Featured guide

Third-party risk management for growing teams

Third-party risk management (TPRM) sounds like enterprise jargon, but the core idea is simple: every vendor, supplier and partner you rely on introduces some risk and the right amount of paperwork keeps that risk visible and manageable. This guide is the pragmatic version, proportional, positive and doable in a week.

12 min read Updated 1 July 2026

What third-party risk management actually is

TPRM is a light discipline of knowing who you rely on, what could go wrong and holding the evidence that shows you've thought about it. For most growing teams, it's five documents per critical vendor, refreshed annually, tiered by risk, with a live record you can hand to a client or auditor on demand.

Tiering vendors so effort matches risk

The single most valuable move in TPRM is tiering. Not every vendor deserves the same scrutiny, a stationery supplier and a data processor are not the same.

TierTypical vendorEvidence depth
Tier 1, criticalHosts data, runs core systems, on client-facing sitesFull pack, annual review, contingency plan
Tier 2, importantHandles PII, financial services, sole-sourceStandard pack, annual review
Tier 3, standardRegular suppliers, low sensitivityInsurance + identity, refreshed annually
Tier 4, minimalAd-hoc, low-value, easily replaceableIdentity + invoice details only

The core TPRM pack

  1. Legal identity, company registration, beneficial owners, UBO.
  2. Financial health, accounts, credit report, bank verification.
  3. Insurance, public liability, PI, employers', cyber where relevant.
  4. Security, ISO 27001, SOC 2, Cyber Essentials, penetration test summary.
  5. Data protection, DPA, sub-processor list, breach notification terms.
  6. Continuity, a paragraph on how they'd recover from a serious incident.

Continuous monitoring, the modern part

Legacy TPRM was one big questionnaire once a year. Modern TPRM watches for changes as they happen, expiring insurance, changing accreditations, new sub-processors, adverse media. Most of this is achievable with expiry tracking and a couple of light integrations.

When something goes wrong

The measure of a TPRM programme isn't how many boxes were ticked, it's how quickly you can answer a client's question after an incident. A live vendor record with a documented tier, live evidence and a named owner gets you to an answer in minutes.

The pragmatic maturity ladder

Stage 1: know who your top-30 vendors are. Stage 2: have five documents on file for each. Stage 3: expiries are tracked automatically. Stage 4: vendors are tiered and reviewed on a cadence. Stage 5: you can produce a client-ready evidence pack in a click. Most teams are between 1 and 2. Credbase makes the jump to 5 straightforward.

Frequently asked questions

Put this into practice today.

Start a free Credbase workspace, add your first supplier and share a live evidence pack in ten minutes.