What a real TPRM program looks like

Third-party risk management (TPRM) sounds like something only banks and hospitals need. It’s not. If your business depends on any external vendor for data handling, infrastructure, or critical services, you’ve got third-party risk whether you’ve named it or not.

A proper TPRM program’s got four moving parts:

  1. Identification - catalog every vendor that touches your data or operations
  2. Assessment - score each vendor’s risk based on what they access and how critical they are
  3. Mitigation - address gaps before they become incidents
  4. Monitoring - keep watching, because risk profiles change constantly

Most companies nail the first two and ignore the last two. That’s like locking your front door but never checking if the lock still works.

The NIST Cybersecurity Framework provides a solid foundation for structuring vendor risk categories, but I’ve found that most mid-market teams need something more practical than a government-issued reference document. They need a checklist they can actually run.

Security questionnaire that matters

Security questionnaires have a reputation problem. They’re long, boring, and vendors hate filling them out. But the alternative - trusting vendors without verification - is worse.

Here’s what your security questionnaire should cover, stripped down to what actually matters:

Data handling and storage

  • Where is our data stored geographically?
  • Is data encrypted at rest and in transit? What encryption standards?
  • Who within the vendor’s organization can access our data?
  • What happens to our data when the contract ends?
  • Do they use subprocessors, and if so, who?

Access controls

  • How do they manage authentication? Multi-factor required?
  • What’s their password policy and rotation schedule?
  • Do they conduct regular access reviews?
  • How quickly can they revoke access when an employee leaves?

Incident response

  • What’s their breach notification timeline? (GDPR requires 72 hours, but you might need faster)
  • Do they have a documented incident response plan?
  • When was it last tested?
  • Will they share forensic reports with you?

Business continuity

  • What’s their recovery time objective (RTO)?
  • When did they last test their disaster recovery plan?
  • Do they have geographic redundancy?

Financial stability assessment

A vendor’s security posture doesn’t matter much if they go bankrupt mid-contract. Financial due diligence doesn’t get the attention it deserves because it feels awkward - like asking someone how much money they have on a first date.

Do it anyway.

What to check:

  • Credit reports and ratings - Services like Dun & Bradstreet or CreditSafe provide standardized reports. A D&B PAYDEX score below 50 is a red flag
  • Revenue trends - Are they growing or shrinking? Consistent revenue decline signals trouble
  • Funding and capitalization - For startups, check runway. How many months of cash do they have?
  • Buyer concentration - If one buyer represents 40% of their revenue, losing that buyer could sink them
  • Insurance coverage - Do they carry adequate professional liability and cyber insurance?
  • Litigation history - Check PACER or local court records for pending lawsuits

Compliance verification beyond the certificate

SOC 2. ISO 27001. GDPR compliance. These three letters-and-numbers combinations show up on every vendor’s marketing page. But here’s what most people miss: a certificate tells you a vendor passed an audit at a specific point in time. It doesn’t tell you anything about today.

SOC 2 (Service Organization Control)
SOC 2 comes in two flavors. Type I says “we had controls in place on this date.” Type II says “we had controls in place and they worked over this period.” You’ll always want Type II. Always read the auditor’s opinion letter, not just the certificate. Look for qualified opinions or exceptions.

ISO 27001
ISO 27001 certification means a vendor’s got an information security management system (ISMS). Good. But the scope matters enormously. A company might certify their headquarters operations while their cloud infrastructure runs uncertified. Ask for the Statement of Applicability to see exactly what’s covered.

GDPR
There’s no such thing as “GDPR certified.” Anyone claiming GDPR certification is either confused or misleading you. What you can verify: Do they have a Data Protection Officer? Can they produce records of processing activities? Do they have a lawful basis for processing your data? Have they conducted a Data Protection Impact Assessment?

Risk scoring that drives decisions

Risk scoring without a clear system is just opinion with numbers attached. You need a method that’s repeatable and that different people in your organization won’t apply differently each time.

Here’s a scoring approach that works for most mid-market teams:

Step 1 - Classify vendor criticality

Tier Description Example
Critical Business stops if they fail Cloud infrastructure, payment processor
Important Major disruption if they fail HR platform, CRM, key supplier
Standard Inconvenient but manageable Office supplies, marketing tools
Low Minimal impact One-off contractors, niche tools

Step 2 - Score risk dimensions (1-5 scale)

  • Data sensitivity - What data do they access? PII gets a 5. Public marketing data gets a 1
  • Integration depth - API access to core systems scores higher than no integration
  • Regulatory exposure - Vendors in regulated activities (financial, health data) score higher
  • Geographic risk - Consider data sovereignty and political stability
  • Financial stability - Based on your financial assessment findings
  • Substitutability - How hard is it to replace them? Single-source vendors score high

Step 3 - Calculate composite score
Multiply criticality tier weight by average dimension score. Critical vendors get a 4x multiplier, Important gets 3x, Standard gets 2x, Low gets 1x.

Ongoing monitoring that catches problems early

This is where most vendor risk programs fall apart. The initial assessment gets done, everyone feels good, and then nobody looks at it again until the contract renewal. Meanwhile, the vendor’s CTO left, they had a quiet data breach they didn’t disclose, and their financial position deteriorated.

What to monitor continuously:

  • Security posture changes - Services like SecurityScorecard or BitSight provide continuous outside-in security ratings. They’re not perfect, but they catch obvious problems
  • News and regulatory actions - Set Google Alerts for vendor names plus terms like “breach,” “lawsuit,” “investigation,” “layoff”
  • Financial signals - Quarterly credit monitoring for critical vendors. Watch for late payments to their own suppliers
  • Compliance status - Track certification expiration dates. Re-verify annually at minimum
  • Performance metrics - SLA adherence, incident frequency, response times
  • Subprocessor changes - Vendors adding new subprocessors can change your risk profile overnight

Monitoring cadence by tier:

  • Critical vendors: Quarterly deep reviews, continuous automated monitoring
  • Important vendors: Semi-annual reviews, monthly automated checks
  • Standard vendors: Annual reviews
  • Low vendors: Review at contract renewal

Putting it all together

A vendor risk assessment template only works if it lives inside a process that people actually follow.
The minimum viable vendor risk process:

  1. New vendor request comes in with business justification
  2. Classify vendor tier based on data access and criticality
  3. Send appropriate security questionnaire (shorter for low-risk, longer for critical)
  4. Run financial stability checks
  5. Verify compliance certifications and scope
  6. Calculate risk score
  7. Route for approval based on score threshold
  8. Set up ongoing monitoring cadence
  9. Document everything in an auditable trail

Each of those steps should have an owner, a deadline, and a clear handoff to the next person. Not a shared spreadsheet. Not an email thread. It’s got to be a real workflow with accountability.

Feedback

Feedback we’ve received suggests that teams who run their vendor risk assessments as structured workflows in Tallyfy cut their assessment cycle time by more than half. Not because the work disappears, but because nobody’s chasing emails or wondering whose turn it is.