Skip to content

Implementation as work products

The TPRM implementation path

7 chapters put decisions, responsibilities and evidence in a defensible order.

Back to Third-party risk

  1. 01

    Framework

    Set governance and risk criteria

    Define scope, roles, risk ownership and binding decision paths.

    Expected work products

    • TPRM policy
    • Role matrix
    • Risk and approval criteria

    Based on: EU, ISO

  2. 02

    Visibility

    Build the service inventory

    Record external services, internal owners, data, access and dependencies completely.

    Expected work products

    • Vendor inventory
    • Service relationships
    • Data and access mapping

    Based on: ISO

  3. 03

    Prioritise

    Apply criticality and tiering

    Derive assessment depth and control cadence from the specific relationship risk.

    Expected work products

    • Tiering model
    • Criticality classes
    • Fourth-party and concentration view

    Based on: EU, BSI

  4. 04

    Assess

    Due diligence and approval

    Connect questions, evidence, findings and residual risk in one traceable decision.

    Expected work products

    • Due diligence result
    • Evidence package
    • Risk and approval decision

    Based on: UP KRITIS / BSI, ISO

  5. 05

    Agree

    Requirements and onboarding

    Agree security, incidents, BCM, subcontractors, audit and exit in operational terms.

    Expected work products

    • Requirements catalogue
    • Control and reporting paths
    • Onboarding approval

    Based on: UP KRITIS / BSI, ISO

  6. 06

    Monitor

    Run monitoring and incident handling

    Manage changes, evidence, performance, risks and incidents over the term of the relationship.

    Expected work products

    • Monitoring plan
    • Review triggers
    • Incident and escalation procedures

    Based on: EU, ISO

  7. 07

    End

    Test the exit and improve the portfolio

    Replace critical dependencies in a controlled way and use the lessons across the portfolio.

    Expected work products

    • Exit and offboarding plans
    • Exit tests
    • Portfolio and management review

    Based on: ISO, BSI