Third-Party Risk Management guide

Discover and onboard third parties

Turn vendor names already present in Asset Management into governed TPRM records, or create and import relationships directly.

Third-Party Risk Manager 10–20 minutes per relationship Updated 9 September 2026

1. Discover candidates from Assets

Use Discover from Assets to scan existing Asset vendor references and surface names that may represent unmanaged third-party relationships. Candidate cards show the suggested name, the number of related Assets and a confidence indicator where available.

2. Accept or dismiss each candidate

Review each suggestion before turning it into a managed third party.

  • Accept when the candidate represents a real relationship that should enter TPRM.
  • Dismiss when the name is internal, duplicate, irrelevant or should not become a managed relationship.
  • Use the Asset count and source context to resolve ambiguous names.
Discovery does not auto-create vendors. The candidate remains separate until a user makes the decision.

3. Complete the third-party record

Confirm the legal or trading name, relationship status, countries, owners, dates and next-review information. Use ownership fields to separate relationship, business and procurement responsibilities where your operating model requires them.

4. Add services and Asset dependencies

Record the specific services the third party provides. A service can carry its own criticality, data-processing, access, recovery and review information, and can be linked to the Assets it supports.

  • Use direct third-party-to-Asset links for the overall vendor relationship.
  • Use service-to-Asset links where the dependency belongs to a specific service.
  • Mark the appropriate Asset as the risk-subject Asset when that relationship is used in a Risk workflow.

5. Use bulk import when appropriate

For larger onboarding exercises, use the current third-party import template and validate a small sample first. Preserve required headers and use stable identifiers to reduce duplicate records.

Verify onboarding

  • The candidate decision is recorded.
  • The third party has the correct relationship status and accountable owners.
  • Relevant services are captured separately.
  • Asset and service dependencies point to the intended records.
  • Next due-diligence and review dates are populated when known.
  • The relationship is ready for tiering.

Common problems

The same company appears more than once

Review aliases, legal/trading names and the source Asset references before accepting another candidate. Prefer one managed third party with aliases and multiple services.

An Asset vendor should not be a TPRM relationship

Dismiss the candidate. Discovery is intentionally a suggestion workflow, not an automatic conversion.

A vendor supports several services

Create separate service records so criticality, data exposure, recovery requirements and reviews can differ by service.