Help Centre workspace

Third-Party Risk Management

Discover external relationships, establish ownership and tiering, perform due diligence, manage findings and monitor ongoing third-party risk.

Start with the workflow

From vendor reference to governed relationship

TPRM turns supplier and service dependency data into a repeatable lifecycle with due diligence, assurance, remediation and review.

1
Discover

Find candidate third parties from Asset vendor references or add them directly.

2
Onboard

Create the relationship, owners, services and Asset dependencies.

3
Tier

Use factor-based scoring to determine governance intensity.

4
Assess

Issue due-diligence assessments and review responses and evidence.

5
Monitor

Track findings, contracts, data, reviews, events and incidents over time.

TPRM workflows

Govern the full third-party lifecycle

Start with the relationship, then apply the level of due diligence and monitoring appropriate to the confirmed tier.

Important operating rules

Tiering is not the enterprise Risk Register

The TPRM tier determines how much governance and due diligence a relationship requires. Enterprise risk remains governed in Risk Management and is linked explicitly when needed.

  • Asset discovery suggestions are candidates until a user accepts them.
  • A third party can have multiple services with different criticality and data exposure.
  • Assessment findings can be remediated in TPRM and escalated to Risk where required.
  • Monitoring signals require review before they become findings or incidents.