Third-party risk management (TPRM) is the discipline of identifying, assessing, and controlling the risks an organisation inherits from vendors, suppliers, and other external partners. It covers due diligence, contractual controls, ongoing monitoring, and offboarding across security, compliance, operational, and reputational dimensions. TPRM has become essential as organisations rely on extended ecosystems of cloud services and outsourced functions.

Content

  • A TPRM programme inventories third parties, tiers them by criticality, and applies proportionate due diligence such as security questionnaires, certification review, and financial assessment before onboarding. Contractual clauses set obligations for data protection, breach notification, and audit rights, while continuous monitoring tracks changes in posture over time. Mature programmes integrate TPRM with supply chain security and concentration-risk analysis so that dependence on critical fourth parties is also surfaced and managed.