Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideTurn vendor names already present in Asset Management into governed TPRM records, or create and import relationships directly.
Use Discover from Assets to scan existing Asset vendor references and surface names that may represent unmanaged third-party relationships. Candidate cards show the suggested name, the number of related Assets and a confidence indicator where available.
Review each suggestion before turning it into a managed third party.
Confirm the legal or trading name, relationship status, countries, owners, dates and next-review information. Use ownership fields to separate relationship, business and procurement responsibilities where your operating model requires them.
Record the specific services the third party provides. A service can carry its own criticality, data-processing, access, recovery and review information, and can be linked to the Assets it supports.
For larger onboarding exercises, use the current third-party import template and validate a small sample first. Preserve required headers and use stable identifiers to reduce duplicate records.
Review aliases, legal/trading names and the source Asset references before accepting another candidate. Prefer one managed third party with aliases and multiple services.
Dismiss the candidate. Discovery is intentionally a suggestion workflow, not an automatic conversion.
Create separate service records so criticality, data exposure, recovery requirements and reviews can differ by service.