Third-party risk · Making supply chains visible
Your risk does not end at the contract.
This hub makes cyber, privacy and continuity risks from IT service providers manageable – from criticality to a tested exit.
- Articles
- 8
- Check questions
- 20
- Templates
- 6
- Chapters
- 7
Start from the work product
Read no more than the next step needs.
01
Assess your starting point
20 questions cover governance, inventory, criticality, due diligence, contracts, monitoring, incidents, subcontractors and exit. Everything stays local.
02
Structure the implementation
7 chapters connect decisions to concrete outcomes.
03
Start from a template
6 open working aids for workshops, registers and reviews.
Source-based orientation
Articles
- 01FundamentalsThird-party risk management: what a TPRM actually governsTPRM connects procurement, information security, privacy, BCM and business ownership across the entire vendor lifecycle.8 min
- 02InventoryVendor inventory and criticality: the service first, then the nameOne provider can deliver several services with completely different risk. The specific relationship is therefore classified, not just the company.8 min
- 03Due diligenceVendor due diligence: asking questions, assessing evidenceA completed questionnaire is a claim. Only matching evidence, scope and recency turn it into a reliable assessment.9 min
- 04RequirementsAgreeing concrete security requirements with vendorsControl objectives only become manageable when scope, deadline, evidence, reporting path and the consequences of a deviation fit the specific service.9 min
- 05MonitoringContinuous monitoring: spotting changes before the annual review beginsContinuous monitoring combines contractual information, performance data, security events, evidence and internal changes.8 min
- 06IncidentsVendor incidents: settling reporting paths and decisions before the incidentIf a provider only starts looking for the right contact after hours have passed, the contractual reporting obligation is operationally worthless.8 min
- 07Supply chainMaking fourth parties and concentration risks visibleMany seemingly independent providers depend on the same cloud, identity, network or software services.8 min
- 08ExitVendor exit: bringing back data, access and operational capability in a controlled wayAn exit does not begin with the termination notice. Critical relationships need return, migration and transition scenarios defined early.9 min
How it connects
The vendor risk chain
Third-party risk management is a lifecycle: select, tier, assess, agree, monitor and end in a controlled way. Each phase produces its own decisions and evidence.
- GOV
- GovernanceGovern
- Policy, roles, risk criteria and approvals set the uniform framework for all relationships.
- INV
- Inventory & tieringPrioritise
- Services, data, access, criticality and dependencies determine the required depth of assessment.
- DUE
- Due diligenceAssess
- Risk-based questions and service-specific evidence make control gaps decidable.
- REQ
- RequirementsAgree
- Contracts and operating agreements translate control objectives into verifiable obligations.
- MON
- Monitoring & incidentMonitor
- Changes, evidence, performance and incidents keep the risk view current over the term.
- EXT
- Fourth party & exitControl
- Subcontractors, concentration, substitutability and offboarding close the risk chain.
From knowledge into operation
Do not lose the results in yet another file.
KaitoSec connects requirements, owners, risks, controls and evidence in one working model.
Written independently on the basis of NIS2, BSI and UP KRITIS publications, ISO/IEC 27036 and our own practice patterns. Not legal or contractual advice.
Content as of: 21.07.2026