Third-Party Risk Assessment

Third-Party Risk Assessment

Third-Party Risk Assessment

Third-party risk management evaluates vendors at onboarding and periodically thereafter, assessing security posture, financial stability, subprocessor relationships, and data handling. Risk tiering allocates diligence depth by the sensitivity of data involved.

Programs typically include contractual requirements and monitoring.

Alternative Names:

TPRM, Vendor Risk Assessment

Why it Matters?

Risk tiering is what makes a program sustainable, since applying full diligence to every vendor is impractical and applying none to any is negligent. A vendor with access to client matter data warrants scrutiny that a facilities supplier does not. The recurring gap is periodic reassessment, because vendors change architecture, ownership, and subprocessors after onboarding without notifying customers.

Frequently Confused with

Related terms

Frequently asked questions

Why tier vendor risk?

Why tier vendor risk?

Because full diligence on every vendor is impractical, so depth should scale with the sensitivity of data the vendor can access.

What is the recurring gap?

What is the recurring gap?

Periodic reassessment, since vendors change architecture, ownership, and subprocessors after onboarding without notifying customers.