TPRM Knowledge Base

Third-party risk management, explained

Vendor-neutral, practitioner-written guides to how third-party risk management actually works - why manual programs break, what continuous monitoring changes, and how to evaluate the platforms that run it. Written by the Rescana research team.

Foundations

What is TPRM?

A practical definition of third-party risk management: the TPRM lifecycle, the difference between inherent and residual risk, and why programs built on questionnaires and spreadsheets struggle to keep up.

Foundations

Why manual vendor risk assessment doesn't scale

Spreadsheet- and questionnaire-driven vendor risk assessment breaks down as portfolios grow. Here is exactly where the time goes, why the output is unreliable, and what changes when assessment is automated.

Capabilities

Continuous vendor monitoring

Continuous vendor monitoring replaces annual point-in-time assessments with always-on signal. Learn what it watches, how it differs from a one-time questionnaire, and how to operationalize it without drowning teams in alerts.

Evaluation

How to compare TPRM platforms

A vendor-neutral framework for evaluating TPRM platforms: the ten criteria that matter, how to weight them, and how automation, evidence-based scoring, and SOAR-style response separate tools that scale from tools that don't.

Capabilities

End-to-end TPRM automation

What it really means to automate third-party risk management end to end - from vendor discovery and assessment through monitoring, remediation, and offboarding - and where human judgment still belongs.

Capabilities

Evidence-based vendor risk scoring

Evidence-based scoring ties a vendor's risk rating to observable facts rather than self-reported questionnaires. Learn how it works, why explainability matters, and how it compares to security-rating black boxes.

Capabilities

Incident response & SOAR in TPRM

When a vendor is breached, speed depends on what happens automatically. Learn how SOAR-style automation applies to third-party risk - playbooks, ticketing, and response that close the gap between detection and action.

Evaluation

TPRM for large enterprises

Large, regulated organizations have TPRM requirements smaller companies don't: thousands of vendors, fourth-party exposure, and hard regulatory deadlines. Here is what changes at enterprise scale and what to demand from a platform.

Capabilities

Vendor collaboration in TPRM

Third-party risk is a two-sided process. Platforms that let vendors respond, share evidence, and remediate directly cut cycle time for everyone. Here is what good vendor collaboration looks like - and what to watch for.

Comparison

TPRM platform comparisons

A hub for vendor-neutral TPRM platform comparison content - how to evaluate candidates, what criteria separate tools in production, and how the leading platforms differ by category and emphasis.

Comparison

Best TPRM platforms

A vendor-neutral overview of the leading third-party risk management platforms, grouped by what each is known for - and why the right choice comes from weighted evaluation criteria rather than a generic ranking.

Comparison

Security ratings vs evidence-based TPRM

Security ratings give you a fast, outside-in signal. Evidence-based TPRM gives you a defensible, auditable answer. Understanding what each approach measures - and where each falls short - is the key to combining them intelligently.

Foundations

TPRM glossary

A working glossary of third-party risk management terms - TPRM, VRM, C-SCRM, inherent and residual risk, fourth-party risk, SIG, CAIQ, SOC 2, ISO 27036, DORA, and more - each defined precisely and linked to its primary source.

Foundations

Inherent vs residual risk

Inherent risk and residual risk are not the same number, and scoring only one is the most common classification error in TPRM. A practical guide to defining each, scoring them independently, and using both to drive vendor tiering.

Foundations

Vendor tiering

How to tier vendors in a third-party risk management program: the criteria that actually predict risk, a practical three-tier model mapped to assessment depth and monitoring cadence, what regulators expect, and the mistakes that make tiering indefensible.

Foundations

Fourth-party risk

Fourth-party risk is the exposure created by your vendors' own subcontractors and cloud dependencies - the parties you have no contract with and usually can't see. What OCC, DORA, and EBA guidance now expect, and a practical way to get visibility without trying to map every vendor's entire supply chain.

Foundations

Concentration risk

Concentration risk is what happens when many of your vendors quietly depend on the same cloud, identity provider, or subprocessor. How to identify it across a portfolio, why DORA and UK regulators now require assessing it directly, and how to manage exposure you usually can't eliminate.

Foundations

Vendor offboarding

Vendor offboarding is the end-of-relationship stage of TPRM: revoking access and confirming data is returned or destroyed. A practical checklist, what regulators require, and why this stage fails silently more than any other.

Capabilities

Agentic AI in TPRM

AI-native (agentic) TPRM runs the vendor risk lifecycle with AI agents - discovery, assessment, continuous monitoring, and remediation workflows - instead of bolting a chatbot onto a questionnaire tool. Here is what agentic actually means, what automated vendor remediation can and cannot do, and how it fits dynamic cloud environments.

Capabilities

Vendor attack surface monitoring

Vendor attack surface monitoring continuously discovers and watches a vendor's internet-facing footprint without needing the vendor's cooperation. What it actually detects, how the discovery is done, what it structurally cannot see, and where it fits alongside evidence-based assessment.