Third-Party Risk Management guide

Tier and assess third parties

Use factor-based tiering to determine governance intensity, then perform due diligence with versioned questionnaire assessments.

Third-Party Risk Manager / Reviewer Depends on assessment scope Updated 9 September 2026

1. Calculate the tier

Complete the configured tiering factors for the relationship. PurpleWASP stores the factor inputs, scores and rationale so the recommendation can be reviewed later.

Tier definitions can drive governance expectations such as due-diligence frequency, reassessment frequency, contract review, risk assessment or executive approval.

2. Confirm the recommended tier

Review the calculated score and recommended tier, then confirm the tier with an appropriate rationale. Confirmation is a governance decision; it does not change the enterprise Risk Register score.

Do not treat TPRM tier as residual risk. The tier determines the intensity of third-party oversight. Enterprise risk remains in Risk Management.

3. Create the due-diligence assessment

Select the appropriate questionnaire template and assessment type. The assessment can apply to the whole third party or to a specific service, and later assessments can supersede earlier ones while preserving history.

4. Review questions, applicability and evidence

Assessment questions are copied into the assessment so the issued questionnaire remains stable even if a template changes later. Questions can be required, score-bearing, evidence-required and mapped to PurpleWASP Controls.

  • Review not-applicable responses and the reason.
  • Check evidence where the question requires it.
  • Use Control mappings to understand which safeguards the answer supports.
  • Do not accept a positive answer as equivalent to verified Control effectiveness.

5. Review the submission

Use reviewer status, comments, awarded score and failure indicators to distinguish vendor responses from your organisation's review conclusion. Complete the overall result, risk indicator and reviewer summary only after material responses have been reviewed.

6. Escalate material issues when required

Assessment failures can become TPRM findings. Where the finding represents enterprise exposure, link or create the appropriate Risk Management record instead of using the TPRM tier as the Risk score.

Common problems

The calculated tier seems too high or low

Review the individual factor inputs, weights and rationale before overriding the recommendation. Record the reason for the confirmed tier.

The assessment score is strong but there is a serious failure

Review the failed question independently. A total percentage can hide a material gap, which should be handled through findings and remediation.

A questionnaire question maps to a Control

The mapping provides assurance context. It does not automatically mark the organisation Control as implemented or effective.