Skip to content

Browser-local readiness check

How resilient is your third-party risk management?

20 questions cover governance, inventory, criticality, due diligence, contracts, monitoring, incidents, subcontractors and exit. Everything stays local.

Back to Third-party risk

  1. 01

    Governance

    Has top management defined TPRM objectives, scope and risk criteria?

    Expected evidence: TPRM policy or governance resolution

  2. 02

    Governance

    Are the responsibilities of business units, vendor owners, procurement, security, privacy and BCM clarified?

    Expected evidence: RACI or role matrix

  3. 03

    Governance

    Are there binding checkpoints before engagement and before substantial changes?

    Expected evidence: Sourcing and change gates

  4. 04

    Governance

    Are accepted residual risks documented with owner, duration and review?

    Expected evidence: Risk acceptances

  5. 05

    Inventory & tiering

    Does a complete inventory of external services with an internal owner exist?

    Expected evidence: Vendor and service inventory

  6. 06

    Inventory & tiering

    Are relationships classified rather than just vendor names?

    Expected evidence: Criticality per service relationship

  7. 07

    Inventory & tiering

    Does the classification consider data, access, time criticality and substitutability?

    Expected evidence: Tiering criteria and result

  8. 08

    Inventory & tiering

    Are relevant subcontractors, regions and concentrations visible?

    Expected evidence: Fourth-party and concentration overview

  9. 09

    Due diligence & contract

    Does due diligence follow criticality and concrete risk scenarios?

    Expected evidence: Risk-based assessment catalogue

  10. 10

    Due diligence & contract

    Are answers validated by service-specific, current evidence?

    Expected evidence: Evidence assessment

  11. 11

    Due diligence & contract

    Are findings treated, accepted or time-boxed before approval?

    Expected evidence: Approval decision and measures

  12. 12

    Due diligence & contract

    Do agreements contain verifiable security, reporting, BCM, audit and exit requirements?

    Expected evidence: Contractual requirements

  13. 13

    Monitoring & incidents

    Are evidence, SLAs, incidents, changes and measures monitored continuously?

    Expected evidence: Monitoring plan or dashboard

  14. 14

    Monitoring & incidents

    Do defined changes trigger an unscheduled reassessment?

    Expected evidence: Review triggers and cases

  15. 15

    Monitoring & incidents

    Are operational 24/7 reporting paths tested with critical providers?

    Expected evidence: Alerting test

  16. 16

    Monitoring & incidents

    Are vendor incidents carried over into your own reporting, risk and BCM processes?

    Expected evidence: Incident interfaces and case records

  17. 17

    Supply chain & exit

    Must critical subcontractors be notified, assessed or approved?

    Expected evidence: Fourth-party rules

  18. 18

    Supply chain & exit

    Are concentration risks evaluated across several relationships?

    Expected evidence: Portfolio analysis

  19. 19

    Supply chain & exit

    Do realistic orderly and unplanned exit scenarios exist for critical services?

    Expected evidence: Exit plan and substitution options

  20. 20

    Supply chain & exit

    Are data, access, keys, deletion and remaining obligations evidenced during offboarding?

    Expected evidence: Closure and deletion record