Home / Insights / Glossary / Third-party risk management (TPRM)

Glossary

Third-party risk management (TPRM)

Assessing and governing the risk introduced by suppliers, vendors and partners.

What it means

TPRM covers supplier due diligence, contractual control, ongoing monitoring and exit. It matters because a dependency you do not operate can still stop you operating, and because regulators increasingly treat a supplier's failure as the buying organisation's failure.

The common state is a questionnaire process that produces files nobody reads and decisions nobody records — assurance as an activity rather than as an input to a decision.

Where MyRISK fits

What we do about it

Third-party risk is the most common subject in MyRISK's own pipeline. Consulting offers a scoped third-party risk assessment; where the need is to show that a specific supplier decision was reasonable and what conditions were attached, that is Trace.

Third-party risk assessment

Is this the thing you are actually trying to fix?

A definition rarely settles it. Tell us what happened — the request, the finding, the challenge or the incident — and we will say where to start, or that it isn't us.