Company Partners Our Teams Contact Blog
Services
Industries
Talk to an expert

What is third-party risk (TPRM)?

DefinitionThird-party risk is the exposure that suppliers, service providers and partners bring to an organization through their access to its data, systems or processes. TPRM (Third-Party Risk Management) is the discipline that identifies, assesses and monitors that risk throughout the relationship.

Why it matters

Outsourcing a service transfers the execution, not the responsibility. A cloud provider, a software vendor or a contractor with remote access can be the entry point for an attack or the source of a leak, and the consequences fall on the contracting company before customers and regulators. Risk also flows down the chain: your suppliers have suppliers, the so-called fourth parties.

How the TPRM lifecycle works

  • Tiering: not every supplier deserves the same rigor. Criticality depends on the data and systems it accesses and the impact if the service stops.
  • Pre-contract assessment: questionnaires, evidence review and, for critical suppliers, deeper verification.
  • Contract: security clauses, incident notification, right to audit, subcontracting and exit terms.
  • Continuous monitoring: periodic reassessments, tracking of incidents and of the supplier's external exposure.
  • Offboarding: access revocation and return or deletion of data.

What evidence to request

An ISO/IEC 27001 certificate shows that an audited security management system exists, provided its scope covers the contracted service. A SOC 2 Type II report shows that specific controls operated over a period. External cyber risk ratings help see the supplier's exposure from the outside, but they do not replace the assessment. In Brazil, the LGPD and, in the financial sector, National Monetary Council rules reinforce the need to control suppliers, and NIST CSF 2.0 placed supply chain risk management within the Govern function.

Network Secure helps structure third-party risk management programs as part of its GRC services.

Frequently asked questions

What is the difference between third-party risk and supply chain risk?

Third-party risk focuses on suppliers and partners the company deals with directly. Supply chain risk widens the view to the whole chain, including suppliers' suppliers and software components.

Is a supplier's ISO 27001 certification enough?

Not on its own. You need to check that the certificate's scope covers the contracted service and complement it with contract clauses and continuous monitoring.

Go deeper