Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideDiscover external relationships, establish ownership and tiering, perform due diligence, manage findings and monitor ongoing third-party risk.
TPRM turns supplier and service dependency data into a repeatable lifecycle with due diligence, assurance, remediation and review.
Find candidate third parties from Asset vendor references or add them directly.
Create the relationship, owners, services and Asset dependencies.
Use factor-based scoring to determine governance intensity.
Issue due-diligence assessments and review responses and evidence.
Track findings, contracts, data, reviews, events and incidents over time.
Start with the relationship, then apply the level of due diligence and monitoring appropriate to the confirmed tier.
Review Asset-derived candidates, accept or dismiss suggestions and establish the governed relationship.
Due diligenceUse factor-based tiering and questionnaire assessments to determine and review third-party posture.
Ongoing oversightManage findings, remediation, assurance, contracts, data, monitoring signals, incidents and periodic review.
The TPRM tier determines how much governance and due diligence a relationship requires. Enterprise risk remains governed in Risk Management and is linked explicitly when needed.
No guidance matches that search.