Third-Party Risk Module
Third-Party Risk Module
Overview
The Third-Party Risk (TPRM) module enables you to assess, monitor, and manage risks associated with vendors, suppliers, and other third-party relationships. It provides structured vendor risk assessment and ongoing monitoring capabilities.
Key Features
- Vendor registration and profiling
- Risk assessment questionnaires
- Due diligence documentation
- Contract and document management
- Periodic review scheduling
- Risk scoring and categorization
- Contact management
Adding a Vendor
To add a new vendor:
- Navigate to Risk - Third-Party Risk
- Click Add Vendor
- Fill in vendor details:
- Vendor Name - Company name
- Category - Vendor type/category
- Description - Services provided
- Risk Level - Initial risk assessment
- Status - Active, Inactive, Under Review
- Click Submit
Vendor Profile Tabs
Each vendor profile includes:
- Form - Basic vendor information and risk assessment
- Contact - Vendor contact persons
- Document - Contracts, certifications, and other documents
- Review - Periodic review history
Risk Assessment
Assess vendor risks:
- Open vendor profile
- Go to Form tab
- Complete risk assessment questionnaire
- Evaluate areas such as:
- Data security practices
- Business continuity
- Compliance certifications
- Financial stability
- Operational resilience
- System calculates overall risk score
Managing Contacts
Add vendor contacts:
- Go to Contact tab
- Click Add Contact
- Enter contact details (name, email, phone, role)
- Designate primary contact if needed
Document Management
Store vendor documents:
- Go to Document tab
- Upload relevant documents:
- Contracts and agreements
- Security certifications (ISO, SOC)
- Insurance certificates
- Audit reports
- NDAs and compliance documents
- Set document expiry dates for tracking
Periodic Reviews
Schedule and conduct reviews:
- Set review frequency (Annual, Semi-annual, Quarterly)
- Go to Review tab
- Click Add Review
- Document review findings
- Update risk score based on findings
Best Practices
- Categorize vendors by criticality
- Maintain updated contact information
- Track document expirations
- Conduct regular risk reassessments
- Document all vendor interactions
- Integrate with overall risk register