Third-Party Risk Management guide

Review and monitor third parties

Manage findings and remediation, evidence, contractual obligations, data exposure, monitoring events, incidents and periodic relationship reviews.

Third-Party Risk Manager / Relationship Owner Ongoing Updated 9 September 2026

1. Manage findings and remediation

Use findings for gaps identified through assessments, monitoring or other assurance activity. Record severity, owner, due date and disposition, then create remediation actions with accountable internal and vendor owners where appropriate.

Use the requires risk or equivalent workflow when the gap should enter enterprise Risk Management.

2. Maintain evidence, contracts and obligations

Store third-party assurance records with validity, verification and integrity metadata. Link evidence to the assessment, finding, contract or other target it supports.

Use contract records to track expiry, notice periods and security/privacy clauses. Contract obligations can carry owners, due dates, review frequency and evidence requirements.

3. Record data exposure and subprocessors

Use data profiles to record classification, processing purpose, countries, encryption, retention and sensitive-data indicators at vendor or service level. Record subprocessors separately, including country, data processed, criticality and approval status.

Fourth parties matter. A subprocessor can also be linked to another managed third party when that relationship is already known to PurpleWASP.

4. Review monitoring events

Monitoring events are signals that require human review. Use source, severity, confidence, timing and raw/reference context to decide whether the event should be dismissed, tracked, escalated to a finding or linked to an incident.

5. Manage third-party incidents

Record affected services, data and business impact, notification dates, regulatory/breach-notification requirements, root cause and lessons learned. Link an enterprise Risk where the incident creates or changes material exposure.

6. Complete periodic reviews

Periodic reviews bring together current facts such as tiering, assessment status, findings, evidence, contracts and monitoring into a review package. Review items identify areas that need attention, while the stored snapshot preserves the posture considered when the decision was made.

Verify ongoing oversight

  • Open findings have owners and realistic due dates.
  • Remediation is verified before closure.
  • Assurance evidence is current and linked to what it supports.
  • Contract and obligation review dates are monitored.
  • Data and subprocessor records reflect the current service.
  • Monitoring events are reviewed rather than left untriaged.
  • Periodic reviews capture an outcome and next-review date.

Common problems

A monitoring event looks serious

Review the source and confidence, then create or link a finding/incident where the signal is substantiated. Do not treat every external signal as confirmed fact.

A remediation action is complete but the finding remains open

Verify the remediation and then update the finding disposition/status according to your review outcome.

The periodic review changed after underlying records were updated

Use the review snapshot to distinguish the facts considered at the time of the review from the relationship's current posture.