The Technical Corner – From Inventory to Release: The TPRM Lifecycle
A third-party risk management program does not become effective simply because it uses a longer questionnaire, a more expensive platform, or a greater number of external ratings.
It becomes effective when it enables the organization to make consistent decisions regarding its dependencies.
Which supplies require a thorough review? What shortcomings can be tolerated? What terms must be included in the contract? Who verifies that the supplier complies with them? What happens if the risk changes or if the relationship must be terminated?
If these questions remain unanswered, the program risks generating a lot of information but providing little oversight.
The problem isn’t a lack of tools. It’s the difficulty of linking inventory, critical issues, assessment, decision-making, contracts, monitoring, and business continuity into a single lifecycle.
The process begins before due diligence
In many organizations, TPRM begins when the procurement department asks the supplier to fill out a questionnaire.
By that point, however, several decisions have already been made. The business has identified the product, the supplier has been selected, and financial negotiations are often well underway. If the assessment reveals a critical issue, it may be difficult to halt the process or impose substantial conditions.
A mature program must act sooner.
Risk management should begin when the need to use an external resource is identified. At this stage, it is necessary to understand which processes will be supported, what information will be processed, which systems will be accessible, and to what extent the organization will become dependent on the service provider.
The TPRM is therefore not a final check on the selected vendor. It is a component of the purchasing decision-making process.
Phase 1. Define the scope and create the inventory
It is not possible to manage suppliers and services that have not been registered.
The inventory should include at least the following:
- the legal entity that provides the product or service;
- the service actually purchased;
- the person in the company responsible for the report;
- the business processes and products supported;
- the systems, data, and locations involved;
- the main known subcontractors;
- the term and value of the contract;
- the location of the disbursement;
- the scheduled dates for review, renewal, and termination.
The most important point is to distinguish between the supplier and the supply.
The same company may operate an essential application and, under a separate contract, provide a service that is easily replaceable. Classifying it as either critical or non-critical only once results in an inaccurate representation.
The correct unit of analysis is the relationship between the supplier, product, or service and the business process it supports.
This approach also makes it easier to integrate TPRM with Business Impact Analysis (BIA). BIA identifies the processes and external resources needed within specific timeframes. The supplier inventory should highlight these same dependencies, ensuring that Business Continuity and procurement do not describe two separate organizations.
Step 2. Classify the severity
Tiering is used to determine the level of detail required.
Applying the same level of due diligence to all suppliers is inefficient. A complex questionnaire sent to hundreds of minor suppliers consumes resources, yields responses that are difficult to verify, and reduces the attention available for truly critical dependencies.
However, the classification should not be based solely on the contract value.
A contract with a limited budget may support a critical process, require privileged access, or include a component that is difficult to replace. Conversely, a high-value contract may involve a service offered by numerous providers.
Some of the most useful criteria include:
Impact of the Outage
Which processes, customers, products, and obligations would be affected if the supply were unavailable?
Replacement Time
Is there a real alternative? How long would the selection, contract negotiation, migration, configuration, certification, and launch take?
Theoretical fungibility is not enough. An alternative is useful only if it can be implemented within the timeframe required by the process.
Access to Systems and Information
Does the supplier have remote access, administrative privileges, personal data, confidential information, or intellectual property?
Operational Role
Does the service support an essential function, a regulated activity, or a service provided directly to the customer?
Concentration
Are more processes dependent on the same vendor? Do more suppliers use the same technology, infrastructure, or subcontractor?
Financial and Commercial Dependence
Is the supplier financially stable? Does the organization account for a significant portion of its revenue? Could the relationship be jeopardized by a liquidity crisis?
The ACN FAQs on the supply chain call for consideration of access to systems and data, the impact of a major disruption, recovery times and costs, and the supplier’s role in system governance. The underlying principle is proportionality: requirements and audits must be based on the criticality of the specific supply.
A three-tier model—critical, relevant, and standard—may be sufficient for many organizations. However, there is no universally correct number of tiers. What matters is that each tier implements clearly defined controls.
Step 3. Conduct due diligence
Due diligence is used to assess risk before entering into or renewing a commitment.
A questionnaire can make it easier to gather information, but it has one obvious limitation: in most cases, the provider evaluates itself.
A positive response does not necessarily prove that the check is effective. It may simply indicate that a policy exists or that the compiler considers the requirement to be met.
Due diligence should therefore distinguish between statements and evidence.
The evidence may include:
- certifications and their scope;
- independent audit reports;
- summary of continuity and disaster recovery tests;
- penetration test results;
- incident management procedures;
- financial data;
- information on disputes and penalties;
- insurance;
- history of interruptions;
- corporate structure and ownership structure;
- the location of data, operations, and infrastructure;
- dependence on subcontractors.
On July 8, 2026, NIST published the final version of SP 1326, a guide on due diligence in the ICT supply chain. The guide identifies five components: influence resulting from foreign ownership or control, origin, resilience, core cybersecurity practices, and downstream levels of the supply chain.
The document specifically addresses ICT providers, but it proposes a principle that applies more broadly: due diligence is an investigative process designed to support a decision, not an exercise in gathering documentation.
How Much to Go Into Detail
The depth of the assessment should depend on the tiering.
For a standard supply, a limited verification of the essential requirements may be sufficient.
For a significant supply, documents, independent evidence, and a financial assessment may be required.
For a critical supply, it may be advisable to hold meetings with the vendor’s management, conduct audits, analyze business continuity plans, verify test results, and examine key downstream dependencies in greater detail.
The goal is not to eliminate every risk. It is to understand it well enough to decide whether—and under what conditions—to enter into the relationship.
Step 4. Make a decision regarding the risk
This phase is often the least formalized.
The questionnaire is completed, a score is calculated, and the result is saved. Any shortcomings are recorded, but it is unclear what effect they are supposed to have.
An assessment is useful only if it leads to a decision.
When faced with an unacceptable risk, the organization may:
- request a correction before the supply begins;
- agree on a remediation plan with specific deadlines;
- introduce compensatory measures;
- limit the scope of the service or the access granted;
- arrange for an alternative supplier;
- formally accept the risk;
- to end the relationship.
The decision should be made by a person with the necessary authority, commensurate with the level of risk.
The contract manager should not be allowed to independently accept a high risk to security, business continuity, or regulatory compliance simply because the supplier is cost-effective.
Remediation must be managed
A remediation plan should specify:
- the deficiency to be corrected;
- the agreed-upon action;
- the person in charge;
- the scheduled date;
- the evidence to be provided;
- temporary measures;
- the consequences of failure to complete the task.
Without escalation and consequences, remediation risks becoming an indefinite extension of the risk.
Step 5. Incorporate the risk into the contract
A contract is the point at which decisions become obligations.
General clauses, such as a commitment to comply with regulations or to take appropriate measures, can be useful but are rarely sufficient. They do not specify what the supplier must do, by when, or what evidence is required.
For critical supplies, the contract should address at least the following areas.
Safety Requirements
The requirements must be proportionate to the service, the accesses, and the data involved.
Operational continuity
The contract should cover plans, restoration objectives, testing, reporting of results, and management of deficiencies.
Accident Reporting
The provider should report, without undue delay, any events that may affect the customer’s service, data, or systems.
The 24- and 72-hour timeframes set forth in the NIS2 Directive pertain, respectively, to the early warning and the notification by the regulated entity after it becomes aware of the significant incident. Using these same timeframes as the maximum deadline granted to the provider may reduce or eliminate the time available to analyze the impact and fulfill obligations.
For the most critical services, it may be preferable to issue an initial announcement within a few hours—even if the information is incomplete—followed by subsequent updates.
Subcontracting
It is necessary to determine whether the supplier may use subcontractors, what information the supplier must provide, and in which cases prior notification or authorization is required.
Right to Audit
The audit policy should define procedures, notice requirements, frequency, access to records, and the handling of nonconformities.
On-site audits are not always the only solution. Independent reports, certifications, and shared audits may be used, provided they provide adequate evidence.
Change Management
Changes to infrastructure, location, ownership, technology, or subcontractors may alter the risk profile. The contract should address at least the most significant changes.
Cooperation During the Crisis
The provider must make available the contacts, information, logs, and resources necessary for incident management and recovery.
Exit and Transition
Timelines, support, data return, knowledge transfer, data deletion, and continuity must be defined during the transition to another operator.
Step 6. Monitor the report
Due diligence provides a snapshot of the supplier at a specific point in time.
During the term of the agreement, properties, financial status, infrastructure, subcontractors, technologies, key personnel, and delivery methods may change.
Monitoring should combine periodic checks with event-triggered checks.
Periodic Monitoring
It may include:
- certification renewal;
- review of the evidence;
- verification of continuity tests;
- SLA monitoring;
- update on the financial situation;
- review of dependencies;
- Review of remediation plans.
Event-Triggered Monitoring
A new evaluation may be necessary in the following cases:
- accident;
- acquisition or change in control;
- use of a new subcontractor;
- transfer of service;
- substantial change in technology;
- financial deterioration;
- change in the scope of the contract;
- repeated failure to comply with SLAs;
- changes in geopolitical or regulatory risk.
Monitoring should not be limited to generating alerts. Every relevant signal must have an owner, an escalation threshold, and a recommended action.
Step 7. Prepare for and Manage the Exit
A relationship with a supplier eventually ends due to expiration, dissatisfaction, an incident, bankruptcy, a strategic decision, or a regulatory requirement.
An unplanned migration can cause disruption even when the decision to switch vendors is the right one.
The exit plan should clarify:
- which provider or solution will replace the service;
- How long will the transition take?;
- what data must be transferred;
- which formats and interfaces will be used;
- what knowledge needs to be transferred;
- How will continuity be ensured during the transition?;
- how access and credentials will be revoked;
- how the deletion of data will be verified;
- How long will the outgoing supplier be required to provide support?
For the most critical supplies, these factors should be evaluated before signing the contract.
Only discovering during a crisis that data cannot be exported, that licenses are not transferable, or that the transition period takes many months means you have accepted a lock-in without fully understanding its implications.
Not everything has to be automated
TPRM platforms can help manage inventories, questionnaires, workflows, deadlines, and alerts.
However, they do not replace a professional evaluation.
An external rating may indicate observable vulnerabilities, but it does not necessarily know the scope of the purchased service. A certification demonstrates that a management system has been audited, but it is necessary to verify whether the service in question falls within the scope of the certification. A questionnaire can gather information, but it does not, on its own, determine whether the risk is acceptable.
Technology should reduce administrative tasks and highlight exceptions. The responsibility for decision-making remains with the organization.
Metrics that measure the program
Counting the number of questionnaires sent out or audits conducted measures the volume of activity, not necessarily its effectiveness.
Key indicators may include:
- percentage of critical supplies related to BIA processes;
- critical supplies for which no alternative is available within the required timeframe;
- expired remediation measures;
- critical contracts lacking the minimum clauses;
- suppliers with outdated ratings;
- accidents reported after the contractual deadline;
- joint ventures involving multiple suppliers;
- missing or outdated exit plans;
- Estimated time to replace each critical supply.
These indicators help us understand not only how much work has been done, but also where the organization remains vulnerable.
Final Questions
A TPRM program should make it possible to quickly answer certain questions:
- Which supplies could disrupt essential processes?
- Which dependencies do not have an alternative that can be implemented in a timely manner?
- What risks were accepted, and by whom?
- Which suppliers still have open remediation cases?
- What changes in the relationship call for a reassessment?
- How long would it take to get out of each difficult relationship?
If this information is scattered across spreadsheets, contracts, questionnaires, and email inboxes, the program technically exists but does not yet provide a reliable view of risk.
The value of third-party risk management does not depend on the number of controls performed. It depends on the ability to identify critical dependencies, decide which risks to accept, and take action before a supplier issue leads to an operational disruption.









