TPRM Knowledge Base

Third-party risk management, explained

Vendor-neutral, practitioner-written guides to how third-party risk management actually works - why manual programs break, what continuous monitoring changes, and how to evaluate the platforms that run it. Written by the Rescana research team.

Foundations

Core concepts - what third-party risk management is, and how vendor risk is classified.

Foundations

What is TPRM?

A practical definition of third-party risk management: the TPRM lifecycle, the difference between inherent and residual risk, and why programs built on questionnaires and spreadsheets struggle to keep up.

Foundations

Why manual vendor risk assessment doesn't scale

Spreadsheet- and questionnaire-driven vendor risk assessment breaks down as portfolios grow. Here is exactly where the time goes, why the output is unreliable, and what changes when assessment is automated.

Foundations

TPRM glossary

A working glossary of third-party risk management terms - TPRM, VRM, C-SCRM, inherent and residual risk, fourth-party risk, SIG, CAIQ, SOC 2, ISO 27036, DORA, and more - each defined precisely and linked to its primary source.

Foundations

Inherent vs residual risk

Inherent risk and residual risk are not the same number, and scoring only one is the most common classification error in TPRM. A practical guide to defining each, scoring them independently, and using both to drive vendor tiering.

Foundations

Vendor tiering

How to tier vendors in a third-party risk management program: the criteria that actually predict risk, a practical three-tier model mapped to assessment depth and monitoring cadence, what regulators expect, and the mistakes that make tiering indefensible.

Foundations

Fourth-party risk

Fourth-party risk is the exposure created by your vendors' own subcontractors and cloud dependencies - the parties you have no contract with and usually can't see. What OCC, DORA, and EBA guidance now expect, and a practical way to get visibility without trying to map every vendor's entire supply chain.

Foundations

Concentration risk

Concentration risk is what happens when many of your vendors quietly depend on the same cloud, identity provider, or subprocessor. How to identify it across a portfolio, why DORA and UK regulators now require assessing it directly, and how to manage exposure you usually can't eliminate.

Foundations

Vendor offboarding

Vendor offboarding is the end-of-relationship stage of TPRM: revoking access and confirming data is returned or destroyed. A practical checklist, what regulators require, and why this stage fails silently more than any other.

Capabilities

How modern TPRM works: continuous monitoring, evidence-based scoring, automation, and remediation.

Capabilities

Continuous vendor monitoring

Continuous vendor monitoring replaces annual point-in-time assessments with always-on signal. Learn what it watches, how it differs from a one-time questionnaire, and how to operationalize it without drowning teams in alerts.

Capabilities

End-to-end TPRM automation

What it really means to automate third-party risk management end to end - from vendor discovery and assessment through monitoring, remediation, and offboarding - and where human judgment still belongs.

Capabilities

Evidence-based vendor risk scoring

Evidence-based scoring ties a vendor's risk rating to observable facts rather than self-reported questionnaires. Learn how it works, why explainability matters, and how it compares to security-rating black boxes.

Capabilities

Incident response & SOAR in TPRM

When a vendor is breached, speed depends on what happens automatically. Learn how SOAR-style automation applies to third-party risk - playbooks, ticketing, and response that close the gap between detection and action.

Capabilities

Vendor collaboration in TPRM

Third-party risk is a two-sided process. Platforms that let vendors respond, share evidence, and remediate directly cut cycle time for everyone. Here is what good vendor collaboration looks like - and what to watch for.

Capabilities

Agentic AI in TPRM

AI-native (agentic) TPRM runs the vendor risk lifecycle with AI agents - discovery, assessment, continuous monitoring, and remediation workflows - instead of bolting a chatbot onto a questionnaire tool. Here is what agentic actually means, what automated vendor remediation can and cannot do, and how it fits dynamic cloud environments.

Capabilities

Vendor attack surface monitoring

Vendor attack surface monitoring continuously discovers and watches a vendor's internet-facing footprint without needing the vendor's cooperation. What it actually detects, how the discovery is done, what it structurally cannot see, and where it fits alongside evidence-based assessment.

Capabilities

Automated evidence collection

Automated evidence collection replaces the manual chase for a vendor's SOC 2 report, ISO 27001 certificate, and questionnaire responses with continuous ingestion and validation against observable facts. What actually gets automated, what it structurally cannot do, and how it differs from a questionnaire.

Choosing a platform

Overview →

Vendor-neutral comparisons and a buyer's framework for evaluating TPRM platforms.

Frameworks & standards

Overview →

The standards and questionnaires that shape a TPRM program.

Frameworks

DORA and third-party risk

What DORA (Regulation (EU) 2022/2554) requires for ICT third-party risk: the Register of Information, key contractual provisions, concentration-risk assessment, subcontracting rules, and oversight of critical providers - mapped to concrete TPRM actions.

Frameworks

ISO/IEC 27036 explained

What ISO/IEC 27036 actually covers across its four parts - overview, requirements, hardware/software/services supply chain security, and cloud services - how it relates to ISO/IEC 27001 Annex A's supplier controls, and where it is worth citing directly in a TPRM program.

Frameworks

CSA CAIQ explained

What the Consensus Assessments Initiative Questionnaire (CAIQ) actually asks, how it maps one-to-one to the CSA Cloud Controls Matrix, where it sits inside the three levels of CSA STAR, and how it differs in practice from the Shared Assessments SIG.

Frameworks

SOC 2 in vendor assessment

How to read a SOC 2 report for vendor due diligence: Type I vs. Type II, the Trust Services Categories, the four sections that matter, complementary user entity controls, subservice organization scoping, and what SOC 2 does not verify.

Frameworks

NIST SP 800-161 (C-SCRM)

What NIST SP 800-161 actually asks an organization to do for cybersecurity supply chain risk management: the multilevel C-SCRM approach, the SP 800-53 SR control family, who it binds, and how it compares to DORA and NIS2.

Frameworks

NIST CSF 2.0 and third-party risk

What NIST Cybersecurity Framework 2.0's GV.SC category requires for supply-chain and third-party risk: all ten GV.SC subcategories, how they replaced CSF 1.1's ID.SC, and how the Quick-Start Guide (SP 1305) and SP 800-161 fit around them.

Frameworks

The SIG questionnaire explained

What the Shared Assessments Standardized Information Gathering (SIG) questionnaire actually covers, how SIG Core differs from SIG Lite, what changed in the 2025 and 2026 editions (AI-lifecycle content, ISO/IEC 42001), how the SIG relates to the SCA and to CAIQ, and how to use it without drowning vendors in an 800-question form.

Compliance & regulations

Overview →

How specific regulations translate into third-party obligations.

Compliance

NIS2 and supply-chain security

What NIS2 (Directive (EU) 2022/2555) requires for supply-chain and third-party security: who is in scope, the Article 21 supply-chain duty, management accountability, incident-reporting timelines, and penalties - turned into concrete TPRM actions.

Compliance

GDPR and third-party risk

What GDPR requires for vendors that process personal data on your behalf: the Article 28 processor contract, sub-processor authorization and flow-down, cross-border transfer rules, and breach-notification duties - turned into concrete TPRM actions.

Compliance

HIPAA and third-party risk

What HIPAA requires for vendors that handle protected health information: who counts as a business associate, what a BAA must contain under the Privacy and Security Rules, subcontractor flow-down, direct liability since the 2013 Omnibus Rule, and breach-notification duties - turned into concrete TPRM actions.

Compliance

PCI DSS and third-party risk

What PCI DSS actually requires for third-party service providers (TPSPs): the five sub-requirements of Requirement 12.8, the written-agreement and responsibility-matrix obligations, what Requirement 12.9 obligates a TPSP to hand back to its customers, and what counts as real evidence of compliance rather than a marketing claim.

Compliance

NYDFS Part 500 and third-party risk

What New York's cybersecurity regulation (23 NYCRR Part 500) requires of covered entities for their third-party service providers under Section 500.11: the required policy elements, the contractual protections, why the small-business exemption does not reach 500.11, and how the Section 500.17 breach clock covers a vendor's incident too.