Browser-local readiness check
How resilient is your third-party risk management?
20 questions cover governance, inventory, criticality, due diligence, contracts, monitoring, incidents, subcontractors and exit. Everything stays local.
- 01
Governance
Has top management defined TPRM objectives, scope and risk criteria?
Expected evidence: TPRM policy or governance resolution
- 02
Governance
Are the responsibilities of business units, vendor owners, procurement, security, privacy and BCM clarified?
Expected evidence: RACI or role matrix
- 03
Governance
Are there binding checkpoints before engagement and before substantial changes?
Expected evidence: Sourcing and change gates
- 04
Governance
Are accepted residual risks documented with owner, duration and review?
Expected evidence: Risk acceptances
- 05
Inventory & tiering
Does a complete inventory of external services with an internal owner exist?
Expected evidence: Vendor and service inventory
- 06
Inventory & tiering
Are relationships classified rather than just vendor names?
Expected evidence: Criticality per service relationship
- 07
Inventory & tiering
Does the classification consider data, access, time criticality and substitutability?
Expected evidence: Tiering criteria and result
- 08
Inventory & tiering
Are relevant subcontractors, regions and concentrations visible?
Expected evidence: Fourth-party and concentration overview
- 09
Due diligence & contract
Does due diligence follow criticality and concrete risk scenarios?
Expected evidence: Risk-based assessment catalogue
- 10
Due diligence & contract
Are answers validated by service-specific, current evidence?
Expected evidence: Evidence assessment
- 11
Due diligence & contract
Are findings treated, accepted or time-boxed before approval?
Expected evidence: Approval decision and measures
- 12
Due diligence & contract
Do agreements contain verifiable security, reporting, BCM, audit and exit requirements?
Expected evidence: Contractual requirements
- 13
Monitoring & incidents
Are evidence, SLAs, incidents, changes and measures monitored continuously?
Expected evidence: Monitoring plan or dashboard
- 14
Monitoring & incidents
Do defined changes trigger an unscheduled reassessment?
Expected evidence: Review triggers and cases
- 15
Monitoring & incidents
Are operational 24/7 reporting paths tested with critical providers?
Expected evidence: Alerting test
- 16
Monitoring & incidents
Are vendor incidents carried over into your own reporting, risk and BCM processes?
Expected evidence: Incident interfaces and case records
- 17
Supply chain & exit
Must critical subcontractors be notified, assessed or approved?
Expected evidence: Fourth-party rules
- 18
Supply chain & exit
Are concentration risks evaluated across several relationships?
Expected evidence: Portfolio analysis
- 19
Supply chain & exit
Do realistic orderly and unplanned exit scenarios exist for critical services?
Expected evidence: Exit plan and substitution options
- 20
Supply chain & exit
Are data, access, keys, deletion and remaining obligations evidenced during offboarding?
Expected evidence: Closure and deletion record