Risk management tool for maintaining compliance information
5.0/5 (5 reviews)Great service for us, and ability to leap frog forward to build our vendor management program.
Pros
Great tool with simple portal capability that is easy to use.
Cons
We really woul like to see the ability to download the IRQ and HAX for a vendor.
Derek, thank you for your review! We are glad to hear the XChange has helped you leapfrog forward in building your vendor management program. Thank you for the helpful feedback regarding the ability to download reports. The XChange currently allows the download of IRQ results, and we will pass on your request for a report download capability to our product development team.
Rating breakdown
Likelihood to recommend: 10/10
TPRM is a full time job when performed properly. HITRUSTAX does it for me and does it well, freeing up my resources for other responsibilities and projects.
Pros
White glove setup, ability to customize to our requirements and wishes, diligent yet polite and professional follow up with my managed vendors, and the price. We are also HITRUST certified, so is nice that HITRUSTAX is under the same umbrella. We KNOW our TPRM partner is familiar with our compliance framework.
Cons
The portal is still maturing, but that can also be a strength because we are helping to polish the final product and get enhancements fairly quickly.
Chris, it is great to hear the XChange is helping with your third-party risk management efforts! We appreciate you and your team's contributions to the product innovation efforts. Thank you for the positive review!
Rating breakdown
Likelihood to recommend: 10/10
Great experience, the staff and support are awesome and have had no issues with the overall program.
Pros
The ease of use is wonderful, easy to navigate console, and great overall workflow process.
Cons
Allow offline downloads for questionnaires would be a good feature.
Victor, it's great to hear you are pleased with your experience with the XChange. We appreciate your positive review and helpful feedback regarding the offline downloads for questionnaires. The full results of the IRQ and the Gaps and Not Applicable sections of the Rapid Assessment are currently available for download. We have passed on the request for additional report download functionality to our product development team.
Rating breakdown
Likelihood to recommend: 9/10
Using HAX has allowed us to enhance our Third Party Risk Management program without the need to add additional staff, since HITRUST is managing the vendor assessment process for us.
Pros
Standardized model for calculating both Inherent Risk and Residual Risk of vendors that uses the HITRUST framework for measurement.
The ability to determine the level of assessment required for a vendor from a Rapid Assessment up to HITRUST CSF Certification.
Vendors may already exist on the XChange which minimizes the assessment time.
Cons
As an early adopter of the platform, we worked with HITRUST to build out features most notability on various status updates.
The reporting features are still in development, but API's can be used to integrate with GRC tools to support individual reporting needs.
Brian, we are pleased to hear the XChange has helped you enhance your Third-Party Risk Management program in an efficient manner. We want to thank you and your team for being early adopters of the XChange and helping guide the product development.
Rating breakdown
Likelihood to recommend: 10/10
Pros
A condensed effective questionnaire that gives assurance of the vendors security program.
Cons
Inability to export full report for record keeping purpose.
Willie, we appreciate your positive review! Thank you for your helpful feedback regarding the ability to export full reports for record-keeping purposes. This request has been passed on to our product development team.
Rating breakdown
Likelihood to recommend: 10/10
Please contact HITRUST Assessment Exchange directly for pricing information.