Third Party Risk Management (TPRM)

Management of compliance and security risks with suppliers and partners.

A

B

C

D

E

F

G

H

I

J

K

L

M

N

O

P

Q

R

S

T

Third Party Risk Management (TPRM) is the structured process of identifying, assessing and mitigating the compliance and security risks that arise from engaging suppliers, vendors and partners. It encompasses due diligence before onboarding, ongoing monitoring of third-party security posture, and contractual requirements for data protection and regulatory compliance. A mature TPRM programme ensures that external relationships do not introduce unacceptable risk to the organisation.

With supply chain attacks and regulatory expectations both increasing, effective TPRM has become a business-critical capability. Organisations should classify third parties by risk level and apply proportionate assessment measures, from self-assessment questionnaires to on-site audits. Regular reviews and clearly defined escalation paths ensure that emerging risks are identified and addressed before they materialise into incidents.

U

V

W

Z

Frequently asked questions

What is Third Party Risk Management (TPRM)?
TPRM is the ongoing programme for identifying, assessing and monitoring the risk that suppliers, vendors and service providers introduce — across the whole relationship, from selection through to exit.
How is TPRM different from a supplier risk assessment?
The assessment is an activity; TPRM is the programme around it. TPRM covers the inventory, tiering, contractual requirements, continuous monitoring and offboarding, and a supplier risk assessment is the step performed within it.
Which regulations require third-party risk management?
ISO 27001:2022 covers supplier relationships in Annex A controls A.5.19 to A.5.23, NIS2 makes supply chain security an explicit obligation under Article 21(2)(d), and DORA sets detailed requirements for ICT third-party risk in the financial sector.