GRC platform

TrustVendor + OneTrust

OneTrust is the leading GRC and privacy management platform. TrustVendor's Vendor Pulse API embeds real-time vendor risk intelligence into OneTrust's third-party risk management module.

How data flows

TrustVendor exposes a REST API and webhooks consumed by OneTrust's workflow engine. Vendor assessments in OneTrust are enriched with live posture, assurance, and certification data.

How to set up

  1. 1 Configure TrustVendor as a data source in OneTrust's integration hub.
  2. 2 Map your third-party inventory to TrustVendor vendor profiles.
  3. 3 Configure risk thresholds and workflow triggers.
  4. 4 Enable continuous evidence enrichment for your third-party assessments.

Common questions

Does TrustVendor integrate with OneTrust's privacy module?
Subprocessor data and data class tracking from TrustVendor are relevant to OneTrust's privacy impact assessment and data mapping workflows.
How do TrustVendor claim predicates map to OneTrust's third-party risk assessment fields?
TrustVendor's predicate vocabulary — certification.active, subprocessor.listed, incident.disclosed, dataflow.declared, and others — maps to OneTrust assessment fields via a configurable field-mapping layer in OneTrust's integration hub. A reference mapping document covering the most common TPRM assessment templates is available from TrustVendor support, and you can extend it for custom assessment templates your team has built.
Can TrustVendor evidence attachments be added to OneTrust assessment responses automatically?
Yes. When TrustVendor detects a new or renewed certification, the artifact's signed snapshot URL is included in the webhook payload. OneTrust's workflow engine can be configured to attach this URL to the corresponding evidence field in an open assessment, eliminating the manual step of downloading and uploading documents.
Does TrustVendor support OneTrust's SAML SSO for user authentication?
SAML SSO for the TrustVendor workspace is available on Growth and Scale plans. Because the OneTrust integration authenticates via a service-account API key rather than user sessions, SSO configuration applies to your human users accessing TrustVendor, not to the integration itself. The API key is scoped to read access on vendor data and write access on watchlist enrollment only.
How does TrustVendor handle regulatory-body reporting workflows in OneTrust?
TrustVendor surfaces signals of type regulatory_action — SEC enforcement notices, HHS OCR HIPAA breach filings, GDPR enforcement tracker entries, and state AG actions — as structured claims with source citations. These feed into OneTrust's risk register enrichment, providing documented evidence of a vendor's regulatory history that your team can reference when completing cross-border transfer impact assessments or regulatory reporting workflows.
Book a demo See API pricing