Skip to content

Open working templates

Third-party risk: start from a defensible draft.

6 templates for workshops, registers, audits and reviews. No forms, straight to the file.

Back to Third-party risk

  1. 01

    Vendor inventory & tiering

    CSVFile in German

    Connect service, dependency, data, access, substitutability, fourth parties and criticality.

    Typical owner: TPRM & Vendor Owner · Based on: ISO, KaitoSec

    Download
  2. 02

    Security due diligence

    CSVFile in German

    Risk-based core questions on governance, access, operations, development, incidents, BCM and the supply chain.

    Typical owner: Information Security · Based on: UP KRITIS / BSI, ISO, KaitoSec

    Download
  3. 03

    Evidence requirements list

    CSVFile in German

    Manage required evidence with scope, validity, assessment result, owner and expiry date.

    Typical owner: Assurance · Based on: ISO, KaitoSec

    Download
  4. 04

    Third-party risk register

    CSVFile in German

    Document scenario, impact, control gap, treatment, residual risk and approval per relationship.

    Typical owner: Risk Owner · Based on: EU, ISO, KaitoSec

    Download
  5. 05

    Annual review & monitoring

    CSVFile in German

    Bundle evidence, SLAs, incidents, changes, measures and new risk signals into one decision.

    Typical owner: Vendor Owner · Based on: ISO, KaitoSec

    Download
  6. 06

    Exit and offboarding plan

    MDFile in German

    Prepare triggers, substitution, data return, access termination, deletion, knowledge transfer and closure.

    Typical owner: Service & Vendor Owner · Based on: ISO, BSI, KaitoSec

    Download