Manage Vendor Risk
Third Party Risk Management and Vendor Assessment
Your vendors can be your weakest link. We help you build a third party risk programme that vets suppliers, tracks their security, and keeps your own compliance intact.
See the engagement path, 6 phasesSee the full Compliance service index
Overview
Third party risk management, or TPRM, is how you assess and control the risk that suppliers, partners, and cloud services introduce into your business. It matters because a breach at a vendor can become your breach, and frameworks like ISO 27001, SOC 2, and the DPDP Act all expect you to manage it. We help you build a repeatable programme: know who your vendors are, tier them by risk, assess the ones that matter, and keep watch after onboarding rather than filing a questionnaire and forgetting it.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the Third Party Risk Assessment (TPRM) engagement, 6 phases in order, each one selectable. Phase 1, Vendor Inventory and Tiering. We build a full list of your third parties and tier them by the risk each one carries to your data and operations. Activities: Compile the vendor list from procurement and finance; Identify what data and access each vendor holds; Define tiering criteria by data sensitivity and criticality; Assign each vendor to a risk tier. Hands over Vendor Inventory with Risk Tiering. Phase 2, Assessment Framework Design. We design questionnaires and criteria that match each tier, so critical vendors get real scrutiny and low-risk ones stay light. Activities: Build tier-specific questionnaires from SIG and ISO 27036; Set scoring criteria and pass thresholds; Define evidence requirements per tier; Agree escalation rules for failed assessments. Hands over Assessment Framework and Questionnaire Set. Phase 3, Due Diligence Assessment. We assess your key vendors against their controls, certifications, and evidence, and score the findings. Activities: Issue questionnaires to in-scope vendors; Review SOC 2 reports and certifications supplied; Validate answers against supporting evidence; Score findings and flag unacceptable risks. Hands over Vendor Due Diligence Reports. Phase 4, Risk Treatment and Contracts. We help you address gaps through remediation, contract clauses, and clear security requirements. Activities: Agree remediation plans with high-risk vendors; Draft security and breach notification clauses; Update contracts at renewal points; Record accepted risks with business sign-off. Hands over Risk Treatment Plan and Contract Clause Library. Phase 5, Ongoing Monitoring. We set up continuous monitoring and reassessment cadences so vendor risk stays visible after onboarding. Activities: Enrol critical vendors in security rating monitoring; Set reassessment cadences per tier; Configure alerts for vendor breaches and rating drops; Track remediation commitments to closure. Hands over Monitoring Setup and Reassessment Calendar. Phase 6, Reporting and Governance. We give you reporting that satisfies your own auditors and feeds your wider compliance programme. Activities: Build the vendor risk dashboard for leadership; Map TPRM evidence to ISO 27001 and SOC 2 controls; Set governance forums and review cadence; Prepare audit-ready reporting packs. Hands over TPRM Governance Pack and Reporting Dashboard. Each phase begins from the artefact the phase before it produced.
Phase 01 Vendor Inventory and Tiering
We build a full list of your third parties and tier them by the risk each one carries to your data and operations.
What Happens In This Phase
- Compile the vendor list from procurement and finance
- Identify what data and access each vendor holds
- Define tiering criteria by data sensitivity and criticality
- Assign each vendor to a risk tier
The Handover
Vendor Inventory with Risk Tiering
The next phase starts from this.
Phase 01 Vendor Inventory and Tiering
We build a full list of your third parties and tier them by the risk each one carries to your data and operations.
What Happens In This Phase
- Compile the vendor list from procurement and finance
- Identify what data and access each vendor holds
- Define tiering criteria by data sensitivity and criticality
- Assign each vendor to a risk tier
The Handover
Vendor Inventory with Risk Tiering
The next phase starts from this.
- 01
Vendor Inventory and Tiering
We build a full list of your third parties and tier them by the risk each one carries to your data and operations.
OutputVendor Inventory with Risk TieringActivities
- Compile the vendor list from procurement and finance
- Identify what data and access each vendor holds
- Define tiering criteria by data sensitivity and criticality
- Assign each vendor to a risk tier
- 02
Assessment Framework Design
We design questionnaires and criteria that match each tier, so critical vendors get real scrutiny and low-risk ones stay light.
OutputAssessment Framework and Questionnaire SetActivities
- Build tier-specific questionnaires from SIG and ISO 27036
- Set scoring criteria and pass thresholds
- Define evidence requirements per tier
- Agree escalation rules for failed assessments
- 03
Due Diligence Assessment
We assess your key vendors against their controls, certifications, and evidence, and score the findings.
OutputVendor Due Diligence ReportsActivities
- Issue questionnaires to in-scope vendors
- Review SOC 2 reports and certifications supplied
- Validate answers against supporting evidence
- Score findings and flag unacceptable risks
- 04
Risk Treatment and Contracts
We help you address gaps through remediation, contract clauses, and clear security requirements.
OutputRisk Treatment Plan and Contract Clause LibraryActivities
- Agree remediation plans with high-risk vendors
- Draft security and breach notification clauses
- Update contracts at renewal points
- Record accepted risks with business sign-off
- 05
Ongoing Monitoring
We set up continuous monitoring and reassessment cadences so vendor risk stays visible after onboarding.
OutputMonitoring Setup and Reassessment CalendarActivities
- Enrol critical vendors in security rating monitoring
- Set reassessment cadences per tier
- Configure alerts for vendor breaches and rating drops
- Track remediation commitments to closure
- 06
Reporting and Governance
We give you reporting that satisfies your own auditors and feeds your wider compliance programme.
OutputTPRM Governance Pack and Reporting DashboardActivities
- Build the vendor risk dashboard for leadership
- Map TPRM evidence to ISO 27001 and SOC 2 controls
- Set governance forums and review cadence
- Prepare audit-ready reporting packs
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
Built by SecureRoot
TrustGrid
Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.
Built by SecureRoot
DPDPA Compass
Our own privacy platform. Consent, notices, data principal requests and records of processing under the DPDP Act.
What Is Examined, and What it Is Measured Against
Map
Map of the Third Party Risk Assessment (TPRM) scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: OneTrust, ProcessUnity, SecurityScorecard, BitSight, Vanta, UpGuard, Jira, Confluence. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: ISO/IEC 27036, NIST SP 800-161, ISO/IEC 27001 Annex A, SOC 2 Trust Services Criteria, Shared Assessments SIG.
What We Run
8 tools
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
5 standards
- AICPA
- SIGShared Assessments
Deliverables
What You Receive
- Vendor inventory and risk tiering
- Assessment questionnaire set
- Vendor due diligence reports
- Risk treatment and remediation plan
- Ongoing monitoring cadence
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
How do we decide which vendors to assess?
By tiering them. A vendor holding your customer data needs deep due diligence, while a low-risk supplier needs far less. We build a tiering model so effort goes where it matters.
Is a security questionnaire enough?
It is a start, not the whole job. We pair questionnaires with evidence review, certifications, and ongoing monitoring so you are not relying on a one-time answer.
How does TPRM support our other compliance work?
Standards like ISO 27001, SOC 2, and the DPDP Act all expect vendor risk management. A solid TPRM programme feeds evidence straight into those audits.
Keep Moving Through Compliance
Service 13 of 13 in this practice area
Practice Area
More in Compliance
- ISO 27001Build and certify your information security management system.
- ISO 27701Extend your ISMS into a privacy information management system.
- ISO 22301Certify how your business keeps running through disruption.
- ISO 42001Govern your AI systems with the first AI management standard.
- DPDP ActGet ready for India's Digital Personal Data Protection Act.
- PCI DSSProtect cardholder data and pass your PCI assessment.
- HIPAAProtect health information and meet HIPAA requirements.
- SOC 2Earn a SOC 2 report your customers can trust.
- CCPAMeet California's consumer privacy requirements.
- GDPRMeet Europe's data protection standard with confidence.
- NEN 7510Certify information security for Dutch healthcare.
- EU AI ActPrepare for Europe's risk-based AI regulation.