Third-Party Risk Management
TPRM is the programme view: how an organisation onboards, reassesses, monitors and offboards third parties over time. Articles in this category cover programme design, cadence, ownership and the difference between a single assessment and a running programme.
Other categories
- Vendor Due DiligenceThe structured process of verifying whether a software supplier meets your organisation's security, privacy, legal and operational requirements before approval.
- Regulatory FrameworksThe frameworks and regulations that shape supplier evaluation — GDPR, ISO 27001, SOC 2, NIS2, DORA and related standards.
- Security Documentation & EvidenceThe documents suppliers publish or provide that make claims verifiable — and how to read, evaluate and work with them.
- SaaS ProcurementIntegrating due diligence into the SaaS buying process so security and compliance reviews support the business rather than block it.