Third-party risk management borrows its vocabulary from a handful of standards and regulations that were not written together and do not use consistent terms. A "framework" in this space can mean a binding EU regulation with named contractual clauses, an ISO standard that is guidance rather than a certificate, or a vendor questionnaire that happens to be industry-standard. Knowing which is which - and what each actually obligates you to do - is the difference between a program that cites a framework correctly and one that just name-drops it.
What this cluster covers
DORA and third-party risk
The EU's Digital Operational Resilience Act is the most prescriptive third-party regime in force today: a Register of Information every in-scope financial entity must maintain, a pre-contract concentration-risk assessment, a named list of contractual clauses (with an enhanced set for critical or important functions), and direct EU oversight of the ICT providers designated most systemically important. Binding law, not guidance - and it reaches non-EU providers through the contracts financial entities sign with them.
ISO/IEC 27036 explained
The ISO standard written specifically for supplier-relationship security, in four parts covering concepts, requirements, hardware/software/services supply chain, and cloud services. It is implementation guidance that sits underneath ISO/IEC 27001 Annex A's five supplier controls (5.19-5.23) rather than a certificate of its own - the practical answer to "what do we actually do" once 27001 tells you supplier risk is in scope.
CSA CAIQ explained
The Cloud Security Alliance's Consensus Assessments Initiative Questionnaire maps one question to each of the 197 control objectives in the Cloud Controls Matrix, and underpins the three assurance levels of CSA STAR - self-assessment, ISO 27001-based certification, and SOC 2-based attestation. A cloud provider answers it once and can publish the result for every prospective customer to check, which is why it is worth looking for before sending a bespoke questionnaire.
How the pieces relate
Two useful distinctions cut across all three. First, binding law versus voluntary standard: DORA is a regulation with fines attached (Article 34); ISO/IEC 27036 and the CAIQ/CCM are standards a program adopts because they are useful, not because a regulator requires that specific document. Second, certification versus guidance versus questionnaire: ISO/IEC 27001 and CSA STAR Certification/Attestation are things an auditor certifies against; ISO/IEC 27036 is guidance with no equivalent accredited certificate; the CAIQ and the Shared Assessments SIG are self-reported questionnaires that a certification can corroborate but not replace.
In practice these stack rather than compete. A cloud vendor supporting a critical function for an EU bank might need to satisfy DORA's Article 30 contractual baseline, hold ISO/IEC 27001 certification whose Annex A 5.19-5.23 controls are implemented per ISO/IEC 27036 Parts 2-4, and publish a current CAIQ response (or STAR Certification) that the bank's TPRM team checks against the vendor's actual attack surface rather than taking at face value. None of the three duplicates the others; each closes a different gap.
Where sector-specific rules fit
Some regimes govern a single sector's third-party obligations rather than a general standard - NIS2, for the wide range of sectors it designates as essential or important entities, is the first of these to publish in this cluster, with more sector regimes planned. Read a sector regulation for the legal duty and its penalties, and a framework or questionnaire on this page for how to actually operationalize the controls it asks for.
Where to start
If a regulator or auditor named a specific framework, start there and work outward - map its requirements to your existing inventory (vendor tiering) and evidence process (evidence-based scoring) rather than building a separate compliance exercise beside your normal program. If nothing has been named yet, ISO/IEC 27001 with 27036 as its supplier-control implementation guide is the most sector-neutral place to anchor a new program, with sector- or region-specific regimes layered on top as they apply.
Frequently asked questions
What frameworks and standards apply to third-party risk management?
The frameworks that come up most often fall into three categories: binding regulations with named third-party obligations (DORA for EU financial entities, NIS2 for a broad set of EU essential and important entities), certifiable management-system standards (ISO/IEC 27001, whose Annex A includes five supplier-relationship controls), and implementation guidance or questionnaires that operationalize those controls (ISO/IEC 27036 for supplier relationships generally, the CSA CAIQ and Cloud Controls Matrix for cloud providers specifically, and the Shared Assessments SIG for third parties broadly). Most programs answer to a combination rather than a single framework, and the practical task is mapping each one's specific requirement to a concrete action in your existing vendor inventory and assessment process.
How do DORA, ISO/IEC 27036, and the CSA CAIQ fit together in a TPRM program?
They operate at different layers and are not substitutes for one another. DORA is binding EU law for financial entities that specifies a Register of Information, pre-contract concentration-risk assessment, and named contractual clauses. ISO/IEC 27036 is implementation guidance for the supplier-relationship controls that ISO/IEC 27001 Annex A requires but does not itself spell out. The CSA CAIQ is a self-reported questionnaire, corroborated by CSA STAR certification or attestation, that documents a cloud provider's controls against the Cloud Controls Matrix. A vendor can be subject to all three at once: DORA sets the legal contractual floor, 27036 shapes how the supplier-relationship controls behind an ISO 27001 certificate are actually run, and the CAIQ or STAR status gives a reusable, checkable record of the cloud-specific controls in between.
Which TPRM framework should a program start with?
Start with whichever framework a regulator, customer, or auditor has already named - map its specific requirements to your vendor inventory and evidence process rather than running a parallel compliance exercise. Absent a named requirement, ISO/IEC 27001 with ISO/IEC 27036 as its supplier-control implementation guide is the most sector-neutral foundation, since its Annex A controls (5.19-5.23) map closely onto 27036's own parts. Layer sector- or region-specific regimes - DORA for EU finance, NIS2 for a wide range of EU essential and important entities - on top once you know which apply, since each adds legally binding specifics a general ISO framework does not cover on its own.