Fundamentals
Third-party risk management: what a TPRM actually governs
TPRM connects procurement, information security, privacy, BCM and business ownership across the entire vendor lifecycle.
8 minute read · Content as of 21.07.2026
The contract is only one control point
Risks arise before selection, during service delivery and at the end of the relationship. A TPRM therefore defines which providers are recorded, how criticality is determined and which assessments, requirements and reviews follow from it.
NIS2 explicitly names supply chain security, including security-related aspects between entities and their direct suppliers or service providers, as part of risk management.
Ownership stays within your own organisation
The business unit and vendor owner are accountable for value and performance. Security, privacy, BCM and procurement supply criteria and assessments. A central TPRM orchestrates decisions but does not take on every risk itself.
- a shared vendor and service inventory
- risk-based criticality classes
- verifiable assessment and approval decisions
- monitoring, incident handling and exit
Sources used
- Directive (EU) 2022/2555 – NIS2 · EU · 2022
- ISO/IEC 27036-1:2021 – Supplier relationships · ISO · 2021
- Bhatti, Mubarak & Nagalingam: Information Security Risk Management in IT Outsourcing – A Quarter-century Systematic Literature Review · Academia
- Vendor, due diligence and exit patterns · KaitoSec