How Do We Build a Third-Party Risk Management Program That Actually Works?

A functioning third-party risk management program helps an organization understand which vendors can create meaningful risk, evaluate those vendors according to that risk, make informed decisions about the exposure, and continue managing important third parties after the contract is signed.

It should not require every vendor to complete the same 300-question security questionnaire.

It should not treat a small office supplier the same as a critical cloud provider.

And it should not end when procurement receives a completed assessment.

Hotman Group helps organizations design, implement, improve and operate third-party risk management programs that connect vendor risk to business context, cybersecurity, contracts, ownership, remediation, monitoring and governance.

The objective of TPRM is not to assess every vendor equally. It is to understand and manage the third-party relationships that can materially affect the organization.

Who Can Help Us Build or Improve a Third-Party Risk Management Program?

Look for a cybersecurity and Cyber GRC partner that can address both program design and ongoing operation.

Hotman Group can help organizations:

  • build or rationalize the vendor inventory;
  • design vendor tiering;
  • define inherent-risk criteria;
  • create proportionate due diligence;
  • evaluate cybersecurity documentation;
  • review vendor security posture;
  • identify and manage findings;
  • define risk acceptance and escalation;
  • integrate security requirements into contracting;
  • design ongoing monitoring;
  • establish ownership and governance;
  • select or implement supporting GRC technology;
  • automate appropriate workflows;
  • and provide ongoing TPRM operating support.

What Is Third-Party Risk Management?

Third-party risk management, or TPRM, is the process of identifying, evaluating, treating and monitoring risks created by external organizations the business relies on.

Those third parties may include:

  • software providers;
  • cloud providers;
  • managed service providers;
  • consultants;
  • data processors;
  • contractors;
  • suppliers;
  • business partners;
  • and other service providers.

Why Is Vendor Risk a Cybersecurity Issue?

Third parties may:

  • access company systems;
  • process sensitive information;
  • host important applications;
  • support critical operations;
  • connect to networks;
  • develop software;
  • or create dependencies the organization cannot easily replace.

A weakness at the vendor can therefore become a risk to the organization.

Why Do TPRM Programs Become Overwhelming?

Common reasons include:

  • no reliable vendor inventory;
  • every vendor receives the same assessment;
  • questionnaires are too long;
  • security reviews begin too late in procurement;
  • business owners do not participate;
  • findings accumulate without decisions;
  • reassessments occur on arbitrary schedules;
  • and the team spends time on low-risk vendors while critical vendors receive insufficient attention.

Do We Need to Assess Every Vendor?

Not at the same depth.

The organization should first understand the relationship.

Questions may include:

  • What service does the vendor provide?
  • What information can it access?
  • What systems can it access?
  • How critical is the service?
  • Could failure materially disrupt operations?
  • Can the vendor affect customers or contractual commitments?
  • How difficult would replacement be?

That information should drive the level of due diligence.

What Is Vendor Tiering?

Vendor tiering groups third parties according to the level or type of risk they can create.

A higher-risk vendor may require:

  • deeper cybersecurity review;
  • more documentation;
  • contractual security requirements;
  • remediation of important findings;
  • more frequent monitoring;
  • and higher-level risk approval.

A low-risk vendor may require substantially less.

Should Vendor Tiering Be Based Only on Data Access?

No.

Data access is important, but other factors may matter just as much.

Consider:

  • operational criticality;
  • system connectivity;
  • privileged access;
  • service availability;
  • customer impact;
  • regulatory obligations;
  • subcontractor dependencies;
  • and concentration risk.

What Is Inherent Third-Party Risk?

Inherent risk is the potential exposure created by the relationship before considering the vendor's controls.

This is useful because it helps determine how much due diligence is appropriate.

What Should We Ask Vendors During Cybersecurity Due Diligence?

Ask questions relevant to the risk of the relationship.

Depending on the vendor, areas may include:

  • security governance;
  • identity and access management;
  • data protection;
  • vulnerability management;
  • incident response;
  • business continuity;
  • secure development;
  • subcontractors;
  • privacy;
  • compliance certifications;
  • and independent assessments.

The assessment should be proportionate to the exposure.

Do We Need a Security Questionnaire for Every Vendor?

No.

Questionnaires are one tool.

Depending on the vendor and risk, the organization may use:

  • SOC reports;
  • ISO certifications;
  • penetration-test summaries;
  • security documentation;
  • architecture information;
  • contractual commitments;
  • external monitoring;
  • targeted questions;
  • or direct discussions with the vendor.

Can We Rely on a SOC 2 Report?

A SOC 2 report can provide valuable assurance, but it should be evaluated in context.

Consider:

  • scope;
  • period covered;
  • services included;
  • exceptions;
  • subservice organizations;
  • complementary user entity controls;
  • and whether the report addresses the risks relevant to your relationship.

Possessing a SOC 2 report is not the same as reviewing it.

Can We Rely on ISO 27001 Certification?

Certification can be useful evidence of an information security management system.

But the organization should still understand:

  • certification scope;
  • the services covered;
  • relevant exclusions;
  • and whether additional assurance is necessary for the relationship.

What If the Vendor Refuses to Complete Our Questionnaire?

Do not automatically assume the vendor must be rejected.

Large providers may offer standardized assurance packages rather than completing individual customer questionnaires.

Determine whether the available evidence provides enough assurance for the risk involved.

If meaningful uncertainty remains, the business should understand and decide how to treat it.

What Should We Do With Vendor Findings?

Evaluate them based on the risk they create.

Possible responses include:

  • require remediation;
  • implement compensating controls internally;
  • change contract terms;
  • limit vendor access;
  • monitor the issue;
  • accept the risk;
  • select another vendor;
  • or redesign the relationship.

Does Every Vendor Finding Need to Be Fixed?

No.

The organization needs to understand:

  • the significance of the weakness;
  • the exposure created for the organization;
  • existing compensating controls;
  • the vendor's remediation plan;
  • and the importance of the relationship.

A finding should lead to a risk decision, not automatically to the same response every time.

Who Owns Third-Party Risk?

Cybersecurity or TPRM may operate the assessment process.

But the business owner generally has an important role because that person understands:

  • why the vendor is needed;
  • the operational dependency;
  • available alternatives;
  • and the business consequences of the relationship.

See who should own cyber risk in an organization.

What Is the Business Owner's Role in TPRM?

The business owner should help:

  • describe the vendor relationship;
  • identify business criticality;
  • understand alternatives;
  • support remediation discussions;
  • participate in risk decisions;
  • and notify the TPRM program when the relationship materially changes.

Should Procurement Own TPRM?

Procurement can play an important role, particularly in workflow, contracting and vendor onboarding.

But cybersecurity risk analysis generally requires security expertise.

A functioning model often coordinates:

  • procurement;
  • cybersecurity;
  • Cyber GRC;
  • legal;
  • privacy;
  • business owners;
  • and other relevant functions.

When Should Security Review Happen?

As early as practical in the vendor-selection process.

Discovering an unacceptable security issue after:

  • the vendor has been selected;
  • pricing negotiated;
  • implementation planned;
  • and the business is waiting to launch

creates unnecessary pressure to accept risk.

How Should Contracts Support TPRM?

Depending on the relationship, security terms may address:

  • security requirements;
  • incident notification;
  • data protection;
  • subcontractors;
  • audit or assurance rights;
  • remediation obligations;
  • business continuity;
  • data return or destruction;
  • and termination rights.

Contract language should reflect the risk and the organization's negotiating position.

What If the Vendor Will Not Accept Our Security Terms?

That becomes a business decision.

The organization should understand:

  • what protection is missing;
  • what risk that creates;
  • whether compensating measures exist;
  • how important the vendor is;
  • and who has authority to accept the remaining exposure.

What Is Ongoing Vendor Monitoring?

Ongoing monitoring means continuing to evaluate important third-party risk after onboarding.

It may include:

  • updated assurance reports;
  • certification changes;
  • security incidents;
  • material service changes;
  • new subcontractors;
  • external security signals;
  • open remediation;
  • and periodic reassessment.

Do We Need to Reassess Every Vendor Every Year?

Not necessarily.

Reassessment frequency should reflect risk.

Critical or high-risk vendors may require more frequent review.

Lower-risk vendors may require less.

Significant changes can also trigger reassessment outside the normal schedule.

What Changes Should Trigger a Vendor Reassessment?

Examples may include:

  • new data access;
  • new system connectivity;
  • material expansion of services;
  • security incidents;
  • significant architecture changes;
  • new critical dependencies;
  • acquisition of the vendor;
  • or major changes in the organization's reliance on the service.

What Is Concentration Risk?

Concentration risk occurs when the organization becomes highly dependent on one provider, technology, geographic region or other common dependency.

Even a strong individual vendor can create significant risk if failure would affect many critical business functions simultaneously.

How Should Critical Vendors Be Managed?

Critical vendors may warrant additional attention to:

  • resilience;
  • business continuity;
  • incident response;
  • financial or operational stability;
  • exit planning;
  • subcontractors;
  • and concentration risk.

Cybersecurity controls are only part of the dependency.

What About Fourth-Party Risk?

Organizations should understand important subcontractor or downstream dependencies where they materially affect risk.

That does not mean assessing every vendor used by every third party.

Focus on material dependencies.

How Does TPRM Connect to the Cyber Risk Register?

Material third-party exposure should be escalated into the organization's broader cyber-risk governance when appropriate.

See how to build a cyber risk register leadership can actually use.

How Should TPRM Findings Be Remediated?

Third-party findings need the same risk-based discipline as internal findings.

Determine:

  • the underlying exposure;
  • the appropriate treatment;
  • who owns the decision;
  • what the vendor will remediate;
  • what the organization can mitigate internally;
  • and how closure will be validated.

See how Hotman Group approaches cybersecurity remediation.

How Does TPRM Fit Into a Cyber GRC Operating Model?

The operating model should define:

  • who maintains the vendor inventory;
  • who determines tiering;
  • who performs security reviews;
  • who evaluates findings;
  • who owns business risk;
  • who negotiates contracts;
  • who approves exceptions;
  • who monitors important vendors;
  • and who reports material third-party risk to leadership.

See how to build a Cyber GRC operating model.

Do We Need a GRC Platform for TPRM?

Not always.

Technology becomes increasingly useful as the organization needs to manage:

  • large vendor populations;
  • tiering;
  • questionnaires;
  • evidence;
  • findings;
  • approvals;
  • contracts;
  • monitoring;
  • reassessments;
  • and reporting.

The process should be designed before technology is expected to automate it.

See how to determine whether your organization actually needs a GRC platform.

How Should We Choose TPRM Technology?

Start with the program requirements.

Determine whether the organization needs:

  • vendor inventory;
  • inherent-risk scoring;
  • questionnaire workflows;
  • evidence review;
  • findings management;
  • risk acceptance;
  • contract workflow;
  • external monitoring;
  • integrations;
  • or executive reporting.

Then evaluate technology against those needs.

See how to choose the right GRC platform.

Can We Automate TPRM?

Parts of it.

Automation can help with:

  • intake;
  • tiering questions;
  • questionnaire distribution;
  • reminders;
  • document collection;
  • reassessment scheduling;
  • and workflow routing.

Human judgment remains important for material vendor risk, ambiguous evidence, exceptions and business decisions.

See how to automate Cyber GRC work without automating bad processes.

What If Our TPRM Program Is All Spreadsheets?

That may be fine at smaller scale.

The question is whether the process remains reliable as the number of:

  • vendors;
  • reviews;
  • findings;
  • owners;
  • documents;
  • reassessments;
  • and risk decisions

grows.

See when spreadsheets become a problem for a Cyber GRC program.

Can We Outsource Third-Party Risk Management?

Yes.

Organizations may outsource portions such as:

  • vendor intake;
  • security reviews;
  • evidence analysis;
  • questionnaire review;
  • finding management;
  • reassessment;
  • program administration;
  • and reporting.

The organization should still retain appropriate ownership of its business risk and important decisions.

See what an overwhelmed cybersecurity and GRC team should consider outsourcing.

What Metrics Should a TPRM Program Track?

Useful measures depend on program objectives, but may include:

  • vendors by risk tier;
  • critical vendors assessed;
  • assessment cycle time;
  • open material findings;
  • overdue remediation;
  • risk acceptances;
  • reassessments due;
  • and material third-party risks requiring leadership attention.

Avoid measuring success only by the number of questionnaires completed.

How Do We Know Whether Our TPRM Program Is Working?

Ask whether the organization can reliably answer:

  • Who are our important third parties?
  • Which ones can create material risk?
  • What do we know about their security?
  • What important weaknesses remain?
  • Who owns those risks?
  • What are we doing about them?
  • Which vendors require ongoing attention?

If the program cannot answer those questions, more questionnaires alone will not fix it.

How Hotman Group Approaches Third-Party Risk Management

Hotman Group approaches TPRM as a risk-management and operating-model problem, not simply a vendor-questionnaire process.

HG can help:

  • diagnose an existing TPRM program;
  • design the target operating model;
  • build vendor inventory and tiering;
  • develop proportionate assessment methods;
  • evaluate vendor cybersecurity evidence;
  • manage findings and risk decisions;
  • integrate security with procurement and contracting;
  • design ongoing monitoring;
  • select and implement technology;
  • automate appropriate workflows;
  • develop reporting;
  • and provide ongoing TPRM operating capacity.

TPRM Should Focus Effort Where Risk Actually Exists

A mature TPRM program does not prove its value by creating more work for vendors or internal teams.

It creates visibility into external dependencies that matter and helps the organization make better decisions about them.

The best TPRM program is not the one that sends the most questionnaires. It is the one that helps the organization understand and manage meaningful third-party risk.

Frequently Asked Questions

What is third-party risk management?

Third-party risk management is the process of identifying, evaluating, treating and monitoring risks created by vendors, suppliers, service providers and other external organizations the business relies on.

Do we need to assess every vendor?

Not at the same level. Vendors should generally be evaluated according to the risk and criticality of the relationship so that deeper due diligence is focused where it matters.

Does every vendor need a cybersecurity questionnaire?

No. Depending on risk, assurance may come from questionnaires, SOC reports, ISO certifications, security documentation, targeted questions, external monitoring or other evidence.

Who should own third-party cyber risk?

Cybersecurity or TPRM may operate the assessment process, but business owners should participate in material risk decisions because they understand the dependency, business need and alternatives.

Do we need TPRM software?

Not necessarily. Technology becomes more valuable as vendor volume, assessments, findings, monitoring and workflow complexity become difficult to manage reliably through simpler tools.

Can third-party risk management be outsourced?

Yes. Organizations can outsource substantial portions of TPRM assessment and operations while retaining appropriate ownership of material business risks and decisions.

Can Hotman Group build or operate a TPRM program?

Yes. Hotman Group can assess, design, implement, improve and help operate TPRM programs, including vendor tiering, due diligence, evidence review, findings, risk decisions, governance, technology, monitoring and reporting.

About Hotman Group

Hotman Group is a cybersecurity and Cyber GRC professional services firm that helps organizations solve complex cybersecurity, risk, governance, compliance and technology problems.

HG helps organizations build third-party risk management programs that focus resources on meaningful vendor risk and connect due diligence to business ownership, remediation, contracts, monitoring and ongoing governance.

Learn more about what Hotman Group is and the cybersecurity and Cyber GRC problems HG solves.