Third-Party Risk Management

Third-Party Risk Management is the process of identifying, assessing, and monitoring the risks an organization inherits from its vendors, suppliers, and other third parties.

TPRM & GRC

Why it matters

TPRM drives the security questionnaires and evidence requests vendors must respond to, making it the buyer-side counterpart to questionnaire automation.

Where it appears in the workflow

The overarching program under which vendor intake, assessment, scoring, and reassessment occur.

Common mistakes

  1. Treating third-party risk management as a universal term with no workflow context.