Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.
Part of Compliance13 services in this practice area

Manage Vendor Risk

Third Party Risk Management and Vendor Assessment

Your vendors can be your weakest link. We help you build a third party risk programme that vets suppliers, tracks their security, and keeps your own compliance intact.

See the engagement path, 6 phasesSee the full Compliance service index

Overview

Third party risk management, or TPRM, is how you assess and control the risk that suppliers, partners, and cloud services introduce into your business. It matters because a breach at a vendor can become your breach, and frameworks like ISO 27001, SOC 2, and the DPDP Act all expect you to manage it. We help you build a repeatable programme: know who your vendors are, tier them by risk, assess the ones that matter, and keep watch after onboarding rather than filing a questionnaire and forgetting it.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the Third Party Risk Assessment (TPRM) engagement, 6 phases in order, each one selectable. Phase 1, Vendor Inventory and Tiering. We build a full list of your third parties and tier them by the risk each one carries to your data and operations. Activities: Compile the vendor list from procurement and finance; Identify what data and access each vendor holds; Define tiering criteria by data sensitivity and criticality; Assign each vendor to a risk tier. Hands over Vendor Inventory with Risk Tiering. Phase 2, Assessment Framework Design. We design questionnaires and criteria that match each tier, so critical vendors get real scrutiny and low-risk ones stay light. Activities: Build tier-specific questionnaires from SIG and ISO 27036; Set scoring criteria and pass thresholds; Define evidence requirements per tier; Agree escalation rules for failed assessments. Hands over Assessment Framework and Questionnaire Set. Phase 3, Due Diligence Assessment. We assess your key vendors against their controls, certifications, and evidence, and score the findings. Activities: Issue questionnaires to in-scope vendors; Review SOC 2 reports and certifications supplied; Validate answers against supporting evidence; Score findings and flag unacceptable risks. Hands over Vendor Due Diligence Reports. Phase 4, Risk Treatment and Contracts. We help you address gaps through remediation, contract clauses, and clear security requirements. Activities: Agree remediation plans with high-risk vendors; Draft security and breach notification clauses; Update contracts at renewal points; Record accepted risks with business sign-off. Hands over Risk Treatment Plan and Contract Clause Library. Phase 5, Ongoing Monitoring. We set up continuous monitoring and reassessment cadences so vendor risk stays visible after onboarding. Activities: Enrol critical vendors in security rating monitoring; Set reassessment cadences per tier; Configure alerts for vendor breaches and rating drops; Track remediation commitments to closure. Hands over Monitoring Setup and Reassessment Calendar. Phase 6, Reporting and Governance. We give you reporting that satisfies your own auditors and feeds your wider compliance programme. Activities: Build the vendor risk dashboard for leadership; Map TPRM evidence to ISO 27001 and SOC 2 controls; Set governance forums and review cadence; Prepare audit-ready reporting packs. Hands over TPRM Governance Pack and Reporting Dashboard. Each phase begins from the artefact the phase before it produced.

Phase 01 Vendor Inventory and Tiering

We build a full list of your third parties and tier them by the risk each one carries to your data and operations.

What Happens In This Phase

  • Compile the vendor list from procurement and finance
  • Identify what data and access each vendor holds
  • Define tiering criteria by data sensitivity and criticality
  • Assign each vendor to a risk tier

The Handover

Vendor Inventory with Risk Tiering

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Vendor Inventory and Tiering

    We build a full list of your third parties and tier them by the risk each one carries to your data and operations.

    OutputVendor Inventory with Risk Tiering

    Activities

    • Compile the vendor list from procurement and finance
    • Identify what data and access each vendor holds
    • Define tiering criteria by data sensitivity and criticality
    • Assign each vendor to a risk tier
  2. 02

    Assessment Framework Design

    We design questionnaires and criteria that match each tier, so critical vendors get real scrutiny and low-risk ones stay light.

    OutputAssessment Framework and Questionnaire Set

    Activities

    • Build tier-specific questionnaires from SIG and ISO 27036
    • Set scoring criteria and pass thresholds
    • Define evidence requirements per tier
    • Agree escalation rules for failed assessments
  3. 03

    Due Diligence Assessment

    We assess your key vendors against their controls, certifications, and evidence, and score the findings.

    OutputVendor Due Diligence Reports

    Activities

    • Issue questionnaires to in-scope vendors
    • Review SOC 2 reports and certifications supplied
    • Validate answers against supporting evidence
    • Score findings and flag unacceptable risks
  4. 04

    Risk Treatment and Contracts

    We help you address gaps through remediation, contract clauses, and clear security requirements.

    OutputRisk Treatment Plan and Contract Clause Library

    Activities

    • Agree remediation plans with high-risk vendors
    • Draft security and breach notification clauses
    • Update contracts at renewal points
    • Record accepted risks with business sign-off
  5. 05

    Ongoing Monitoring

    We set up continuous monitoring and reassessment cadences so vendor risk stays visible after onboarding.

    OutputMonitoring Setup and Reassessment Calendar

    Activities

    • Enrol critical vendors in security rating monitoring
    • Set reassessment cadences per tier
    • Configure alerts for vendor breaches and rating drops
    • Track remediation commitments to closure
  6. 06

    Reporting and Governance

    We give you reporting that satisfies your own auditors and feeds your wider compliance programme.

    OutputTPRM Governance Pack and Reporting Dashboard

    Activities

    • Build the vendor risk dashboard for leadership
    • Map TPRM evidence to ISO 27001 and SOC 2 controls
    • Set governance forums and review cadence
    • Prepare audit-ready reporting packs

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Built by SecureRoot

TrustGrid

Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.

Built by SecureRoot

DPDPA Compass

Our own privacy platform. Consent, notices, data principal requests and records of processing under the DPDP Act.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the Third Party Risk Assessment (TPRM) scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: OneTrust, ProcessUnity, SecurityScorecard, BitSight, Vanta, UpGuard, Jira, Confluence. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: ISO/IEC 27036, NIST SP 800-161, ISO/IEC 27001 Annex A, SOC 2 Trust Services Criteria, Shared Assessments SIG.

What We Run

8 tools

  • OneTrust
  • ProcessUnity
  • SecurityScorecard
  • BitSight
  • Vanta
  • UpGuard
  • Jira
  • Confluence

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

5 standards

  • ISO/IEC 27036
  • NIST SP 800-161
  • ISO/IEC 27001 Annex A
  • SOC2AICPATrust Services Criteria
  • SIGShared Assessments
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Vendor inventory and risk tiering
  • Assessment questionnaire set
  • Vendor due diligence reports
  • Risk treatment and remediation plan
  • Ongoing monitoring cadence

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

How do we decide which vendors to assess?

By tiering them. A vendor holding your customer data needs deep due diligence, while a low-risk supplier needs far less. We build a tiering model so effort goes where it matters.

Is a security questionnaire enough?

It is a start, not the whole job. We pair questionnaires with evidence review, certifications, and ongoing monitoring so you are not relying on a one-time answer.

How does TPRM support our other compliance work?

Standards like ISO 27001, SOC 2, and the DPDP Act all expect vendor risk management. A solid TPRM programme feeds evidence straight into those audits.

Keep Moving Through Compliance

Service 13 of 13 in this practice area