Third-Party Risk (TPRM)
Tiering that a knockout rule can override
Inherent factors compute a score and a band, and a knockout rule can force a tier regardless, because some combinations are critical whatever the arithmetic says.
- Tier factors and factor scores feeding configurable scoring profiles
- Knockout rules that override the computed band outright
- Fourth-party links, so the chain past your direct vendor is visible
- Review schedule rules that set reassessment cadence by tier
Inherent risk factors
- Data classificationConfidential,
- System access levelPrivileged,
- Service criticalityHigh,
- Fourth-party reliancePresent,
Knockout rule applied. Privileged access to confidential data forces Tier 1, whatever the computed score says.
Contracts
Obligations tracked, not just documents stored
Contracts carry categorised obligations with their own status, a full status history, and review decisions with approvals, so a contractual security commitment is a tracked object.
- Contract obligations by category, each with status
- Contract status history retained end to end
- Review decisions with recorded approvals
- Engagements scoped to entities, with service and asset links
Treatment decision
- 1Treatment planActions with owners, priority, and due dates
- 2Action trackingStatus per action, SLA where defined
- 3ReassessmentResidual score recalculated after closure
Due diligence
Evidence with an expiry date
Due diligence requests move through lifecycle phases and carry document validity, so expired attestations surface instead of silently ageing in a folder.
- Requests typed by kind, with lifecycle phase and status
- Document type and validity status tracked per artefact
- Questionnaire assessments with sections, scoring dimensions, and methods
- Score overrides captured with their own approval status
Level 3: Well Defined
A standard process is defined and followed across the organisation.
Every question in the control library carries its own written descriptor at each level.
Issues
Findings that come out of assessments
Assessment responses can trigger issues automatically, categorised and severity-rated, so a weak answer becomes tracked work rather than a note in a report.
- Issues with severity, status, category, source, and type
- Assessment-triggered issue creation
- Comments and attachments per issue
- Lifecycle history across the whole vendor relationship
Privileged access review not evidenced
Traced to control · raised from assessment
Export current privileged accounts
IT Ops
Confirm owner for each account
System owners
Remove unowned accounts
IT Ops · waiting on “Confirm owner for each account”
Attach review evidence
Security · waiting on “Remove unowned accounts”
Evidence is reviewed and accepted, not just attached
Framework alignment
Works with your control frameworks
This module shares the platform control library. Map national frameworks and global standards alongside jurisdiction-specific authorities.
Solutions by role
Built for your team
See third-party risk in your environment
A walkthrough scoped to your entities, your frameworks, and the way your programme is actually run.