What third-party risk management actually is
TPRM is a light discipline of knowing who you rely on, what could go wrong and holding the evidence that shows you've thought about it. For most growing teams, it's five documents per critical vendor, refreshed annually, tiered by risk, with a live record you can hand to a client or auditor on demand.
Tiering vendors so effort matches risk
The single most valuable move in TPRM is tiering. Not every vendor deserves the same scrutiny, a stationery supplier and a data processor are not the same.
| Tier | Typical vendor | Evidence depth |
|---|---|---|
| Tier 1, critical | Hosts data, runs core systems, on client-facing sites | Full pack, annual review, contingency plan |
| Tier 2, important | Handles PII, financial services, sole-source | Standard pack, annual review |
| Tier 3, standard | Regular suppliers, low sensitivity | Insurance + identity, refreshed annually |
| Tier 4, minimal | Ad-hoc, low-value, easily replaceable | Identity + invoice details only |
The core TPRM pack
- Legal identity, company registration, beneficial owners, UBO.
- Financial health, accounts, credit report, bank verification.
- Insurance, public liability, PI, employers', cyber where relevant.
- Security, ISO 27001, SOC 2, Cyber Essentials, penetration test summary.
- Data protection, DPA, sub-processor list, breach notification terms.
- Continuity, a paragraph on how they'd recover from a serious incident.
Continuous monitoring, the modern part
Legacy TPRM was one big questionnaire once a year. Modern TPRM watches for changes as they happen, expiring insurance, changing accreditations, new sub-processors, adverse media. Most of this is achievable with expiry tracking and a couple of light integrations.
When something goes wrong
The measure of a TPRM programme isn't how many boxes were ticked, it's how quickly you can answer a client's question after an incident. A live vendor record with a documented tier, live evidence and a named owner gets you to an answer in minutes.
The pragmatic maturity ladder
Stage 1: know who your top-30 vendors are. Stage 2: have five documents on file for each. Stage 3: expiries are tracked automatically. Stage 4: vendors are tiered and reviewed on a cadence. Stage 5: you can produce a client-ready evidence pack in a click. Most teams are between 1 and 2. Credbase makes the jump to 5 straightforward.
Frequently asked questions
Put this into practice today.
Start a free Credbase workspace, add your first supplier and share a live evidence pack in ten minutes.