Skip to content
Two LinesRisk
Third-party riskTPRM

Your risk perimeter extends far beyond your company.

We build and operate third-party risk programs for regulated organizations: an inventory you can trust, tiering that reflects service impact, assessments proportionate to exposure, and monitoring that keeps working after the report is filed.

  • Programs designed for hundreds or thousands of vendors
  • Assessment depth set by tier, not by habit
  • Fourth-party and concentration visibility
  • Remediation tracked to validated closure
Typical starting point

Where engagements usually begin — and what tends to be true on day one.

Vendors in the inventory
Incomplete by 15–30%
Tiering basis
Contract value, not service impact
Evidence location
Email threads and shared drives
Reassessment trigger
A date in a calendar
Fourth parties recorded
Rarely
Dependency map01

Who you depend on, and who they depend on.

Direct suppliers are the visible layer. The dependencies that cause incidents usually sit one or two levels beyond the contract you signed.

Yourorganization
Capabilities02

What we deliver.

Engagements combine these depending on where the program is today — a first inventory, a scaling problem, or a regulator asking how the controls are evidenced.

01

Inventory and tiering

Most programs fail at the inventory. If the population is incomplete or the tier is assigned by whoever raised the purchase order, everything downstream inherits the error.

  • Vendor inventory build & reconciliation
  • Criticality and impact assessment
  • Risk tiering model & scoring
  • Critical vendor identification
  • Data classification & processing scope
  • Intake and onboarding workflow
02

Due diligence and assessment

Assessment depth set by tier, not by habit. Tier 1 gets architecture, evidence and testing. Low-tier suppliers get a proportionate review and stop consuming the queue.

  • Security & resilience assessments
  • Questionnaire design and analysis
  • Evidence collection & validation
  • SOC 2 / ISO report review
  • Control effectiveness testing
  • Financial and legal risk inputs
03

Dependency and concentration

Four unrelated vendors can still be a single point of failure. Concentration only becomes visible when the inventory records platform, region and upstream provider.

  • Fourth-party and subprocessor mapping
  • Concentration by provider & region
  • Shared-dependency analysis
  • Critical service dependency mapping
  • Exit and contingency planning
  • Substitutability assessment
04

Monitoring and lifecycle

Between assessments is where exposure changes. Reassessment should be triggered by an event as often as it is triggered by a date.

  • Continuous vendor monitoring
  • Certification & report expiry tracking
  • Findings and remediation tracking
  • Periodic and event-driven reassessment
  • Performance and SLA signals
  • Offboarding & termination review
How we run it03

From an unreliable list to a defensible program.

  1. 01

    Establish the population

    Reconcile procurement, finance, identity and security sources into one inventory. Almost every engagement finds material vendors that were never assessed because they were never recorded.

  2. 02

    Tier against service impact

    Criticality is a property of the process the vendor supports, not of the contract value. We define tiering criteria the first line can apply consistently and the second line can defend.

  3. 03

    Assess proportionately

    A depth-of-assessment matrix per tier: evidence set, control coverage, testing approach, approval authority and reassessment frequency, all agreed up front.

  4. 04

    Drive findings to closure

    Findings rated against defined criteria, assigned to a named owner, tracked to an agreed date, and closed only after the remediation is validated rather than reported.

  5. 05

    Monitor between cycles

    Expiring evidence, subprocessor changes, disclosed vulnerabilities, SLA trends and concentration shifts feed the profile continuously, and trigger reassessment where they are material.

Bring your vendor population into one view.

We can start with an assessment of the current program, a build of the inventory and tiering model, or by taking on the assessment queue directly.