Implementation as work products
The TPRM implementation path
7 chapters put decisions, responsibilities and evidence in a defensible order.
- 01
Framework
Set governance and risk criteria
Define scope, roles, risk ownership and binding decision paths.
Expected work products
- TPRM policy
- Role matrix
- Risk and approval criteria
Based on: EU, ISO
- 02
Visibility
Build the service inventory
Record external services, internal owners, data, access and dependencies completely.
Expected work products
- Vendor inventory
- Service relationships
- Data and access mapping
Based on: ISO
- 03
Prioritise
Apply criticality and tiering
Derive assessment depth and control cadence from the specific relationship risk.
Expected work products
- Tiering model
- Criticality classes
- Fourth-party and concentration view
Based on: EU, BSI
- 04
Assess
Due diligence and approval
Connect questions, evidence, findings and residual risk in one traceable decision.
Expected work products
- Due diligence result
- Evidence package
- Risk and approval decision
Based on: UP KRITIS / BSI, ISO
- 05
Agree
Requirements and onboarding
Agree security, incidents, BCM, subcontractors, audit and exit in operational terms.
Expected work products
- Requirements catalogue
- Control and reporting paths
- Onboarding approval
Based on: UP KRITIS / BSI, ISO
- 06
Monitor
Run monitoring and incident handling
Manage changes, evidence, performance, risks and incidents over the term of the relationship.
Expected work products
- Monitoring plan
- Review triggers
- Incident and escalation procedures
Based on: EU, ISO
- 07
End
Test the exit and improve the portfolio
Replace critical dependencies in a controlled way and use the lessons across the portfolio.
Expected work products
- Exit and offboarding plans
- Exit tests
- Portfolio and management review
Based on: ISO, BSI