Skip to content

Third-party risk · Making supply chains visible

Your risk does not end at the contract.

This hub makes cyber, privacy and continuity risks from IT service providers manageable – from criticality to a tested exit.

Articles
8
Check questions
20
Templates
6
Chapters
7

Source-based orientation

Articles

  1. 01FundamentalsThird-party risk management: what a TPRM actually governsTPRM connects procurement, information security, privacy, BCM and business ownership across the entire vendor lifecycle.8 min
  2. 02InventoryVendor inventory and criticality: the service first, then the nameOne provider can deliver several services with completely different risk. The specific relationship is therefore classified, not just the company.8 min
  3. 03Due diligenceVendor due diligence: asking questions, assessing evidenceA completed questionnaire is a claim. Only matching evidence, scope and recency turn it into a reliable assessment.9 min
  4. 04RequirementsAgreeing concrete security requirements with vendorsControl objectives only become manageable when scope, deadline, evidence, reporting path and the consequences of a deviation fit the specific service.9 min
  5. 05MonitoringContinuous monitoring: spotting changes before the annual review beginsContinuous monitoring combines contractual information, performance data, security events, evidence and internal changes.8 min
  6. 06IncidentsVendor incidents: settling reporting paths and decisions before the incidentIf a provider only starts looking for the right contact after hours have passed, the contractual reporting obligation is operationally worthless.8 min
  7. 07Supply chainMaking fourth parties and concentration risks visibleMany seemingly independent providers depend on the same cloud, identity, network or software services.8 min
  8. 08ExitVendor exit: bringing back data, access and operational capability in a controlled wayAn exit does not begin with the termination notice. Critical relationships need return, migration and transition scenarios defined early.9 min

How it connects

The vendor risk chain

Third-party risk management is a lifecycle: select, tier, assess, agree, monitor and end in a controlled way. Each phase produces its own decisions and evidence.

GOV
GovernanceGovern
Policy, roles, risk criteria and approvals set the uniform framework for all relationships.
INV
Inventory & tieringPrioritise
Services, data, access, criticality and dependencies determine the required depth of assessment.
DUE
Due diligenceAssess
Risk-based questions and service-specific evidence make control gaps decidable.
REQ
RequirementsAgree
Contracts and operating agreements translate control objectives into verifiable obligations.
MON
Monitoring & incidentMonitor
Changes, evidence, performance and incidents keep the risk view current over the term.
EXT
Fourth party & exitControl
Subcontractors, concentration, substitutability and offboarding close the risk chain.

From knowledge into operation

Do not lose the results in yet another file.

KaitoSec connects requirements, owners, risks, controls and evidence in one working model.

Written independently on the basis of NIS2, BSI and UP KRITIS publications, ISO/IEC 27036 and our own practice patterns. Not legal or contractual advice.

Content as of: 21.07.2026