Third-Party Risk Management (TPRM) is the discipline of identifying, assessing, and continuously monitoring the risks that vendors, suppliers, and other external partners introduce into an organisation. Because modern businesses rely on a deep web of SaaS tools, processors, and subcontractors, a weakness in a third party can become the organisation’s own breach or compliance failure.
A typical TPRM programme inventories vendors, tiers them by criticality and data access, assesses each one through security questionnaires and evidence such as SOC 2 reports or ISO 27001 certificates, and then re-assesses on a schedule. It also tracks contractual safeguards and, where personal data is shared, the data-processing terms required under regimes like the DPDP Act and GDPR.
The hard part is keeping assessments current and proportionate. Manual questionnaire chasing does not scale, so mature programmes prioritise by risk tier and automate evidence collection and reassessment.
Comply automates this — see the vendor risk page.