Glossary

TPRM (Third Party Risk Management)

TPRM (Third Party Risk Management) is the discipline of identifying, assessing, treating and monitoring the risks an organisation carries because of its relationships with external suppliers, service providers and partners — chiefly cybersecurity, continuity, compliance and data protection risks.

What TPRM covers, and what it does not

TPRM addresses the risk carried by the organisation because of a third party, not that third party's commercial performance. A vendor can deliver flawlessly and still be a major risk: sensitive data hosted outside the EU, no recovery plan, dependency on a single subcontractor. Conversely, price negotiation, operational SLA tracking and the procurement relationship belong to vendor management, which shares the supplier repository with TPRM but not its objectives.

The scope covers four risk families: cybersecurity (the third party as an attack path), continuity (the third party as a point of failure), compliance (the third party as an extension of the regulated perimeter) and data protection (the third party as a processor under GDPR).

Why TPRM became a regulatory obligation

Until recently TPRM was good practice. Three European texts made it binding: NIS2 imposes supply chain security on essential and important entities, DORA governs the use of ICT providers in the financial sector, and ISO 27001 dedicates a set of controls to supplier relationships. GDPR separately requires a contractual framework for any processor handling personal data.

In practice, a TPRM programme must now be documented and demonstrable, not merely effective: third-party inventory, criticality criteria, evidence of assessment, traceable decisions.

Ready to take control of your third-party risk?

I'm a company

We'll get back to you within 24 hours

I'm a vendor

Immediate onboarding

Create a free account