Full definition
Third-party risk management (TPRM) is defined as: Third-party risk management (TPRM) is the ongoing process of identifying, assessing and monitoring the risks that suppliers, vendors, contractors and other external parties bring to your organisation.
Third-party risk management (TPRM) is the ongoing discipline of understanding what could go wrong when another company acts on your behalf, and putting controls in place to reduce that risk. It covers financial, operational, security, privacy, regulatory and reputational risk from every external party you rely on.
In practice TPRM is a lifecycle: due diligence before contract, evidence collection at onboarding, monitoring during the engagement and formal offboarding when the relationship ends. Documents such as insurance certificates, security certifications and policy statements are the artefacts that prove each stage.
A mature TPRM programme is risk-based, meaning the depth of review scales with the criticality of the supplier. A cleaning contractor and a data-hosting vendor are both third parties, but they should not carry the same evidence burden.
Also known as
TPRM