Skip to main content
Category: Third-Party and Supply Chain

Third-Party Management

Also known as: TPRM, Vendor Risk Management, Third-Party Risk Management, Third-Party Vendor Management
Simply put

Third-party management is the process organizations use to oversee and manage their relationships with outside entities such as vendors, suppliers, and service providers. A closely related discipline, third-party risk management (TPRM), focuses specifically on identifying and reducing the risks that arise from using these external parties. Both aim to help an organization understand and control what could go wrong when it depends on others to support its operations.

Formal definition

Third-party management refers to the set of processes by which an organization oversees and governs relationships with external entities, including vendors, suppliers, and other service providers integrated into its operations or IT infrastructure. The closely associated practice of third-party risk management (TPRM) is a form of risk management concentrating on identifying, assessing, managing, and mitigating risks associated with the use of third parties, and is often codified in a third-party risk management policy that provides a structured framework for these activities. In practice, the scope, ownership, and rigor of these processes generally vary by organization, sector, and jurisdiction; the evidence provided does not specify accountability assignments (for example, whether responsibility sits with management, procurement, or a dedicated risk function), and this entry does not address related distinctions such as inherent versus residual third-party risk. This entry is educational and not legal, audit, or compliance advice.

Why it matters

Organizations increasingly depend on external vendors, suppliers, and service providers to support their operations and, in many cases, to run parts of their IT infrastructure. Because these third parties are integrated into the business, weaknesses or failures on their side can translate directly into disruptions, exposures, or losses for the organization that relies on them. Third-party management, and the more risk-focused discipline of third-party risk management (TPRM), exists to help an organization understand and control what could go wrong when it depends on others.

The significance of this discipline generally grows with the number and criticality of external relationships an organization maintains. A single vendor may touch sensitive data, deliver essential services, or sit deep within operational and technology dependencies, meaning that oversight is not a one-time procurement step but an ongoing process. Many organizations codify their approach in a third-party risk management policy that provides a structured framework for identifying, assessing, managing, and mitigating third-party risks.

The evidence provided does not specify particular incidents, statistics, or regulatory requirements, and the scope and rigor of third-party management generally vary by organization, sector, and jurisdiction. What remains consistent is the underlying rationale: reliance on outside parties introduces risks that an organization cannot fully control directly, so structured oversight is needed to make those risks visible and manageable. This entry is educational and not legal, audit, or compliance advice.

Who it's relevant to

Chief Risk Officers and Risk Functions
Because TPRM is a form of risk management focused on external parties, risk functions are typically concerned with how third-party risks are identified, assessed, managed, and mitigated across the organization's relationships. The evidence does not specify where accountability formally sits, so the practical division of responsibility generally depends on the organization's own structure.
Chief Compliance Officers
Compliance leaders often have an interest in how third-party relationships are governed, particularly where a structured third-party risk management policy sets out expectations. The scope and applicability of any requirements generally vary by sector and jurisdiction, which the evidence provided does not detail.
Procurement and Vendor Management Teams
Teams that monitor and manage day-to-day interactions with vendors and suppliers are central to third-party management processes. How this operational role connects to broader risk oversight typically depends on the organization's design, which the evidence provided does not specify.
Boards and Audit or Risk Committees
Directors and their committees generally have an oversight interest in how significant third-party dependencies and risks are managed, without owning the operational execution. The extent of board involvement typically varies by organization and the criticality of the relationships involved.
Internal Auditors and Assurance Providers
Assurance functions may examine whether third-party management processes and any governing policy operate as intended. The evidence provided describes the framework at a conceptual level and does not address distinctions such as control design versus operating effectiveness, which auditors would typically consider separately.

Inside TPRM

Third-Party Inventory and Segmentation
A maintained record of external parties (vendors, suppliers, agents, distributors, service providers, and other counterparties) through which an organization operates, typically segmented by criticality or risk tier so that oversight effort can be proportionate to the exposure each relationship presents. Segmentation criteria vary by organization and sector.
Risk-Based Due Diligence
The pre-engagement and periodic assessment of a third party's financial condition, operational capacity, compliance posture, ownership, and integrity risks. The depth of due diligence generally scales with the assessed risk of the relationship; enhanced due diligence is typically reserved for higher-risk parties such as those in sanctioned or corruption-prone contexts.
Contractual Controls
Provisions embedded in agreements that allocate responsibilities and enable oversight, such as audit and information rights, compliance representations, subcontracting restrictions, service levels, data protection obligations, and termination triggers. Contract terms are a governance mechanism but do not by themselves demonstrate that controls operate effectively.
Ongoing Monitoring
Continued surveillance of a third party's performance and risk profile over the life of the relationship, which may include periodic re-assessment, performance reviews, screening against sanctions and adverse media, and monitoring of concentration or financial-health indicators. Monitoring is distinct from one-time onboarding due diligence.
Roles and Accountability
The allocation of responsibility across the organization. Business or relationship owners in the first line typically own and manage third-party relationships and their risks; second-line risk and compliance functions generally set policy, provide challenge, and aggregate reporting; internal audit provides independent assurance; and the board or a designated committee exercises oversight of the overall program, particularly for material outsourcing or concentration risk.
Termination and Exit Management
Planning for the orderly wind-down, transition, or replacement of a third party, including data return or destruction, transition of services, and continuity arrangements. Exit planning is generally emphasized for critical or hard-to-substitute relationships.

Common questions

Answers to the questions practitioners most commonly ask about TPRM.

Is third-party management the same as vendor procurement or sourcing?
No. Procurement and sourcing focus on selecting suppliers and negotiating commercial terms, whereas third-party management is the broader, ongoing discipline of identifying, assessing, monitoring, and governing the risks a third party poses across the relationship lifecycle. Procurement is typically one input to third-party management, but the two are not interchangeable. In many organizations, procurement sits within a business or operations function, while risk assessment and ongoing monitoring involve risk, compliance, and control owners. The precise allocation of these responsibilities depends on the entity's structure, sector, and governance model.
Does completing due diligence at onboarding mean a third party has been adequately managed?
Not on its own. Onboarding due diligence is generally a point-in-time assessment, and third-party risk can change over the life of a relationship as circumstances, ownership, performance, or the risk environment evolve. Third-party management typically contemplates ongoing monitoring, periodic reassessment, and defined offboarding, not a single upfront check. Treating due diligence as a one-time event, rather than as part of a continuous process, is a common misconception. The appropriate frequency and depth of ongoing monitoring generally depend on the risk the third party presents and any applicable jurisdictional or sector expectations.
How should an organization decide how much scrutiny a given third party warrants?
Most programs apply a risk-based, tiered approach so that scrutiny is proportionate to the risk a relationship presents rather than applied uniformly. Factors commonly considered include the nature of the services, access to data or systems, criticality to operations, regulatory sensitivity, and geographic or sector exposure. Higher-risk relationships typically receive more extensive due diligence and more frequent monitoring, while lower-risk ones receive lighter treatment. The specific tiering criteria and thresholds are a matter of the organization's own judgment, risk appetite, and any applicable requirements, and they should be documented and applied consistently.
Who is accountable for third-party risk within an organization?
Accountability is generally distributed rather than held by a single function. The business relationship owner typically owns the day-to-day management and performance of the third party as a first-line responsibility. Risk and compliance functions generally provide oversight, set standards, and challenge, consistent with a second-line role, while internal audit or another assurance function may provide independent assurance over the program's design and operating effectiveness. The board or a relevant committee typically retains oversight of significant third-party or concentration risks. The exact allocation depends on the organization's operating model and any applicable frameworks; outsourcing an activity does not generally transfer the underlying accountability.
How can an organization keep third-party monitoring current after onboarding?
Ongoing monitoring is typically operationalized through a combination of periodic reassessments timed to a third party's risk tier, defined trigger events that prompt review, performance and service-level tracking, and processes for capturing changes such as ownership, control environment, or regulatory status. Some organizations supplement internal review with external information sources. Maintaining an accurate inventory of third parties and their risk classifications is generally a prerequisite for effective monitoring. The appropriate mix and cadence of these activities depend on the risks involved and the resources and judgment of the organization; this entry describes common practices rather than a prescribed standard.
What role does contract design play in third-party management?
Contracts typically serve as a mechanism to translate risk expectations into enforceable obligations, addressing matters such as scope, service levels, information and audit rights, security and confidentiality expectations, subcontracting, and termination or exit provisions where relevant. Well-designed contract terms can support monitoring and remediation, but they do not substitute for ongoing management, since the existence of a clause does not by itself confirm it is being met. Specific contractual provisions vary by relationship, sector, and jurisdiction, and drafting is a matter for qualified legal advice. This entry is educational and does not constitute legal, audit, or compliance advice.

Common misconceptions

Outsourcing an activity to a third party transfers the associated risk and accountability away from the organization.
Delegating an activity generally does not transfer accountability. In many jurisdictions and under common supervisory expectations, the contracting organization remains responsible for outcomes, and its board and management retain oversight duties regardless of who performs the work.
A signed contract with strong compliance clauses means the third-party risk is controlled.
Contractual terms represent control design, not operating effectiveness. Whether obligations such as audit rights or compliance covenants are actually exercised and honored must be verified through ongoing monitoring and, where appropriate, independent assurance.
Due diligence completed at onboarding is sufficient for the life of the relationship.
Third-party risk profiles change over time as ownership, financial condition, performance, and external circumstances shift. Onboarding due diligence is typically a starting point that should be supplemented by periodic re-assessment and ongoing monitoring proportionate to risk.

Best practices

Maintain a current inventory of third parties and segment it by criticality and risk so oversight effort is proportionate to exposure.
Calibrate due diligence to assessed risk, reserving enhanced procedures for higher-risk relationships rather than applying uniform depth to all parties.
Embed audit and information rights, compliance representations, and clear termination triggers in contracts, and periodically test whether those rights are actually exercised.
Establish ongoing monitoring that revisits risk periodically over the relationship life cycle rather than relying solely on onboarding assessments.
Define and document roles so that first-line business owners manage relationships, second-line functions set policy and provide challenge, and the board or a committee oversees material exposures and concentration risk.
Develop exit and continuity plans for critical or hard-to-substitute third parties, addressing service transition and data handling before disruption occurs.