What Is TPRM (Third-Party Risk Management)?

Also called: Vendor risk management, VRM

Related problems: Customers and auditors asking how we vet our vendors; Dozens of SaaS tools and providers with access to our data and nobody tracking them; A supplier's breach became our incident; Security questionnaires pile up with no way to decide which vendors matter most

Third-party risk management (TPRM) is the ongoing process of finding out which outside parties your business depends on or shares data with, judging how much risk each one brings, and keeping an eye on that risk for as long as the relationship lasts. The outside parties are usually vendors and service providers, such as cloud platforms, SaaS tools, managed service providers and contact center outsourcers, but they can include partners, contractors and resellers too. Security is the most visible concern, but TPRM programs often also weigh financial health, operational resilience, privacy and regulatory exposure.

At a glance

  • TPRM covers the whole relationship: before signing, during the contract and at exit.
  • Vendors are typically tiered by risk, so the deepest review goes to the providers that hold your data or run critical processes.
  • Evidence usually includes security questionnaires, independent reports such as SOC 2 or ISO/IEC 27001 certificates, and contract terms.
  • Many regulations and customer contracts expect you to show how you oversee providers.
  • Your vendors’ own suppliers (fourth parties) can matter too, depending on the service.

What problem it solves

Mid-market companies now run on outside services. Payroll, email, file storage, phone systems, CRM and backups often sit with providers, and many of those providers hold sensitive data or privileged access. When a provider is breached or goes down, the impact lands on you: your customers’ data, your outage, your notification duties. A supply chain attack can reach many customers through one trusted vendor.

At the same time, customers, insurers and auditors increasingly ask how you choose and oversee your vendors. Without a program, the answers are scattered across procurement emails, IT tickets and contract folders. TPRM gives a repeatable way to decide which vendors need scrutiny, what evidence is enough and who signs off on the remaining risk.

How it works

Inventory. Build and maintain a list of third parties, what each does for you, who owns the relationship and what data or systems it can reach. Finance, procurement and SaaS discovery tools often find vendors IT didn’t know about.

Tiering. Rate each vendor’s inherent risk using factors such as data sensitivity, access level, business criticality and regulatory relevance. The tier sets how deep the review goes.

Due diligence. For higher tiers, collect a security questionnaire, independent reports such as a SOC 2 report, insurance certificates, and details on subcontractors and data locations. Findings feed your risk assessment process.

Contracting. Translate requirements into terms: security obligations, breach notice timelines, audit or evidence rights, data return and deletion, and subcontractor limits.

Ongoing monitoring. Reassess on a schedule matched to the tier, track remediation commitments, and watch for incidents, ownership changes or new services. Some programs add outside security ratings or news monitoring. Significant open risks go on the risk register with an owner.

Offboarding. Revoke access, confirm data return or deletion, and close out the vendor record.

Vendor risk tiers

TPRM has no official certification levels. Most programs use internal tiers like these; the names and criteria vary by organization and regulator.

Tier What typically puts a vendor here Typical review Evidence a vendor usually shows
Critical Holds sensitive or regulated data, has privileged access, or runs a process you can’t operate without Full assessment before signing, annual reassessment, executive sign-off on open risks Independent audit reports, detailed questionnaire, penetration test summary, continuity plans, insurance
High Handles confidential data or connects to internal systems Standard questionnaire plus independent report, periodic reassessment SOC 2 or ISO/IEC 27001 evidence, questionnaire, contract security terms
Moderate Limited data or access, replaceable service Short questionnaire or attestation, review at renewal Short-form questionnaire, policy summaries
Low No access to data or systems Basic due diligence (legal, financial, sanctions screening as applicable) Standard contract terms

When it matters for buyers

  • When you sign a new provider that will hold data or have access. Ask for evidence before the contract, while you still have leverage.
  • When a customer or regulator asks how you oversee vendors. Financial services and healthcare buyers, in particular, may be expected to show a documented process.
  • When vendor sprawl sets in. Dozens of small SaaS contracts can add up to real exposure.
  • When a vendor has an incident. A current inventory tells you quickly which data and systems are affected.

Our governance, risk and compliance overview covers tools and services that help run a third-party risk program.

Questions to ask vendors

  • Which independent reports or certifications do you hold, and are they scoped to the service we would buy?
  • Which subcontractors or sub-processors will handle our data, and where?
  • How quickly will you notify us of a security incident affecting our data, and what will the notice include?
  • What access will your staff have to our systems or data, and how is it controlled and logged?
  • Will you agree to contract terms on security obligations, evidence on request and data return or deletion at exit?
  • How do you manage risk from your own suppliers?

How it differs from vendor management

Vendor management is the broader business practice of overseeing suppliers’ performance, cost, service levels and contracts. Third-party risk management is the risk lens within or alongside it: what could go wrong because you rely on this party, and is that acceptable. In many mid-market companies the same people do both, but the questions differ. Vendor management asks whether a provider is delivering value; TPRM asks whether the provider could cause a breach, outage or compliance failure, and what you are doing about it.

Frequently Asked Questions

Is TPRM the same as vendor risk management?
In most organizations, yes. Vendor risk management is the older and narrower name; third-party risk management can also cover partners, resellers, contractors and other outside parties that are not strictly vendors.
Do we have to assess every vendor the same way?
No, and most programs don't. Vendors are usually tiered by the data, access and business processes they touch, and the depth of review follows the tier: a full assessment and contract terms for critical providers, a lighter check for low-risk ones.
Is a SOC 2 report enough to approve a vendor?
It is strong evidence, but check that the report covers the service you are buying, that its period is recent, and what exceptions and complementary user controls it lists. Many programs pair it with a questionnaire, contract terms and ongoing monitoring.
Which regulations expect third-party risk management?
Several do, depending on your industry and location. Examples include financial-sector rules such as GLBA safeguards, the New York DFS cybersecurity regulation and banking guidance, plus HIPAA business associate requirements in healthcare. Confirm what applies to you with counsel or your auditor; this is not legal advice.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.