Third-Party Risk Management
Third-Party Risk Management is the process of identifying, assessing, and monitoring the risks an organization inherits from its vendors, suppliers, and other third parties.
Why it matters
TPRM drives the security questionnaires and evidence requests vendors must respond to, making it the buyer-side counterpart to questionnaire automation.
Where it appears in the workflow
The overarching program under which vendor intake, assessment, scoring, and reassessment occur.
Common mistakes
- Treating third-party risk management as a universal term with no workflow context.