# What is Third-Party Risk Management (TPRM)?

> Third-party risk management is the governance discipline that identifies, assesses, contracts for, and monitors the security risk introduced by vendors, suppliers, and partners across the relationship lifecycle.

- Canonical URL: https://yellowcube.eu/glossary/third-party-risk-management/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

TPRM covers onboarding due diligence, security requirements in contracts, evidence review (certifications, attestations, penetration results), access and data-sharing boundaries, incident-notification duties, monitoring for deterioration, and orderly exit. It applies the same lifecycle whether the third party is a SaaS tool, an MSP, or a component supplier.

### Key points

- **Risk-tiered effort:** A vendor handling critical data or holding privileged access deserves deeper assurance than the office plant service — match scrutiny to the risk the relationship actually carries.
- **Contracted controls:** Security duties, audit or evidence rights, breach-notification windows, subcontractor flow-downs, and exit/data-return terms must exist in writing before reliance begins.
- **Important limitation:** Assessments and attestations are point-in-time evidence about a supplier, not continuous proof. Questionnaires reflect what vendors claim; certifications scope what was examined — neither substitutes for monitoring the actual connection and data flows.

### Related terms

[Third-party cyber risk](<https://yellowcube.eu/glossary/third-party-cyber-risk/>) · [Supply-chain security](<https://yellowcube.eu/glossary/supply-chain-security/>) · [Service-level agreement (SLA)](<https://yellowcube.eu/glossary/service-level-agreement/>) · [Cyber insurance](<https://yellowcube.eu/glossary/cyber-insurance/>) · [Compliance automation](<https://yellowcube.eu/glossary/compliance-automation/>)

### Sources

[NIST SP 800-161 Rev. 1, Cybersecurity Supply Chain Risk Management Practices](https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final) · [NIST IR 8276, Key Practices in Cyber Supply Chain Risk Management](https://csrc.nist.gov/pubs/ir/8276/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

