Manage Vendor Risk
Third Party Risk Management and Vendor Assessment
Your vendors can be your weakest link, and your regulators and customers already treat their failures as yours. We help you build a third party risk programme that tiers suppliers, assesses the ones that matter, and keeps watch after onboarding.
See the engagement path, 6 phasesSee the full Compliance service index
Overview
Third party risk management is how you assess and control the risk that suppliers, partners and cloud services bring into your business. It matters because a breach at a vendor becomes your incident, your customers' questionnaires ask how you manage it, and the frameworks and laws you answer to all require it: ISO 27001 and SOC 2 expect supplier controls, the DPDP Act makes you accountable for the processors handling personal data on your behalf, and Indian financial regulators set expectations for outsourced IT and third-party arrangements. We help Indian companies build a repeatable programme: know who your vendors are, tier them by risk, assess the ones that matter, write the contract terms, and keep monitoring rather than filing a questionnaire and forgetting it.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the Third Party Risk Assessment (TPRM) engagement, 6 phases in order, each one selectable. Phase 1, Vendor Inventory and Tiering. We build a full list of your third parties and tier them by the risk each one carries to your data and operations. Activities: Compile the vendor list from procurement and finance; Identify what data and access each vendor holds; Define tiering criteria by data sensitivity and criticality; Assign each vendor to a risk tier. Hands over Vendor Inventory with Risk Tiering. Phase 2, Assessment Framework Design. We design questionnaires and criteria that match each tier, so critical vendors get real scrutiny and low-risk ones stay light. Activities: Build tier-specific questionnaires from SIG and ISO 27036; Set scoring criteria and pass thresholds; Define evidence requirements per tier; Agree escalation rules for failed assessments. Hands over Assessment Framework and Questionnaire Set. Phase 3, Due Diligence Assessment. We assess your key vendors against their controls, certifications, and evidence, and score the findings. Activities: Issue questionnaires to in-scope vendors; Review SOC 2 reports and certifications supplied; Validate answers against supporting evidence; Score findings and flag unacceptable risks. Hands over Vendor Due Diligence Reports. Phase 4, Risk Treatment and Contracts. We help you address gaps through remediation, contract clauses, and clear security requirements. Activities: Agree remediation plans with high-risk vendors; Draft security and breach notification clauses; Update contracts at renewal points; Record accepted risks with business sign-off. Hands over Risk Treatment Plan and Contract Clause Library. Phase 5, Ongoing Monitoring. We set up continuous monitoring and reassessment cadences so vendor risk stays visible after onboarding. Activities: Enrol critical vendors in security rating monitoring; Set reassessment cadences per tier; Configure alerts for vendor breaches and rating drops; Track remediation commitments to closure. Hands over Monitoring Setup and Reassessment Calendar. Phase 6, Reporting and Governance. We give you reporting that satisfies your own auditors and feeds your wider compliance programme. Activities: Build the vendor risk dashboard for leadership; Map TPRM evidence to ISO 27001 and SOC 2 controls; Set governance forums and review cadence; Prepare audit-ready reporting packs. Hands over TPRM Governance Pack and Reporting Dashboard. Each phase begins from the artefact the phase before it produced.
Phase 01 Vendor Inventory and Tiering
We build a full list of your third parties and tier them by the risk each one carries to your data and operations.
What Happens In This Phase
- Compile the vendor list from procurement and finance
- Identify what data and access each vendor holds
- Define tiering criteria by data sensitivity and criticality
- Assign each vendor to a risk tier
The Handover
Vendor Inventory with Risk Tiering
The next phase starts from this.
Phase 01 Vendor Inventory and Tiering
We build a full list of your third parties and tier them by the risk each one carries to your data and operations.
What Happens In This Phase
- Compile the vendor list from procurement and finance
- Identify what data and access each vendor holds
- Define tiering criteria by data sensitivity and criticality
- Assign each vendor to a risk tier
The Handover
Vendor Inventory with Risk Tiering
The next phase starts from this.
- 01
Vendor Inventory and Tiering
We build a full list of your third parties and tier them by the risk each one carries to your data and operations.
OutputVendor Inventory with Risk TieringActivities
- Compile the vendor list from procurement and finance
- Identify what data and access each vendor holds
- Define tiering criteria by data sensitivity and criticality
- Assign each vendor to a risk tier
- 02
Assessment Framework Design
We design questionnaires and criteria that match each tier, so critical vendors get real scrutiny and low-risk ones stay light.
OutputAssessment Framework and Questionnaire SetActivities
- Build tier-specific questionnaires from SIG and ISO 27036
- Set scoring criteria and pass thresholds
- Define evidence requirements per tier
- Agree escalation rules for failed assessments
- 03
Due Diligence Assessment
We assess your key vendors against their controls, certifications, and evidence, and score the findings.
OutputVendor Due Diligence ReportsActivities
- Issue questionnaires to in-scope vendors
- Review SOC 2 reports and certifications supplied
- Validate answers against supporting evidence
- Score findings and flag unacceptable risks
- 04
Risk Treatment and Contracts
We help you address gaps through remediation, contract clauses, and clear security requirements.
OutputRisk Treatment Plan and Contract Clause LibraryActivities
- Agree remediation plans with high-risk vendors
- Draft security and breach notification clauses
- Update contracts at renewal points
- Record accepted risks with business sign-off
- 05
Ongoing Monitoring
We set up continuous monitoring and reassessment cadences so vendor risk stays visible after onboarding.
OutputMonitoring Setup and Reassessment CalendarActivities
- Enrol critical vendors in security rating monitoring
- Set reassessment cadences per tier
- Configure alerts for vendor breaches and rating drops
- Track remediation commitments to closure
- 06
Reporting and Governance
We give you reporting that satisfies your own auditors and feeds your wider compliance programme.
OutputTPRM Governance Pack and Reporting DashboardActivities
- Build the vendor risk dashboard for leadership
- Map TPRM evidence to ISO 27001 and SOC 2 controls
- Set governance forums and review cadence
- Prepare audit-ready reporting packs
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
Built by SecureRoot
TrustGrid
Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.
Built by SecureRoot
DPDP Compass
Our own privacy platform. Consent, notices, data principal requests and records of processing under the DPDP Act.
What Is Examined, and What it Is Measured Against
Map
Map of the Third Party Risk Assessment (TPRM) scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: OneTrust, ProcessUnity, SecurityScorecard, BitSight, Vanta, UpGuard, Jira, Confluence. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: ISO/IEC 27036, NIST SP 800-161, ISO/IEC 27001:2022 Annex A, SOC 2 Trust Services Criteria, Shared Assessments SIG.
What We Run
8 tools
- OneTrust
- ProcessUnity
- SecurityScorecard
- BitSight
- Vanta
- UpGuard
- Jira
- Confluence
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
5 standards
- ISO/IEC 27036
- NIST SP 800-161
- ISO/IEC 27001:2022 Annex A
- SOC2AICPATrust Services Criteria
- SIGShared Assessments
Deliverables
What You Receive
- Vendor inventory and risk tiering
- Assessment questionnaire set
- Vendor due diligence reports
- Risk treatment and remediation plan
- Ongoing monitoring cadence
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
How do we decide which vendors to assess?
By tiering them, so effort follows risk instead of being spread evenly. Tiering usually considers what data the vendor handles, particularly personal or regulated data, whether they connect into your network or code, how critical they are to services you must keep running, and how hard they would be to replace. A payroll platform holding employee data and a cloud hosting provider running production sit in the top tier and need evidence-based due diligence; an office supplier needs almost none. The register matters as much as the method: most organisations underestimate their vendor count because procurement, engineering and marketing each sign their own tools. We build the inventory first, often from accounts payable and single sign-on records, then agree a tiering model your team can apply consistently. We also record an owner for each vendor inside your business, because assessments stall when no one is accountable for chasing a supplier who does not reply.
Is a security questionnaire enough?
It is a start, not the job. A questionnaire records what a vendor says about itself at one moment, and the answers are often written by a sales team. For vendors in higher tiers, pair it with evidence: a current SOC 2 report or ISO 27001 certificate with its scope statement read carefully, penetration test summaries, and specific answers about where your data is stored, who can access it and how incidents are notified. Then check the contract carries the terms you rely on. For the highest tier, add periodic reassessment and monitoring of external signals. The common failure is a folder of completed questionnaires nobody has reviewed since onboarding, which gives assurance in name only. We also set a reassessment cadence per tier, so the programme has a rhythm rather than an annual scramble, and a vendor whose certificate has lapsed or whose scope never covered your service is caught during the year rather than during your own audit.
What should vendor contracts require?
At minimum: clear purpose and permitted use of your data, confidentiality, security obligations proportionate to the risk, incident and breach notification with a deadline short enough for your own reporting duties, restrictions and approval on subcontracting with equivalent terms flowed down, audit or evidence rights, return or deletion of data at the end of the contract, and cooperation with regulatory or customer audits. Where personal data is involved, the contract needs the processor terms the DPDP Act and, for EU data, Article 28 of the GDPR require, plus transfer mechanisms where data leaves a jurisdiction. Contracts are where third party risk work usually stalls, because renegotiation takes time. We prioritise the vendors where the gap between contract and actual risk is widest. We also keep a simple record of which clauses each vendor actually agreed, because relying on your standard template when the signed agreement says something weaker is a gap that only surfaces during an incident.
How does TPRM support our other compliance work?
It feeds them directly. ISO 27001 expects supplier relationships to be managed and monitored, SOC 2 examines vendor management as part of the common criteria, and PCI DSS requires service provider due diligence and monitoring where card data is involved. Under the DPDP Act, a Data Fiduciary remains accountable for processors acting on its behalf, so the processor register, contracts and oversight are evidence of that accountability. For regulated financial entities, supervisory expectations around outsourced IT and third-party arrangements sit on top. One vendor inventory, one tiering model and one evidence trail can serve every one of those, which is why we build the programme once rather than answering each audit separately. We also keep the register in a form auditors can read directly, with tiering rationale, assessment dates and evidence attached to each vendor, so the same record answers an ISO 27001 auditor, a SOC 2 auditor and a customer questionnaire without being rebuilt each time. That reuse is where most of the saving comes from.
How long does it take to stand up a TPRM programme?
For most organisations, six to twelve weeks to a working programme, following our phases. The vendor inventory and tiering take one to two weeks, designing the assessment framework one to two, the first round of due diligence on the vendors that matter three to six, and risk treatment and contract work two to four, with monitoring and governance running from then on. The pace depends mainly on how quickly vendors respond and how many contracts need changing, neither of which is fully in your control. We usually run the top tier first so the programme produces evidence early, then work down. Ongoing cost is far lower than the initial pass, because later assessments start from what is already recorded. We also hand over the framework and templates so your team can run later rounds without us, which is usually what makes the programme survive its second year.
What does a TPRM engagement cost?
We do not publish a figure, because the work scales with your vendor population. The quote depends on how many vendors you have and how many fall into tiers that need real due diligence, whether personal or regulated data is involved, how many contracts need reviewing or renegotiating, whether you want us to run assessments or to build the framework for your team to run, and whether ongoing monitoring and reporting are included. Tooling, if you choose a third party risk platform, sits outside our fee, and many organisations start well with a structured register and a defined process. We scope after seeing your vendor inventory, then give you a fixed price in writing, phased so the highest-risk vendors are assessed first. We also make clear what you can run internally, since a competent team with a good framework can handle most lower-tier assessments and reserve outside help for the vendors that carry real risk.
Keep Moving Through Compliance
Service 13 of 13 in this practice area
Practice Area
More in Compliance
- ISO 27001Build and certify your information security management system.
- ISO 27701Build a certifiable privacy information management system.
- ISO 22301Certify how your business keeps running through disruption.
- ISO 42001Govern your AI systems with the first AI management standard.
- DPDP ActGet ready for India's Digital Personal Data Protection Act.
- PCI DSSProtect cardholder data and pass your PCI assessment.
- HIPAAProtect health information and meet HIPAA requirements.
- SOC 2Earn a SOC 2 report your customers can trust.
- CCPAMeet California's consumer privacy requirements.
- GDPRMeet Europe's data protection standard with confidence.
- NEN 7510Certify information security for Dutch healthcare.
- EU AI ActPrepare for Europe's risk-based AI regulation.