[{"data":1,"prerenderedAt":218},["ShallowReactive",2],{"section-links-solutions-en":3,"section-links-reglementation-en":36,"section-links-guides-en":65,"section-links-comparatifs-en":90,"glossary-en-tprm":103,"glossary-see-also-en-tprm":209},[4,8,12,16,20,24,28,32],{"label":5,"to":6,"description":7},"DORA + ISO 27001","\u002Fen\u002Fsolutions\u002Fdora-iso27001-compliance-software","Run DORA and ISO 27001 in one platform: CTPP register, SoA, Annex A controls and unified audit exports.",{"label":9,"to":10,"description":11},"NIS2 vendors","\u002Fen\u002Fsolutions\u002Fnis2-vendor-compliance","Extend your NIS2 compliance to your vendor chain: assessment campaigns, supply chain mapping and regulator-ready exports.",{"label":13,"to":14,"description":15},"Supply chain","\u002Fen\u002Fsolutions\u002Fsupply-chain-cybersecurity","Map your supply chain, assess your vendors' cybersecurity and track remediation through to risk closure.",{"label":17,"to":18,"description":19},"Third-party GRC","\u002Fen\u002Fsolutions\u002Fthird-party-grc-platform","CISAPP brings governance, risk and compliance (GRC) together for your third-party ecosystem: regulatory frameworks, audits and risk register.",{"label":21,"to":22,"description":23},"TPRM SaaS","\u002Fen\u002Fsolutions\u002Ftprm-saas","CISAPP is a TPRM SaaS platform unifying assessment campaigns, scoring, dependency mapping and regulatory compliance.",{"label":25,"to":26,"description":27},"Vendor risk","\u002Fen\u002Fsolutions\u002Fvendor-risk-management","Map, assess and steer your vendor risk with campaigns, a security score and a centralised risk register.",{"label":29,"to":30,"description":31},"Questionnaires","\u002Fen\u002Fsolutions\u002Fvendor-security-questionnaire","Run preconfigured vendor security questionnaire campaigns (ISO 27001, NIS2, DORA, GDPR) and track responses in real time.",{"label":33,"to":34,"description":35},"SecOps score","\u002Fen\u002Fsolutions\u002Fvendor-security-score","Track a vendor security score computed automatically from external technical scans (DNS, TLS, exposure, headers, breach), with history and alerts.",[37,41,45,49,53,57,61],{"label":38,"to":39,"description":40},"AI Act","\u002Fen\u002Fregulations\u002Fai-act","Prepare your EU AI Act compliance: AI system register, FRIA and article-level mapping, connected to your risk management.",{"label":42,"to":43,"description":44},"DORA","\u002Fen\u002Fregulations\u002Fdora","Manage your critical third-party ICT provider (CTPP) register, TLPT testing, and ICT incidents in an audit-ready DORA framework.",{"label":46,"to":47,"description":48},"GDPR","\u002Fen\u002Fregulations\u002Fgdpr","Maintain your records of processing activities and DPIAs, and manage data breaches with a severity wizard and a 72-hour notification tracker.",{"label":50,"to":51,"description":52},"ISO 27001","\u002Fen\u002Fregulations\u002Fiso-27001","Manage your Statement of Applicability (SoA), Annex A controls and ISO 27001 audit evidence in a single platform.",{"label":54,"to":55,"description":56},"NIS2","\u002Fen\u002Fregulations\u002Fnis2","Manage your NIS2 obligations (Article 21 measures, significant incidents, supply chain) and prepare regulator-ready exports from one platform.",{"label":58,"to":59,"description":60},"Part-IS","\u002Fen\u002Fregulations\u002Fpart-is","EASA Part-IS compliance (Regulations (EU) 2023\u002F203 and 2022\u002F1645): aviation ISMS, PSOE levels, Present & Suitable self-assessment, evidence and audit questionnaire.",{"label":62,"to":63,"description":64},"TISAX","\u002Fen\u002Fregulations\u002Ftisax","Understand TISAX assessment levels (AL1 to AL3), the VDA ISA catalogue, label validity, and what an automotive supplier must prove to its customers.",[66,70,74,78,82,86],{"label":67,"to":68,"description":69},"Fourth-party risk","\u002Fen\u002Fresources\u002Ffourth-party-risk","Your vendors depend on subcontractors you've never assessed. How to identify and manage this often-invisible fourth-party risk.",{"label":71,"to":72,"description":73},"Questionnaire fatigue","\u002Fen\u002Fresources\u002Fsecurity-questionnaire-fatigue","Why security questionnaires overwhelm procurement, security teams, and vendors alike, and how to break the re-entry cycle without losing rigor.",{"label":75,"to":76,"description":77},"Supply chain attack","\u002Fen\u002Fresources\u002Fsupply-chain-cyberattack","How a cyberattack at a vendor spreads into your organization, why it's hard to anticipate, and how to structure your defense against it.",{"label":79,"to":80,"description":81},"Concentration & SPOF","\u002Fen\u002Fresources\u002Fvendor-concentration-risk-spof","How to identify single points of failure (SPOF) hidden in your vendor chain and map risk concentration before an incident reveals it for you.",{"label":83,"to":84,"description":85},"Due diligence","\u002Fen\u002Fresources\u002Fvendor-cyber-due-diligence","How to structure cyber due diligence before signing a vendor contract, what to ask, and how to avoid inheriting a third party's risk unknowingly.",{"label":87,"to":88,"description":89},"Incident playbook","\u002Fen\u002Fresources\u002Fvendor-security-incident-playbook","What to do in the first hours after a vendor discloses a security incident: a 5-step playbook to assess impact, contain, and document.",[91,95,99],{"label":92,"to":93,"description":94},"CISAPP vs spreadsheet","\u002Fen\u002Fcomparisons\u002Fcisapp-vs-spreadsheet-third-party-risk","How far a spreadsheet takes you in vendor risk management, and the point at which it costs more than a platform: a comparison on verifiable criteria.",{"label":96,"to":97,"description":98},"European alternatives","\u002Fen\u002Fcomparisons\u002Feuropean-alternatives-us-tprm-platforms","What choosing a European vendor changes for third-party risk management: applicable law, data transfers, sovereignty and GDPR compliance.",{"label":100,"to":101,"description":102},"TPRM selection criteria","\u002Fen\u002Fcomparisons\u002Ftprm-platform-selection-criteria","An evaluation grid for third-party risk platforms: regulatory coverage, assessment cycle, evidence, hosting, integrations and total cost of ownership.",{"id":104,"title":105,"author":106,"body":107,"definition":181,"description":182,"entities":183,"extension":185,"faq":186,"keywords":187,"meta":191,"navigation":192,"ogImage":193,"path":194,"persona":195,"publishedAt":193,"regulation":193,"relatedFeatures":196,"relatedPages":197,"seeAlso":198,"seo":202,"shortTitle":184,"slug":203,"sources":204,"stem":205,"term":206,"tldr":193,"updatedAt":207,"__hash__":208},"glossary_en\u002Fen\u002Fglossary\u002Ftprm.md","TPRM: Third Party Risk Management definition | CISAPP","CISAPP",{"type":108,"value":109,"toc":175},"minimark",[110,115,128,148,152,168],[111,112,114],"h2",{"id":113},"what-tprm-covers-and-what-it-does-not","What TPRM covers, and what it does not",[116,117,118,119,123,124,127],"p",{},"TPRM addresses the risk ",[120,121,122],"em",{},"carried by the organisation"," because of a third party, not that third party's commercial performance. A vendor can deliver flawlessly and still be a major risk: sensitive data hosted outside the EU, no recovery plan, dependency on a single subcontractor. Conversely, price negotiation, operational SLA tracking and the procurement relationship belong to ",[120,125,126],{},"vendor management",", which shares the supplier repository with TPRM but not its objectives.",[116,129,130,131,135,136,139,140,143,144,147],{},"The scope covers four risk families: ",[132,133,134],"strong",{},"cybersecurity"," (the third party as an attack path), ",[132,137,138],{},"continuity"," (the third party as a point of failure), ",[132,141,142],{},"compliance"," (the third party as an extension of the regulated perimeter) and ",[132,145,146],{},"data protection"," (the third party as a processor under GDPR).",[111,149,151],{"id":150},"why-tprm-became-a-regulatory-obligation","Why TPRM became a regulatory obligation",[116,153,154,155,158,159,161,162,164,165,167],{},"Until recently TPRM was good practice. Three European texts made it binding: ",[156,157,54],"a",{"href":55}," imposes supply chain security on essential and important entities, ",[156,160,42],{"href":43}," governs the use of ICT providers in the financial sector, and ",[156,163,50],{"href":51}," dedicates a set of controls to supplier relationships. ",[156,166,46],{"href":47}," separately requires a contractual framework for any processor handling personal data.",[116,169,170,171,174],{},"In practice, a TPRM programme must now be ",[132,172,173],{},"documented and demonstrable",", not merely effective: third-party inventory, criticality criteria, evidence of assessment, traceable decisions.",{"title":176,"searchDepth":177,"depth":177,"links":178},"",2,[179,180],{"id":113,"depth":177,"text":114},{"id":150,"depth":177,"text":151},"TPRM (Third Party Risk Management) is the discipline of identifying, assessing, treating and monitoring the risks an organisation carries because of its relationships with external suppliers, service providers and partners — chiefly cybersecurity, continuity, compliance and data protection risks.","Definition of TPRM (Third Party Risk Management): scope, difference with classic vendor management, and its place in NIS2, DORA and ISO 27001.",[184],"TPRM","md",[],[184,188,189,190],"third party risk management","vendor risk","TPRM definition",{},true,null,"\u002Fen\u002Fglossary\u002Ftprm","both",[],[],[199,200,201],"vendor-due-diligence","fourth-party-risk","security-posture-score",{"title":105,"description":182},"tprm",[],"en\u002Fglossary\u002Ftprm","TPRM (Third Party Risk Management)","2026-08-16","MZ4KhQYLlqS0BPjPhA4HBVWwh5kMRaYdhtLWl_FXEqM",[210,212,215],{"label":67,"to":211},"\u002Fen\u002Fglossary\u002Ffourth-party-risk",{"label":213,"to":214},"Security posture score","\u002Fen\u002Fglossary\u002Fsecurity-posture-score",{"label":216,"to":217},"Vendor due diligence","\u002Fen\u002Fglossary\u002Fvendor-due-diligence",1791391151298]