TPRM · 5 min read
Third-Party Risk Management Basics
Your vendors' weaknesses become your risk. The lifecycle for assessing and monitoring them, and the agreements that hold them accountable.
Why third parties are your risk
Most organizations hand data and access to vendors, suppliers, and service providers: and many of the biggest breaches started in a third party. Third-Party Risk Management (TPRM) is the discipline of making sure those partners protect your data and systems as well as you would. A vendor's vulnerability is, in practice, *your* risk.
The lifecycle
- Due diligence (before): assess the vendor's security before signing: questionnaires, evidence of audits (SOC 2, ISO 27001), and independent assessments. Higher-risk vendors get deeper scrutiny.
- Contracting: bake security into the agreement (see below), including a right-to-audit clause.
- Onboarding: grant only the access required (least privilege) and document the data shared.
- Monitoring (ongoing): recheck posture periodically, watch for breaches, and re-assess on renewal or major change.
- Offboarding: revoke access and confirm data is returned or destroyed.
Know your agreements
Interviewers love these acronyms:
- SLA (Service-Level Agreement): the measurable service commitments (uptime, response times).
- MOU/MOA: memoranda of understanding/agreement: roles and intentions between parties.
- MSA (Master Service Agreement): the overarching contract terms.
- NDA: confidentiality obligations.
- BPA (Business Partners Agreement): terms between partners sharing responsibility.
The theme: the contract is where third-party security becomes *enforceable*, not just hoped for.
