Skip to content

Fundamentals

Third-party risk management: what a TPRM actually governs

TPRM connects procurement, information security, privacy, BCM and business ownership across the entire vendor lifecycle.

Back to Third-party risk

8 minute read · Content as of 21.07.2026

The contract is only one control point

Risks arise before selection, during service delivery and at the end of the relationship. A TPRM therefore defines which providers are recorded, how criticality is determined and which assessments, requirements and reviews follow from it.

NIS2 explicitly names supply chain security, including security-related aspects between entities and their direct suppliers or service providers, as part of risk management.

Ownership stays within your own organisation

The business unit and vendor owner are accountable for value and performance. Security, privacy, BCM and procurement supply criteria and assessments. A central TPRM orchestrates decisions but does not take on every risk itself.

  • a shared vendor and service inventory
  • risk-based criticality classes
  • verifiable assessment and approval decisions
  • monitoring, incident handling and exit

Sources used

Back to Third-party risk