Third-Party Risk Management Specialist
Run the full vendor risk lifecycle with confidence, from intake to offboarding.
Tuition
$399
Intermediate
Level
4
Modules
8
Lessons
4
Graded quizzes
2
Assignments
5 hours
Estimated time
What you will be able to do
- You will be able to explain why third-party risk matters and map each stage of the vendor risk lifecycle.
- You will be able to run vendor intake, assign tiers, and assess inherent risk before any control review.
- You will be able to select and interpret due diligence questionnaires such as the SIG and CAIQ.
- You will be able to read a SOC 2 Type II report and an ISO 27001 certificate to judge the strength of a vendor's controls.
- You will be able to document a defensible risk decision and choose the right treatment (accept, mitigate, transfer, or avoid).
- You will be able to identify and request the key security and privacy clauses a vendor contract should contain.
- You will be able to design an ongoing monitoring and reassessment cadence proportional to vendor risk.
What is inside
4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.
- 01
Why Third-Party Risk Matters and the Vendor Lifecycle
Understand why outsourcing transfers work but not accountability, and learn the end-to-end stages of the vendor risk lifecycle. This module gives you the mental model the rest of the course builds on.
2 lessons · 5 quiz questions
- 02
Intake, Tiering, and Due Diligence
Learn how vendors enter the program, how to assign a risk tier from inherent risk factors, and how to run proportionate due diligence using standard questionnaires like the SIG and CAIQ. This is the analyst's day-to-day work.
2 lessons · 5 quiz questions · assignment
- 03
Reviewing SOC 2 and ISO 27001 Evidence
Move beyond questionnaires to independent assurance. Learn to read a SOC 2 Type II report section by section and to interpret an ISO 27001 certificate and Statement of Applicability so you can judge what a vendor's evidence really proves.
2 lessons · 5 quiz questions
- 04
Risk Decisions, Contracts, and Ongoing Monitoring
Turn assessment findings into a documented risk decision, secure the relationship with the right contract clauses, and keep watching the vendor over time. This module closes the lifecycle loop from decision to reassessment and offboarding.
2 lessons · 5 quiz questions · assignment