Third-party risk management evaluates vendors at onboarding and periodically thereafter, assessing security posture, financial stability, subprocessor relationships, and data handling. Risk tiering allocates diligence depth by the sensitivity of data involved.
Programs typically include contractual requirements and monitoring.
Alternative Names:
TPRM, Vendor Risk Assessment
Why it Matters?
Risk tiering is what makes a program sustainable, since applying full diligence to every vendor is impractical and applying none to any is negligent. A vendor with access to client matter data warrants scrutiny that a facilities supplier does not. The recurring gap is periodic reassessment, because vendors change architecture, ownership, and subprocessors after onboarding without notifying customers.
Frequently Confused with
Related terms
Frequently asked questions
Why tier vendor risk?
What is the recurring gap?





