§ How TPRM Works · Process Guide

Third-party risk management: the end-to-end process

A practical walkthrough of how compliance teams identify, assess, remediate, and continuously monitor vendor risk — from initial intake through to supervisory evidence and audit-ready reporting.

§ What is TPRM

Third-party risk management defined

Third-party risk management (TPRM) is the structured process of identifying, assessing, and continuously monitoring the risks that vendors, suppliers, and service providers introduce into your organisation. Every organisation that depends on external parties for ICT services, data processing, or critical operations carries third-party risk. TPRM is the discipline that makes that risk visible, measurable, and manageable.

60%+

of data breaches involve a third party, according to IBM Cost of a Data Breach 2024

50+

EU and US regulatory frameworks require structured third-party risk programmes

117 days

average vendor-to-customer disclosure delay for third-party breaches

§ The TPRM process

Five steps from intake to continuous oversight

TPRM is not a one-time assessment. It is a continuous cycle that runs from initial vendor intake through to ongoing monitoring and board-level reporting. Here is how the process works end to end.

01

Identify and register vendors

Build a complete inventory of every third party that accesses your systems, processes your data, or delivers a service you depend on. Classify each by business criticality, data sensitivity, and regulatory scope. This vendor register is the foundation of your TPRM programme — without it, you cannot know what you are exposed to.

In Supplier Shield: import your vendor list, apply automated criticality scoring, and surface missing sub-contractor data in one session.
02

Assess risk before and after onboarding

Before onboarding a new vendor, conduct structured due diligence proportionate to the criticality of the service. After onboarding, run periodic assessments aligned to the regulatory frameworks that apply: DORA Art. 28(4) for financial entities, NIS2 Art. 21 for essential entities, ISO 27001:2022 clauses 5.19–5.22 for any organisation seeking certification.

In Supplier Shield: 50+ pre-built framework questionnaires. Vendors respond via a browser link with no account required.
03

Remediate findings and close contractual gaps

Assessments produce findings. Findings require owners, deadlines, and a documented remediation trail. For regulated entities, contractual gaps are as important as technical ones: DORA Art. 30 requires specific provisions in every critical ICT contract, and most organisations have gaps they are unaware of until they look systematically.

In Supplier Shield: assign findings to named owners, set deadlines, and track every status change with an immutable audit log.
04

Monitor continuously

Risk does not stand still. A vendor that passed your assessment 12 months ago may have experienced a breach, changed their sub-processing arrangements, or had a key certification lapse. Continuous monitoring — combining automated OSINT signals with scheduled review cycles — keeps your risk picture current without requiring a full assessment for every change.

In Supplier Shield: automated OSINT scanning gives every vendor an A–F risk grade that updates continuously. Aiko AI answers questions about your live vendor data.
05

Report and produce supervisory evidence

TPRM programmes only add value if the output reaches decision-makers and satisfies regulators. Board-level reporting, risk committee briefings, and supervisory submissions all require structured, consistent, and audit-ready outputs. For DORA-regulated entities, the annual Register of Information submission to the NCA is a hard compliance deadline.

In Supplier Shield: one-click export of the EBA Annex III Register of Information. Structured audit packs for NIS2 and ISO 27001 reviews.

§ Platform capabilities

What Supplier Shield automates in your TPRM programme

A–F grades · zero manual research

OSINT automated risk scoring

Every vendor in your register is continuously scanned for DNS hygiene, TLS configuration, breach exposure, and threat intelligence signals. You start every assessment with the vendor's external risk grade already quantified.

50+ frameworks · vendors respond via link

Multi-framework assessment campaigns

Launch a full assessment cycle across your vendor portfolio in one session. Automated reminders follow up without manual chasing. One questionnaire can simultaneously satisfy DORA, NIS2, and ISO 27001 obligations.

Immutable · timestamped · one-click export

Audit-ready evidence store

Every assessment, finding, remediation action, and status change is logged with a timestamp. When your regulator or auditor asks for evidence of your TPRM programme, you export the full pack in one click.

See TPRM in action on your vendor portfolio.

Book a focused session with our team. We will walk through your current vendor landscape and show you exactly where Supplier Shield structures the process.

Acuna GRC from CHF 5,388 / year · Supplier Shield add-on·No per-user fees·Swiss-hosted·Read the DORA guide