Third-party risk management (TPRM) is the ongoing process of finding out which outside parties your business depends on or shares data with, judging how much risk each one brings, and keeping an eye on that risk for as long as the relationship lasts. The outside parties are usually vendors and service providers, such as cloud platforms, SaaS tools, managed service providers and contact center outsourcers, but they can include partners, contractors and resellers too. Security is the most visible concern, but TPRM programs often also weigh financial health, operational resilience, privacy and regulatory exposure.
At a glance
- TPRM covers the whole relationship: before signing, during the contract and at exit.
- Vendors are typically tiered by risk, so the deepest review goes to the providers that hold your data or run critical processes.
- Evidence usually includes security questionnaires, independent reports such as SOC 2 or ISO/IEC 27001 certificates, and contract terms.
- Many regulations and customer contracts expect you to show how you oversee providers.
- Your vendors’ own suppliers (fourth parties) can matter too, depending on the service.
What problem it solves
Mid-market companies now run on outside services. Payroll, email, file storage, phone systems, CRM and backups often sit with providers, and many of those providers hold sensitive data or privileged access. When a provider is breached or goes down, the impact lands on you: your customers’ data, your outage, your notification duties. A supply chain attack can reach many customers through one trusted vendor.
At the same time, customers, insurers and auditors increasingly ask how you choose and oversee your vendors. Without a program, the answers are scattered across procurement emails, IT tickets and contract folders. TPRM gives a repeatable way to decide which vendors need scrutiny, what evidence is enough and who signs off on the remaining risk.
How it works
Inventory. Build and maintain a list of third parties, what each does for you, who owns the relationship and what data or systems it can reach. Finance, procurement and SaaS discovery tools often find vendors IT didn’t know about.
Tiering. Rate each vendor’s inherent risk using factors such as data sensitivity, access level, business criticality and regulatory relevance. The tier sets how deep the review goes.
Due diligence. For higher tiers, collect a security questionnaire, independent reports such as a SOC 2 report, insurance certificates, and details on subcontractors and data locations. Findings feed your risk assessment process.
Contracting. Translate requirements into terms: security obligations, breach notice timelines, audit or evidence rights, data return and deletion, and subcontractor limits.
Ongoing monitoring. Reassess on a schedule matched to the tier, track remediation commitments, and watch for incidents, ownership changes or new services. Some programs add outside security ratings or news monitoring. Significant open risks go on the risk register with an owner.
Offboarding. Revoke access, confirm data return or deletion, and close out the vendor record.
Vendor risk tiers
TPRM has no official certification levels. Most programs use internal tiers like these; the names and criteria vary by organization and regulator.
| Tier | What typically puts a vendor here | Typical review | Evidence a vendor usually shows |
|---|---|---|---|
| Critical | Holds sensitive or regulated data, has privileged access, or runs a process you can’t operate without | Full assessment before signing, annual reassessment, executive sign-off on open risks | Independent audit reports, detailed questionnaire, penetration test summary, continuity plans, insurance |
| High | Handles confidential data or connects to internal systems | Standard questionnaire plus independent report, periodic reassessment | SOC 2 or ISO/IEC 27001 evidence, questionnaire, contract security terms |
| Moderate | Limited data or access, replaceable service | Short questionnaire or attestation, review at renewal | Short-form questionnaire, policy summaries |
| Low | No access to data or systems | Basic due diligence (legal, financial, sanctions screening as applicable) | Standard contract terms |
When it matters for buyers
- When you sign a new provider that will hold data or have access. Ask for evidence before the contract, while you still have leverage.
- When a customer or regulator asks how you oversee vendors. Financial services and healthcare buyers, in particular, may be expected to show a documented process.
- When vendor sprawl sets in. Dozens of small SaaS contracts can add up to real exposure.
- When a vendor has an incident. A current inventory tells you quickly which data and systems are affected.
Our governance, risk and compliance overview covers tools and services that help run a third-party risk program.
Questions to ask vendors
- Which independent reports or certifications do you hold, and are they scoped to the service we would buy?
- Which subcontractors or sub-processors will handle our data, and where?
- How quickly will you notify us of a security incident affecting our data, and what will the notice include?
- What access will your staff have to our systems or data, and how is it controlled and logged?
- Will you agree to contract terms on security obligations, evidence on request and data return or deletion at exit?
- How do you manage risk from your own suppliers?
How it differs from vendor management
Vendor management is the broader business practice of overseeing suppliers’ performance, cost, service levels and contracts. Third-party risk management is the risk lens within or alongside it: what could go wrong because you rely on this party, and is that acceptable. In many mid-market companies the same people do both, but the questions differ. Vendor management asks whether a provider is delivering value; TPRM asks whether the provider could cause a breach, outage or compliance failure, and what you are doing about it.
