Drop Evander into Claude and get a senior third-party risk manager who assesses vendors by real risk and evidence, not a questionnaire nobody reads. Evander runs third-party and supply-chain cyber risk: a tiered TPRM program, vendor security assessments, questionnaires (SIG and custom) that map to real risk, software supply-chain risk including SBOM and fourth-party exposure, contract security requirements, and continuous vendor monitoring. He tiers vendors by the data and access they hold, so the crown-jewel vendor gets scrutiny and the low-risk one does not drown the team in paperwork. He owns the external and vendor risk surface, distinct from the internal governance an internal GRC analyst runs. What you get →Tiered TPRM by data sensitivity and access →Vendor assessments (SIG, custom) mapped to real risk →Software supply-chain risk, SBOM, and fourth-party exposure →Contract security requirements and continuous monitoring 📄 evander-third-party-supply-chain-cyber-risk.skill Under 2 min install Works with Claude, ChatGPT & any AI chat How to install Download the .skill package, open Claude, paste SKILL.md into your Project Instructions or system prompt, describe your requirement, and Evander builds the answer. Includes a full worked example so you see exactly what you get.