Copla has launched third-party risk management software aimed at any organisation handling vendor relationships across procurement, IT, legal and compliance functions, extending well beyond regulated financial entities.
The launch responds to a compliance gap that spans industries rather than sitting within one. According to the World Economic Forum’s Global Cybersecurity Outlook 2025, 69% of organisations find regulations too complex or too numerous, or are unable to confirm whether their third-party suppliers actually meet requirements.
Across most companies, the shortfall stems from four recurring problems: risk checks carried out annually instead of continuously, onboarding that relies on manually chasing documents, reporting undermined by errors from moving data between spreadsheets, and risk accumulating several layers down a subcontractor chain that no single register was designed to capture.
That pressure is sharper still within regulated sectors. Financial firms subject to the EU’s Digital Operational Resilience Act (DORA) are required to keep a Register of Information on their ICT third-party providers permanently current, rather than submitting it as a once-a-year exercise.
Preparedness for this obligation has fallen short: during the European Supervisory Authorities’ 2024 dry-run, fewer than 6.5% of the nearly 1,000 participating firms cleared every data quality check, while separate findings showed just 8% of financial entities achieved full compliance with DORA’s third-party risk rules, and 46% identified the register as the toughest element to satisfy.
Copla argues that the root cause, keeping vendor relationships, certifications and contract terms aligned without one shared source of truth, extends far beyond financial services.
Copla’s third-party risk management software replaces the scattered registers, spreadsheets and email chains many teams currently depend on with a single system covering onboarding, risk assessment and continuous monitoring.
Its capabilities span vendor inventory and onboarding with automated document collection and questionnaires, approval workflows spanning multiple teams, risk scoring across six domains, certification tracking with expiry alerts, breach and dark-web monitoring, contract lifecycle management, and an audit-ready log of changes.
The software is available immediately to companies of any size managing third-party vendor relationships.
Copla CEO and co-founder Aurimas Bakas said, “Manual monitoring assumes risk waits for the calendar. In practice, certifications lapse on their own schedule, vendors get breached mid-quarter, and by the time an annual review catches it, the gap has usually been open for months.
“We built the software to close that gap: to track third-party risk as it changes, flag it as it happens, and keep the record current enough that an audit never starts with a scramble.”
With this launch considered, what does Copla catch that traditional third-party risk programmes miss?
According to Bakas, most traditional third-party risk management programmes include vendor registries, questionnaires and security risk assessments — a good starting point, but in his opinion, not enough.
He said, “Copla’s third-party risk management software handles the full vendor lifecycle, including sourcing, onboarding, due diligence, contract management, continuous risk monitoring and reporting.”
Additionally, what changes when third-party risk moves from annual reviews to continuous monitoring?
At Copla, Bakas claims it is the firm’s mission to build controls that reduce real risk rather than just documentation that satisfies an auditor. DORA’s own language points the same way: Article 28 sets out enduring responsibility for outsourcing arrangements, not a once-a-year assessment obligation.
Bakas concluded, “Because as important as compliance is, you have to know the tools you’re using will protect you in real scenarios. An annual review produces a point-in-time judgement that starts decaying the day it’s filed. A new breach, a new subcontractor, and a changed certificate all sit outside it until the next cycle. Continuous monitoring catches risk indicators as they happen, and allows companies to react in time.”
Copyright © 2026 RegTech Analyst
Copyright © 2026 RegTech Analyst





