognized cloud security assurance standard.

Choosing the Right Assessment

Not all assessments serve the same audience. Use this quick guide to identify which report fits your needs:

  • General procurement or IT risk: Start with the SIG or CAIQ for broad, fast coverage.

  • Cloud security review: The CAIQ maps directly to cloud-specific controls and is optimized for SaaS evaluations.

  • Continuous monitoring: CyberGRX's Exchange model allows dynamic, always-current access.

  • Supply chain or DORA/NIS2 compliance: CyberVadis provides analyst-validated evidence aligned to European regulatory standards.

  • Financial services or highly regulated industries: Request the TruSight/KY3P report for independently validated, audit-ready evidence.

Assessment

Type

Best For

Validation Level

CyberGRX

Exchange platform

Tiered risk assessment with automated validation

Auto-validated, tiered evidence review

CyberVadis

Evidence-based assessment

Supply chain risk; analyst-reviewed scoring

Remote analyst validation (six-eyes review)

TruSight / S&P KY3P

Assessment-as-a-Service

Financial services institutions; deep independent validation

Independent on-site and  remote validation

SIG 

Questionnaire

General vendor due diligence, broad industry use

Self-reported

CAIQ 

Questionnaire

Cloud security due diligence

Self-reported

What the Market Tells Us

As enterprise landscapes are shifting rapidly, security leaders are no longer willing to accept "security by checkbox." The market is demanding deeper transparency, continuous verification and, above all, efficiency. The global TPRM market has been evolving and the forces driving this growth include expanding vendor ecosystems, rising cyberattack frequency and increasingly prescriptive regulation.

For risk, security, and procurement teams, the shift happening across the market translates into three very practical outcomes: 

  • Operational efficiency: Vendor reviews that used to take weeks of back-and-forth questionnaires now take days. Standardized, pre-completed reports mean your team isn't waiting on a vendor to fill out a custom form before a deal or renewal can move forward; the evidence is already there.

  • Cost optimization: Every hour that your risk or procurement team spends searching for documentation is an hour not spent on higher-value work. The "assess once, share many" model, used by assessments like CyberGRX and TruSight/KY3P, exists specifically to eliminate the duplicative assessment cycles that drive up the real cost of vendor due diligence.

  • Regulatory risk reduction: Frameworks like DORA in Europe and FFIEC guidance in the US are raising the bar from simple questionnaire completion to evidence-based oversight. Independently validated, current assessments give a defensible, audit-ready record.

Security Evaluation, Simplified

By maintaining a comprehensive portfolio of third-party assessments, from the broadly accessible SIG and CAIQ to the independently validated TruSight/KY3P report, Confluent equips your security, risk, and procurement teams with the evidence they need, in the format they want. 

Whether you are onboarding to Confluent for the first time, completing an annual vendor review, or preparing for a regulatory audit, the Confluent Trust Center is ready to support you. 

  • Saurabh Ghelani, Global Trust Officer at Confluent, leads the Office of the CISO to oversee security, regulatory compliance, and trust initiatives. His team champions Confluent’s security and privacy posture to accelerate customer adoption and support global market growth. By leading vital regulatory programs, Saurabh drives a proactive security strategy and fosters a culture of compliance to ensure delivery of secure, trusted solutions to customers worldwide.

  • Swati Manocha, APAC Regional Lead for the Office of the CISO at Confluent, drives trust and security initiatives. Her work spans customer trust engagements across strategic and regulated accounts, including security audits, security contract negotiations, and due diligence. By translating evolving regional regulatory requirements into practical programs and customer-focused assurance, Swati helps build confidence in trusted solutions.

Did you like this blog post? Share it now