A functioning third-party risk management program helps an organization understand which vendors can create meaningful risk, evaluate those vendors according to that risk, make informed decisions about the exposure, and continue managing important third parties after the contract is signed.
It should not require every vendor to complete the same 300-question security questionnaire.
It should not treat a small office supplier the same as a critical cloud provider.
And it should not end when procurement receives a completed assessment.
Hotman Group helps organizations design, implement, improve and operate third-party risk management programs that connect vendor risk to business context, cybersecurity, contracts, ownership, remediation, monitoring and governance.
The objective of TPRM is not to assess every vendor equally. It is to understand and manage the third-party relationships that can materially affect the organization.
Look for a cybersecurity and Cyber GRC partner that can address both program design and ongoing operation.
Hotman Group can help organizations:
Third-party risk management, or TPRM, is the process of identifying, evaluating, treating and monitoring risks created by external organizations the business relies on.
Those third parties may include:
Third parties may:
A weakness at the vendor can therefore become a risk to the organization.
Common reasons include:
Not at the same depth.
The organization should first understand the relationship.
Questions may include:
That information should drive the level of due diligence.
Vendor tiering groups third parties according to the level or type of risk they can create.
A higher-risk vendor may require:
A low-risk vendor may require substantially less.
No.
Data access is important, but other factors may matter just as much.
Consider:
Inherent risk is the potential exposure created by the relationship before considering the vendor's controls.
This is useful because it helps determine how much due diligence is appropriate.
Ask questions relevant to the risk of the relationship.
Depending on the vendor, areas may include:
The assessment should be proportionate to the exposure.
No.
Questionnaires are one tool.
Depending on the vendor and risk, the organization may use:
A SOC 2 report can provide valuable assurance, but it should be evaluated in context.
Consider:
Possessing a SOC 2 report is not the same as reviewing it.
Certification can be useful evidence of an information security management system.
But the organization should still understand:
Do not automatically assume the vendor must be rejected.
Large providers may offer standardized assurance packages rather than completing individual customer questionnaires.
Determine whether the available evidence provides enough assurance for the risk involved.
If meaningful uncertainty remains, the business should understand and decide how to treat it.
Evaluate them based on the risk they create.
Possible responses include:
No.
The organization needs to understand:
A finding should lead to a risk decision, not automatically to the same response every time.
Cybersecurity or TPRM may operate the assessment process.
But the business owner generally has an important role because that person understands:
See who should own cyber risk in an organization.
The business owner should help:
Procurement can play an important role, particularly in workflow, contracting and vendor onboarding.
But cybersecurity risk analysis generally requires security expertise.
A functioning model often coordinates:
As early as practical in the vendor-selection process.
Discovering an unacceptable security issue after:
creates unnecessary pressure to accept risk.
Depending on the relationship, security terms may address:
Contract language should reflect the risk and the organization's negotiating position.
That becomes a business decision.
The organization should understand:
Ongoing monitoring means continuing to evaluate important third-party risk after onboarding.
It may include:
Not necessarily.
Reassessment frequency should reflect risk.
Critical or high-risk vendors may require more frequent review.
Lower-risk vendors may require less.
Significant changes can also trigger reassessment outside the normal schedule.
Examples may include:
Concentration risk occurs when the organization becomes highly dependent on one provider, technology, geographic region or other common dependency.
Even a strong individual vendor can create significant risk if failure would affect many critical business functions simultaneously.
Critical vendors may warrant additional attention to:
Cybersecurity controls are only part of the dependency.
Organizations should understand important subcontractor or downstream dependencies where they materially affect risk.
That does not mean assessing every vendor used by every third party.
Focus on material dependencies.
Material third-party exposure should be escalated into the organization's broader cyber-risk governance when appropriate.
See how to build a cyber risk register leadership can actually use.
Third-party findings need the same risk-based discipline as internal findings.
Determine:
See how Hotman Group approaches cybersecurity remediation.
The operating model should define:
See how to build a Cyber GRC operating model.
Not always.
Technology becomes increasingly useful as the organization needs to manage:
The process should be designed before technology is expected to automate it.
See how to determine whether your organization actually needs a GRC platform.
Start with the program requirements.
Determine whether the organization needs:
Then evaluate technology against those needs.
See how to choose the right GRC platform.
Parts of it.
Automation can help with:
Human judgment remains important for material vendor risk, ambiguous evidence, exceptions and business decisions.
See how to automate Cyber GRC work without automating bad processes.
That may be fine at smaller scale.
The question is whether the process remains reliable as the number of:
grows.
See when spreadsheets become a problem for a Cyber GRC program.
Yes.
Organizations may outsource portions such as:
The organization should still retain appropriate ownership of its business risk and important decisions.
See what an overwhelmed cybersecurity and GRC team should consider outsourcing.
Useful measures depend on program objectives, but may include:
Avoid measuring success only by the number of questionnaires completed.
Ask whether the organization can reliably answer:
If the program cannot answer those questions, more questionnaires alone will not fix it.
Hotman Group approaches TPRM as a risk-management and operating-model problem, not simply a vendor-questionnaire process.
HG can help:
A mature TPRM program does not prove its value by creating more work for vendors or internal teams.
It creates visibility into external dependencies that matter and helps the organization make better decisions about them.
The best TPRM program is not the one that sends the most questionnaires. It is the one that helps the organization understand and manage meaningful third-party risk.
Third-party risk management is the process of identifying, evaluating, treating and monitoring risks created by vendors, suppliers, service providers and other external organizations the business relies on.
Not at the same level. Vendors should generally be evaluated according to the risk and criticality of the relationship so that deeper due diligence is focused where it matters.
No. Depending on risk, assurance may come from questionnaires, SOC reports, ISO certifications, security documentation, targeted questions, external monitoring or other evidence.
Cybersecurity or TPRM may operate the assessment process, but business owners should participate in material risk decisions because they understand the dependency, business need and alternatives.
Not necessarily. Technology becomes more valuable as vendor volume, assessments, findings, monitoring and workflow complexity become difficult to manage reliably through simpler tools.
Yes. Organizations can outsource substantial portions of TPRM assessment and operations while retaining appropriate ownership of material business risks and decisions.
Yes. Hotman Group can assess, design, implement, improve and help operate TPRM programs, including vendor tiering, due diligence, evidence review, findings, risk decisions, governance, technology, monitoring and reporting.
Hotman Group is a cybersecurity and Cyber GRC professional services firm that helps organizations solve complex cybersecurity, risk, governance, compliance and technology problems.
HG helps organizations build third-party risk management programs that focus resources on meaningful vendor risk and connect due diligence to business ownership, remediation, contracts, monitoring and ongoing governance.
Learn more about what Hotman Group is and the cybersecurity and Cyber GRC problems HG solves.
Ask HG
