Third-Party Risk Assessment (TPRM)
Assesses risk introduced by suppliers, outsourced providers, technology partners, and critical service providers.
Scope
Reviews vendor security, data access, cloud and SaaS exposure, contractual controls, compliance posture, continuity capability, SLAs, and incident notification obligations.
The gaps it finds
Critical vendor dependency risk, weak contracts, poor supplier assurance, data exposure, missing SLAs, vendor continuity gaps, and weak ongoing monitoring.
Value to the board
Reduces hidden dependency risk and improves oversight of vendors that can affect operations, data, compliance, or reputation.
Framework alignment
- ISO 27036
- ISO 31000
- Supplier risk management practices
Reporting
Like every assessment in the portfolio, this engagement ends with the full deliverable set, from executive summary and maturity scorecard to remediation roadmap and board dashboard. The methodology page describes each deliverable.
Scope this assessment
A scoping conversation confirms objectives, stakeholders, systems, and the document request list before any work begins.