Glossary Terms

Third-Party Risk Management

The lifecycle process for identifying and controlling risks created by vendors, partners and other external organisations.
On this page

What is third-party risk management?

Third-party risk management, or TPRM, is the lifecycle process used to identify, assess and control risks created by vendors, suppliers, partners and other external organisations. It can cover privacy, cybersecurity, operational resilience, legal compliance, financial stability, concentration, ethics and AI use.

The programme begins before contracting and continues through onboarding, service changes, renewal and offboarding. A one-time questionnaire is not sufficient for critical or high-risk relationships because providers, products, sub-processors and threat conditions change.

Why does third-party risk matter?

Organisations remain exposed when a provider mishandles data, suffers a breach, fails operationally or uses AI in an unexpected way. Outsourcing a process does not outsource accountability or customer impact. Complex supply chains can also hide fourth parties and international transfers.

Effective TPRM helps teams make consistent procurement decisions, focus oversight according to risk and maintain evidence for customers, regulators and audits.

How are third parties assessed?

Assessment usually begins with inherent-risk tiering based on data, access, criticality, geography, connectivity and service type. Due diligence may review policies, certifications, test reports, architecture, incident history, financial information, sub-processors and contract terms.

Evidence should be evaluated rather than merely collected. Identified gaps need owners, remediation deadlines, compensating controls or formal risk acceptance.

How does ongoing monitoring work?

Monitoring can include updated evidence, security ratings, incident alerts, sub-processor changes, service performance, regulatory developments and contract renewals. The frequency should reflect risk. Critical providers may require regular review and resilience testing.

Offboarding should remove access, recover assets, confirm deletion, preserve necessary evidence and manage replacement or transition. Dependencies should be understood before the relationship ends.

Frequently asked questions

Does every vendor need the same assessment?

No. Assessment should be proportionate. A provider with sensitive data or critical access requires deeper review than a low-risk supplier.

What is inherent vendor risk?

It is the risk created by the proposed service before considering the provider’s controls or contractual safeguards.

Can certifications replace due diligence?

No. Certifications provide useful evidence but may not cover the specific service, configuration, data or risk relevant to the organisation.

Who owns vendor risk?

The business owner remains accountable for the relationship, supported by procurement, security, privacy, legal, risk and operational teams.

Should AI vendors receive additional review?

Yes, where relevant. Review should cover model purpose, data use, training, outputs, monitoring, human oversight, security and regulatory roles.

Book your personalised demo!
And see how leading organisations are already powering their Privacy and AI Governance with context-aware operations.