The Diligence Certificate System auto-issues program-level certificates of diligence — TPRM, continuous monitoring, supply chain, ERM, policy, training and per-decision risk acceptance — each tamper-evident, framework-mapped, and filed straight into the Data Room.
Issued when a TPRM program is active with vendors in portfolio and a completed assessment — mapped to NIST CSF ID.SC controls.
Issued when LiveThreat monitoring is active on at least one vendor — mapped to NIST CSF DE.CM and ISO 27001 supplier controls.
Issued when an SBOM is ingested — mapped to NIST CSF ID.SC, NIST SP 800-161 and ISO 27036.
Issued for an active ERM program with a risk acceptance on record — mapped to NIST GV/RA, ISO 31000 and COSO ERM.
Separate certificates attest a published, acknowledged policy program and workforce training completion above threshold.
A SOX-grade risk acceptance approved with all required signoffs issues its own certificate — mapped to SOX 404 and COSO.
An eligibility check runs daily; certificates issue automatically the moment a tenant crosses a threshold, and re-issue as evidence refreshes — no one commissions a PDF.
Every certificate PDF embeds its control mappings, so auditors and customers see at a glance which controls it evidences.
Each certificate is written to storage and also registered as a Data Room file entry — one artefact, reachable by download link or in the room.
Certificates land in the right Data Room folder — Compliance, Vendor Risk, RiskOps, Privacy — browsable next to the evidence behind them.
Diligence Certificates are part of the Trust Operations Platform — issued from your live evidence, mapped to frameworks, and filed where auditors and customers can verify them.