Open working templates
Third-party risk: start from a defensible draft.
6 templates for workshops, registers, audits and reviews. No forms, straight to the file.
- 01Download
Vendor inventory & tiering
CSVFile in GermanConnect service, dependency, data, access, substitutability, fourth parties and criticality.
Typical owner: TPRM & Vendor Owner · Based on: ISO, KaitoSec
- 02Download
Security due diligence
CSVFile in GermanRisk-based core questions on governance, access, operations, development, incidents, BCM and the supply chain.
Typical owner: Information Security · Based on: UP KRITIS / BSI, ISO, KaitoSec
- 03Download
Evidence requirements list
CSVFile in GermanManage required evidence with scope, validity, assessment result, owner and expiry date.
Typical owner: Assurance · Based on: ISO, KaitoSec
- 04Download
Third-party risk register
CSVFile in GermanDocument scenario, impact, control gap, treatment, residual risk and approval per relationship.
Typical owner: Risk Owner · Based on: EU, ISO, KaitoSec
- 05Download
Annual review & monitoring
CSVFile in GermanBundle evidence, SLAs, incidents, changes, measures and new risk signals into one decision.
Typical owner: Vendor Owner · Based on: ISO, KaitoSec
- 06Download
Exit and offboarding plan
MDFile in GermanPrepare triggers, substitution, data return, access termination, deletion, knowledge transfer and closure.
Typical owner: Service & Vendor Owner · Based on: ISO, BSI, KaitoSec