Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

GLOSSARY · Third parties

Third-Party Risk Management (TPRM)

Third-Party Risk Management (TPRM) is the program by which an organization identifies the suppliers, service providers and partners it depends on, tiers them by the criticality of what they touch, assesses their security posture in proportion to that tier, monitors them between assessments, and drives the remediation of the gaps found, jointly with the third party. Its output is a defensible answer to a question every regulator now asks: what do you know about the security of the companies your operations run through?

Tier first, then assess in proportion

A program that sends the same 300-question form to every vendor collects a mailbox of PDFs and learns little. TPRM starts with an inventory and a tiering: what data, access and business activity does the supplier touch, and what would its failure interrupt? A critical tier gets a contextual assessment, evidence and a remediation plan; a low tier gets a short attestation and external monitoring. Proportion is what makes the program sustainable at hundreds of suppliers.

Between two assessments

An assessment describes a supplier on the day it answered. Monitoring covers the rest: external security ratings and attack-surface signals, breach news, a certificate that expires, a SOC 2 period that lapses. A degraded signal should re-open the supplier’s risk, not wait for next year’s questionnaire. This is where a composite grade that blends the assessment, the business impact of the service and the external signals earns its place, provided its computation is visible.

What NIS2 and DORA require

NIS2 lists supply-chain security among the mandatory risk-management measures, including the security practices of direct suppliers and service providers. DORA devotes a full chapter to ICT third-party risk: a strategy, a register of information on every contractual arrangement, pre-contracting due diligence, mandatory contract clauses, exit strategies for critical services, and an EU oversight regime for critical ICT providers. TPRM is the program those obligations describe.

ON MINDLAPSE

Where this term lives in the platform.

The pages that put the definition to work.

SEE IT VERIFIED

Definitions are the easy part. Proving them is the product.

Thirty minutes on your scope: risk, compliance, third parties, and how each term above becomes a verified control.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.