Skip to main content
Course

Third-Party Risk Management Specialist

Run the full vendor risk lifecycle with confidence, from intake to offboarding.

Intermediate

Level

4

Modules

8

Lessons

4

Graded quizzes

2

Assignments

5 hours

Estimated time

What you will be able to do

  • You will be able to explain why third-party risk matters and map each stage of the vendor risk lifecycle.
  • You will be able to run vendor intake, assign tiers, and assess inherent risk before any control review.
  • You will be able to select and interpret due diligence questionnaires such as the SIG and CAIQ.
  • You will be able to read a SOC 2 Type II report and an ISO 27001 certificate to judge the strength of a vendor's controls.
  • You will be able to document a defensible risk decision and choose the right treatment (accept, mitigate, transfer, or avoid).
  • You will be able to identify and request the key security and privacy clauses a vendor contract should contain.
  • You will be able to design an ongoing monitoring and reassessment cadence proportional to vendor risk.

What is inside

4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.

  1. 01

    Why Third-Party Risk Matters and the Vendor Lifecycle

    Understand why outsourcing transfers work but not accountability, and learn the end-to-end stages of the vendor risk lifecycle. This module gives you the mental model the rest of the course builds on.

    2 lessons · 5 quiz questions

  2. 02

    Intake, Tiering, and Due Diligence

    Learn how vendors enter the program, how to assign a risk tier from inherent risk factors, and how to run proportionate due diligence using standard questionnaires like the SIG and CAIQ. This is the analyst's day-to-day work.

    2 lessons · 5 quiz questions · assignment

  3. 03

    Reviewing SOC 2 and ISO 27001 Evidence

    Move beyond questionnaires to independent assurance. Learn to read a SOC 2 Type II report section by section and to interpret an ISO 27001 certificate and Statement of Applicability so you can judge what a vendor's evidence really proves.

    2 lessons · 5 quiz questions

  4. 04

    Risk Decisions, Contracts, and Ongoing Monitoring

    Turn assessment findings into a documented risk decision, secure the relationship with the right contract clauses, and keep watching the vendor over time. This module closes the lifecycle loop from decision to reassessment and offboarding.

    2 lessons · 5 quiz questions · assignment