GlossaryCompliance operations

TPRM

Short answer

TPRM (Third Party Risk Management) is the process of identifying, assessing and monitoring the security risks that come from suppliers and service providers with access to a company's data or systems, before signing with them and throughout the relationship.

Why suppliers matter

Many incidents start at a supplier: a compromised IT provider, a SaaS tool that leaks data or a software update that carries malware, known as a supply chain attack. A company's security is only as strong as the providers that can reach its systems and data.

The TPRM process

It starts with an inventory of suppliers, classified by how critical they are and what data they handle. Critical suppliers are assessed before contracting, through security questionnaires, certifications such as ISO 27001 or SOC 2 reports, and contract clauses on security, incident notification and audit rights. The relationship is then reviewed periodically, and access is removed when it ends.

What regulations require

NIS2 lists supply chain security among its mandatory risk management measures. DORA goes further for financial entities, with a register of information covering all ICT contracts and specific contract requirements, explained in the five pillars of DORA. ISO 27001 covers supplier relationships in Annex A 5.19 to 5.23.

The other side of the table

For suppliers, TPRM means answering more security questionnaires from customers. A recognised certification and a well organised set of evidence make those reviews faster and help close deals.

Related terms

Keep reading on this topic

Running security as a repeatable process: policy management, risk registers, evidence upkeep, supplier assessment and audit readiness between cycles.

Go to the topic hub