top of page

Search Results

Search this site

506 results found with an empty search

Blog Posts (117)

  • Build Yourself, Build Your Program: A TPRM Career Guide for the Age of AI

    Every few years a profession gets a moment where the ground shifts and the people who read it early pull away from the people who wait. Third party risk management is in one of those moments right now. The pressure is easy to feel and hard to name, so let me name it plainly: the part of your job that is easiest to automate is the part most programs still spend most of their time on. This is not a threat to fear. It is a map. It tells you exactly where to stop investing your career, and exactly where to start. The rest of this blog will discuss that map. Not the technology for its own sake, but what it means for how you should be building yourself and your program over the next two years. The skill that is quietly losing its value For most of our careers, questionnaire throughput was a real skill. Knowing the frameworks very well, moving assessments through the pipeline, keeping the register current, chasing third parties for responses. People built reputations on being fast and thorough at this, and they deserved to. That skill is depreciating, and the reason is simple. A third party can now generate a flawless questionnaire response in twenty minutes with an AI model. You can review it in twenty seconds with another one. When both sides automate the exchange of claims, the exchange stops carrying information. The output is fast, polished, confident, and empty. If your professional value is anchored to moving that exchange efficiently, your value is anchored to the one thing the technology just commoditized. This is uncomfortable to say out loud, and I say it because the practitioners who hear it early have time to move, and the ones who hear it late do not. The good news is that the skills replacing questionnaire throughput are more interesting, more durable, and far harder to automate. Where the value is moving Think of the modern TPRM skill set in three horizons. What you should acquire now, what you should build in parallel, and what you should aim to own over the next two to three years. This is as true for how you develop yourself as it is for how you develop your program. Acquire now: evidence literacy and AI judgment. The single highest-leverage move available to you is learning to read for evidence instead of attestation. That means reading a SOC 2 for the findings that hide outside the exceptions table, the complementary user entity controls that are quietly your obligations, and the subservice carve-outs that are a fourth-party map printed inside the report. It means telling the difference between a control that is enforced and one that is merely available, a distinction that lives in configuration exports, not questionnaires. And it means knowing where AI genuinely helps in your workflow and where it fails, so you can use it without being fooled by it. None of this requires a technical background. All of it requires unlearning the habit of treating a filled-in form as an answer. Build in parallel: governance and monitoring design. As volume rises and headcount stays flat, the analyst's job shifts from doing assessments to governing how they get done. That means designing which controls receive human review and which can be AI-accepted with spot-checks, documenting overrides in a way that survives an examiner, and building monitoring that fires on real signals instead of the calendar. Your assessment cycle takes weeks; public breach disclosure now averages well over a hundred days. Annual reassessment was never going to close that gap. The practitioners who can design event-driven monitoring, and defend it, become indispensable. Own long-term: program architecture and business translation. The most durable skills are the ones furthest from automation: designing an AI-augmented program from the ground up, and translating technical findings into the language a Chief Financial Officer (CFO) or a board risk committee will act on. These are the capabilities that turn a senior practitioner into a program leader, and they compound every year you hold them. Building the program, not just the résumé Everything above is also a blueprint for the program you are responsible for, because your career and your program advance through the same moves. Start by asking the question most programs never ask out loud: why does our program actually exist? Is it funded by regulatory mandate, by customer and market pressure, or by genuine conviction that the program prevents real losses? The honest answer shapes everything. A program that can only demonstrate documentation is now competing against infinitely cheap documentation and losing. A program that can demonstrate prevented loss has no such competition. If you cannot point to a single incident your program caught that would have cost the business real money, then the value of your program is reduced. This is the most important thing on your roadmap, not another questionnaire integration. Then, you will want to point your technology investments at evidence rather than attestations. The wave of automation has currently meant "faster questionnaires", which points current investments to the least informative part of the process. The programs that will matter most are shifting the object of automation from what a third party says to what can be observed: from documents to query-able data, from attestation to configuration, from annual cycles to continuous signals. And when you evaluate any AI-assisted tool, hold it to a standard of auditability. When an examiner asks you to reconstruct one decision, can the tool show the inputs, the model version, the citations, and the human who signed off? Most cannot. That question is the best filter you have for separating serious platforms from confident demos. Why this is bigger than our function The reason this deserves real attention, from you and from your leadership, is that delegated trust has become the largest attack surface most enterprises have. Companies outsource more of what they do every year. Every third party relationship, every integration, every AI agent granted standing access is a delegation of trust and an extension of the attack surface. The incidents that defined recent years were not perimeter failures; they were trust failures, a compromised build pipeline, a stolen integration token, a socially engineered supplier help desk. Enterprise resilience now rests on third party risk in a way it simply did not a decade ago. That is the opportunity hiding inside the disruption. A function that was often treated as a compliance cost center is becoming central to whether an organization can withstand the failure of the many parties it depends on. The practitioners who build the evidence-first skills, and the programs built on them, are the ones who will be in the room when it matters. Where to start this quarter Preparation does not require permission or budget. Pick your three most critical third parties and write down, honestly, what you actually know about their security posture versus what they attested. That gap is your starting point. Read the scope section of your next SOC 2 yourself, not the AI summary. Run one assessment you did manually through an AI tool and study where it agreed, missed, and surprised you. Build the habit of collecting one piece of observable evidence per critical third party per quarter. Small, unglamorous, and compounding. This conviction is why we built the "TPRM in the Age of AI" series with TPRA. Module 1, AI and the Future of Third-Party Risk, lays out what is changing and why, from first principles, and closes with concrete actions you can take this week and this quarter. Module 2, The Practitioner's Skill Stack, is the hands-on training for the evidence-first skills above: reading the artifacts, running AI with discipline, and designing monitoring that works. Both are CPE-eligible through the TPRA training platform. They exist to help you make exactly the moves this article describes. The questionnaire era is ending, and that is good news for anyone willing to build. The work ahead is not to fill out the form faster. It is to become the practitioner, and to build the program, that can tell whether the form was ever true. Start now, while it is still early. Being early is the whole advantage. Author Bio Clarence Chio Cofounder and CEO of Coverbase Clarence Chio is cofounder and CEO of Coverbase and has taught AI and security at UC Berkeley since 2019. He is the instructor for the "TPRM in the Age of AI" professional development series, available through TPRA. Coverbase is one platform for third-party risk and security, with AI that tailors to your program and controls and continuously evaluates every surface of exposure.

  • What TPRM Practitioners Need to Know About the IIA’s New Third-Party Topical Requirement

    A New Requirement Takes Effect September 15, 2026 On September 15, 2026, the Institute of Internal Auditors’ (IIA) new Third-Party Topical Requirement goes into effect, establishing a consistent, mandatory framework for internal auditors conducting assurance engagements that involve third party management (TPRM). For TPRM practitioners, the requirement provides greater clarity into what internal audit may examine and the types of practices, controls, and evidence organizations should be prepared to demonstrate. The IIA has published two core documents: Third-Party Topical Requirement – Provides the mandatory baseline of requirements internal auditors must follow when performing assurance engagements on third party management. Third-Party Topical Requirement User Guide – Provides guidance for implementing the requirement, including examples of evidence and controls internal auditors may consider. Additional information is available on the IIA Third-Party Topical Requirement resource page. Unlike a regulatory or industry-specific standard, the requirement establishes principles that can be applied across organizations and industries. Many align with existing regulatory guidance and established TPRM practices, while others extend beyond traditional TPRM activities into areas such as sourcing decisions and contract performance monitoring. Why This Matters: A Professional Perspective I’ve worked in third party and vendor risk management for more than 20 years, working with more than 100 organizations across financial services, healthcare, pharmaceuticals, energy, and other highly regulated industries. That experience has given me the opportunity to see TPRM programs at very different stages of maturity, as well as how the audits evaluating those programs have changed over time. Audits that once focused more narrowly on vendor due diligence and basic controls have expanded to examine how organizations govern third party relationships, manage risk across the lifecycle, and demonstrate that their processes are working as intended. The IIA’s new Third-Party Topical Requirement reflects much of that evolution. It also brings greater attention to several challenges I’ve encountered across organizations and industries over the years. With that perspective, here’s what TPRM practitioners should know about the new requirement, along with five areas that I believe deserve particular attention as organizations prepare. What the Topical Requirement Is The Third-Party Topical Requirement is a mandatory component of the IIA’s International Professional Practices Framework. When internal auditors perform an assurance engagement that addresses third party management, whether as part of a planned engagement or because third party risk becomes relevant during an audit, they are required to use the Topical Requirement as their framework. Each audit will still reflect the professional judgment, scope, and priorities of the team conducting it, but the requirement provides a consistent foundation from which to work. What Auditors Will Be Looking For The Topical Requirement contains 17 requirements organized into three categories: governance, risk management, and controls. Each category has defined criteria, supported by the User Guide with examples of evidence auditors may consider. Third Party Governance, 4 Requirements Governance focuses on whether the organization has a formalized approach to third party management. This includes documented policies and procedures covering the full lifecycle of the relationship, clearly defined roles and responsibilities, and communication protocols that keep appropriate stakeholders informed. Third Party Risk Management, 4 Requirements Risk management focuses on whether risk practices are standardized and comprehensive throughout the lifecycle. This includes how the organization identifies, assesses, prioritizes, and responds to third party risks, how issues are escalated and managed when they arise, and how risk information flows to leadership and oversight bodies. Third Party Controls, 9 Requirements Controls focus on operational execution throughout the lifecycle, including sourcing, due diligence, contracting, onboarding, monitoring, corrective action protocols, and offboarding. The requirements also address maintaining a complete, accurate, and current inventory of third party relationships, an area that can present practical challenges when third parties enter an organization through multiple channels. Five Areas That Deserve a Closer Look Based on my experience with TPRM programs across industries and at different stages of maturity, there are five areas I would pay particular attention to when preparing for the new requirement. 1. Lifecycle-Based Framework Across organizations, third party management frequently spans multiple business functions, each with its own policies, processes, systems, and responsibilities. That can make it difficult to create a cohesive view of third party management across the enterprise. The requirement calls for a formalized, documented approach that spans the full third party lifecycle. Organizations should consider whether activities across functions are sufficiently coordinated and whether policies, procedures, and responsibilities support a consistent enterprise approach. 2. Accurate, Documented Procedures Policies and procedures don’t always mature at the same pace. In many programs I’ve worked with, policies benefit from formal approval and regular review cycles, while the procedures supporting them may receive less attention over time. Procedures should clearly define roles, accountability, and documentation requirements and accurately reflect how the organization operates today. That review is particularly important as processes and technologies change, including the adoption of AI-enabled solutions. 3. Communications and Reporting Reporting can remain difficult even for well-established TPRM programs. Often, what appears to be a reporting problem begins further upstream with the quality and consistency of the underlying data. When third party data is captured by different functions without consistent fields, definitions, ownership, or collection practices, maintaining accurate and complete reporting becomes more difficult. Practitioners should consider both their reporting capabilities and the quality of the data supporting those reports. 4. Risk Domains Beyond Cyber Another pattern that has emerged over the years is the significant attention given to cybersecurity within third party risk programs. Regulatory requirements and established information security ownership have helped make cyber a well-defined component of TPRM in many organizations. The Topical Requirement, however, addresses a much broader set of risks, including strategic, reputational, financial, legal, operational, and geopolitical risks. Organizations should consider whether these additional risk domains have appropriate ownership, assessment processes, and oversight within the broader third party management framework. 5. Accurate Third Party Inventory Maintaining an accurate third party inventory continues to be a practical challenge for many organizations. One reason is structural: third parties may enter through procurement, accounts payable, corporate cards, or direct relationships established by individual business units. When those channels are not connected to a consistent process or system of record, gaps in the inventory can result. Organizations should evaluate whether they have clearly defined ownership, consistent processes for identifying and recording third parties, and a reliable system of record for third party relationships. What TPRM Practitioners Can Do Now The IIA has provided internal auditors with a clear framework to work from. For TPRM practitioners, preparation can focus on three things: Understand what's expected. Read the Topical Requirement and User Guide to understand the policies, practices and evidence auditors will look for. Evaluate your scope of operations. Focus on things you are responsible for within the third party management lifecycle and be honest about where you stand today. Coordinate with cross-functional peers. For those things outside your scope but within the Topical Requirement, work with your peers who own those activities to ensure responsibilities are clear, documented, and coordinated. Auditors will want to see a unified approach, not disconnected functions operating independently. The new requirement does not mean every element of third party management needs to sit within the TPRM function. It does mean organizations should be able to demonstrate how responsibilities and activities work together across the lifecycle. Starting that review now gives practitioners an opportunity to understand their current state, identify areas that may need attention, and coordinate with the other functions responsible for third party management before the requirement takes effect. Author Bio Tom Rogers Founder and CEO of Vendor Centric Tom Rogers is the Founder and CEO of Vendor Centric, a professional services firm that works exclusively with third-party and vendor management leaders to build, improve, mature and run their programs. With over 20 years in the field, Tom has worked with over 100 clients across financial services, healthcare, pharma, energy, and other highly regulated industries. He brings a practical, real-world perspective to helping leaders build operations that don't just hold up under scrutiny but actually deliver value. Tom and his team built a free self-assessment tool that maps to all 17 standards within the IIA’s Third-Party Topical Requirement. It takes about 15-20 minutes to complete and gives you an interactive gap analysis as soon as you’re done, along with a downloadable report you can share with the colleagues you’ll need to work with to close the gaps. You can access the tool here. You can connect with Tom on LinkedIn or reach him at trogers@vendorcentric.com.

View All

Other Pages (383)

  • VIRTUAL CONFERENCE | TPRA

    Join TPRA’s free 2025 Virtual Conference on September 10 to explore continuous improvement in Third Party Risk Management. Attend expert-led sessions, earn CPE credits, and enhance your TPRM strategy. 2026 Virtual Conference Emerging Risks & Operational Resiliency Wednesday, September 9, 2026 • 9:00 AM - 4:00 PM Central Open to All • Free • 6 CPE Credits Available Register Now Join the Third Party Risk Association (TPRA) for our 2026 Virtual Conference: " Emerging Risks & Operational Resiliency " on Wednesday, September 9 , 2026, from 9:00 AM to 4:00 PM CT . What to Expect As organizations navigate an increasingly complex risk landscape, this conference will explore the latest emerging threats—from evolving regulatory expectations to third party vulnerabilities and operational disruptions. Attendees will gain actionable guidance on strengthening resilience, enhancing risk frameworks, and proactively addressing uncertainties that can impact business continuity. Through expert-led sessions, participants will leave better equipped to anticipate challenges, adapt to change, and build more robust, future-ready organizations. Who Should Attend? This conference is ideal for: TPRM professionals seeking to enhance their programs Risk management and compliance officers Procurement and vendor management specialists IT and cybersecurity professionals involved in third party risk Whether you’re focused on third-party risk, enterprise risk, or operational continuity, this event offers valuable perspectives and tools to help you stay ahead in a rapidly shifting environment. Register Now TRACK 1 Driving Resilience Through Continuous Improvement TRACK 2 Driving TPRM Transformation Through Innovation TRACK 3 Navigating Emerging Risks & Regulatory Change Agenda Fliter by: Track 8:55 AM - 9:00 AM 5 minutes View Full Session Presentation Welcome & Kick-Off Julie Gaiaschi, CEO & Co-founder, TPRA Zoom Lobby General Session Kick off this virtual conference with a few words from Julie Gaiaschi , CEO & Co-founder… Read More 9:00 AM - 9:50 AM 50 minutes View Full Session Presentation From Headlines to Action - Managing Geopolitical Risk Across Third-Party Ecosystems Sandeep Suresh, Supply Wisdom Room 1 Track 1: Driving Resilience Through Continuous Improvement Geopolitical events no longer impact only global enterprises—they can disrupt organizations of every size through… Read More 9:00 AM - 9:50 AM 50 minutes View Full Session Presentation A New Can of Worms: Why Compliance Alone Can't Contain a Zero-Cost Adversary Richard Hummel, SecurityScorecard Room 2 Track 2: Driving TPRM Transformation Through Innovation Compliance frameworks are built on an assumption that no longer holds: that adversaries need time,… Read More 9:00 AM - 9:50 AM 50 minutes View Full Session Presentation Beyond the Checklist: Building a Unified Third-Party Control Framework Jan Stappers, LL.M., PgD EVP, GRC Solutions Strategy, Mitratech Room 3 Track 3: Navigating Emerging Risks & Regulatory Change The TPRM landscape has become a maze of overlapping mandates, standards, and stakeholder expectations, and… Read More 10:00 AM - 10:50 AM 50 minutes View Full Session Presentation Continuous Monitoring That Improves Oversight Ken Wolckenhauer, Nordea Bank Room 1 Track 1: Driving Resilience Through Continuous Improvement Turning on risk monitoring and alert feeds is easy but turning them into better decisions… Read More 10:00 AM - 10:50 AM 50 minutes View Full Session Presentation Moving at Attacker's Speed: How to Rethink TPRM for the Post-Mythos Era Jake Olcott, Bitsight Room 2 Track 2: Driving TPRM Transformation Through Innovation Third-party risk management was built for a slower world. Today, organizations face a growing volume… Read More 10:00 AM - 10:50 AM 50 minutes View Full Session Presentation Gaining c-suite acceptance of emerging risks: regulation is your friend Rachel Elliott, DRI Room 3 Track 3: Navigating Emerging Risks & Regulatory Change Navigating emerging supply chain risks is becoming evermore complex, particularly with events become concurrent. The… Read More 11:00 AM - 11:50 AM 50 minutes View Full Session Presentation The Risk You Reviewed Isn’t the Risk You Have Natalie Druckmann, Certa Room 1 Track 1: Driving Resilience Through Continuous Improvement The third-party risk function is caught between two converging threats and most programs are equipped… Read More 11:00 AM - 11:50 AM 50 minutes View Full Session Presentation Staying One Step Ahead: Why Intelligence Is Replacing Traditional Third-Party Risk Management Austin Starowicz, RiskRecon Room 2 Track 2: Driving TPRM Transformation Through Innovation Cybersecurity isn't becoming more difficult because organizations have more vendors—it's becoming more difficult because adversaries… Read More 11:00 AM - 11:50 AM 50 minutes View Full Session Presentation The Risks Beyond the Hype: Operational Resilience, Hidden Financial Exposure, and the Next Frontier of TPRM Courtney Turner, Deere & Co Room 3 Track 3: Navigating Emerging Risks & Regulatory Change As organizations race to manage AI-related risks, other emerging threats are quietly gaining momentum. This… Read More 12:00 PM - 1:00 PM 60 minutes View Full Session Presentation Lunch Meal Take a break to enjoy some lunch before jumping back into learning with our next… Read More 1:00 PM - 1:50 PM 50 minutes View Full Session Presentation Your Vendor Didn’t Change, But Its AI Did: Rethinking Material Change in TPRM Brian Shaw, Independent Room 1 Track 1: Driving Resilience Through Continuous Improvement A third party may remain under the same contract while quietly changing its models, data… Read More 1:00 PM - 1:50 PM 50 minutes View Full Session Presentation When Risk Evolves, Agility Wins: AI Transforms Third-Party Risk Management Bryn Sedlacek, Aravo Room 2 Track 2: Driving TPRM Transformation Through Innovation Today's TPRM programs must support resilient operations, secure IT, ethical business practices, regulatory compliance, and… Read More 1:00 PM - 1:50 PM 50 minutes View Full Session Presentation Third-Party Risks and Sanctions Michael Volkov, Volkov Law Group Room 3 Track 3: Navigating Emerging Risks & Regulatory Change With the beginning of the aggressive trade enforcement era, companies need to focus on third-party… Read More 2:00 PM - 2:50 PM 50 minutes View Full Session Presentation Fourth-Party Risk: The Exposure You Can’t Always See Tracey Forney, previously Sr Information Security Manager with Federal Reserve Room 1 Track 1: Driving Resilience Through Continuous Improvement Dependencies on sub-contractors and upstream providers can introduce risk that is not obvious from primary… Read More 2:00 PM - 2:50 PM 50 minutes View Full Session Presentation We Don’t Know What We Don’t Know: The Inherent Risk of Mature TPRM Paul Valente, VISO TRUST Room 2 Track 2: Driving TPRM Transformation Through Innovation A vendor assessment can be thorough and defensible while still missing the risk that matters.… Read More 3:00 PM - 3:50 PM 50 minutes View Full Session Presentation The AI-Enabled Vendor: Building a Third-Party AI Risk Assessment Aligned to NIST AI RMF Nitin Agarwal, Luminace Room 1 Track 1: Driving Resilience Through Continuous Improvement Third-party vendors are rapidly embedding generative and agentic AI into the services organizations already consume,… Read More 3:00 PM - 3:50 PM 50 minutes View Full Session Presentation Beyond the AI Hype: What’s Actually Working in Third-Party Risk Management Sophia Corsetti, ProcessUnity Room 2 Track 2: Driving TPRM Transformation Through Innovation AI has produced no shortage of demos, claims, and new terminology. But after the initial… Read More 2:00 PM - 2:50 PM 50 minutes View Full Session Presentation From Finding to Fixing: Managing Third-Party Issues, Exceptions & Performance Kholofelo Mothibi, Corebride Financial Room 3 Track 3: Navigating Emerging Risks & Regulatory Change Identifying a vendor risk is only the beginning. The real test of a TPRM program… Read More 3:50 PM - 4:00 PM 10 minutes View Full Session Presentation Conference Conclusion Julie Gaiaschi, CEO & Co-founder, TPRA Zoom Lobby General Session We will close out this event with a few announcements and drawings for raffle prizes! Speakers Apply to Speak Courtney Turner Enterprise Third Party Risk Manager Deere & Co Paul Valente Co-founder & Chief Customer Officer VISO TRUST Richard Hummel VP, Threat Intelligence SecurityScorecard Brian Shaw Third-Party Risk & Compliance Executive Independent Ken Wolckenhauer Head of Vendor Management Nordea Bank Maxine Ayers Director Operational Risk Management Corebridge Financial Kholofelo Mothibi Head of TPRM Corebridge Financial Natalie Druckmann VP, Head of EMEA Certa.ai Sandeep Suresh Managing Director Supply Wisdom Sophia Corsetti Sr Product Marketing Manager ProcessUnity Nitin Agarwal Director Enterprise AI & Risk Luminace Tracey Forney previously Sr Information Security Manager Federal Reserve Bryn Sedlacek VP, Product Management Aravo Solutions, Inc Michael Volkov CEO The Volkov Law Group PC Austin Starowicz Director, Solutions Consulting Mastercard Cybersecurity Rachael Elliott Director of Global Strategy and Innovation DRI International Jake Olcott VP Government Affairs Bitsight Jan Stappers LL.M., PgD EVP, GRC Solutions Strategy Mitratech Prevalent Julie Gaiaschi CEO & Co-founder Third Party Risk Association (TPRA) Thank you to our Sponsors ! Interested Sponsors Be sure to visit their virtual booths during the event!

  • TPRA – Third Party Risk Management Resources, Certification & Networking

    Join the TPRM community at TPRA for expert resources, training, templates, and tools to strengthen your third party risk program and grow your network. Join the only not-for-profit, vendor-agnostic professional association uniting thousands of TPRM professionals worldwide. Furthering the profession of third party risk management through knowledge-sharing & networking. Learn More Join Now The all-in-one source for Third Party Risk Management (TPRM) tools, templates, training, networking, certifications & industry best practices. MEMBERSHIP CONNECT & DISCOVER Individuals & organizations working together to advance the industry. More > EDUCATION MEETINGS & TRAINING Certifications & training for risk professionals to advance their careers & enhance their programs. More > RESOURCES INFORMATION SHARING SITE White papers, templates, guidance & more to enhance your program. More > TOOLS & AUTOMATION EXPLORE & CONTACT Detailed profiles of trusted TPRM service provider organizations & their offerings. More > Advance Your Career in Risk Management: Learn About the Benefits of TPRA Membership > Practitioner Plans Standard: FREE Premium: $199/yr BENEFITS Member Meetings Interactive monthly calls to discuss a variety of third party risk topics decided upon by members. Conferences In-person and virtual conferences dedicated solely to third party risk topics. Networking Online interaction with your peers through membership forums and document databases. Industry-Specific Meetings Quarterly special interest calls based on your industry. Demos, Surveys, Webinars Access to third party risk management service provider demos, surveys, & webinars. Certifications TPRM professional certifications that establish credibility and demonstrate your commitment to mastering your skills and knowledge within the industry. Join Now Vendor Plans 4 available plans starting at $8,000/yr BENEFITS Priority & Discount Sponsorship Opportunities Be the first to sponsor conferences and receive discounted member rates, as well as priority positioning. Networking & Collaboration Attend monthly and quarterly meetings with TPRM practitioners and other service providers to network, collaborate, create resources, share insights, and more! Promotional Opportunities Work with the TPRA staff to communicate to Practitioner Members the your organization's webinars, surveys, demos, blog posts, and white papers. Advisory Councils Join our TPRM Service Provider Advisory Council, as well as other groups, dedicated to collaborating, sharing insights, and providing strategic guidance. Quarterly Updates Receive quarterly updates with industry innovators to collaborate on practitioner needs. Join Now Meetings Open to All Meetings Open to All Member Meetings & Events On-Demand Meetings Wednesday, September 23, 2026 9:00 AM – 12:00 PM CT Consultant Showcase Register > Friday, September 25, 2026 12:00 – 4:00 PM CT AI for TPRM Professionals Register > Monday, October 5, 2026 5:00 – 8:00 PM CT TPRMP October Training & Exam Bundle Register > Monday, October 5, 2026 5:00 – 8:00 PM CT TPRMP October Training Only Register > CONTACT US OUR INFORMATION Address: P.O. Box 824 Ankeny, Iowa 50021 USA Email: info@tprassociation.org For any general inquiries, please fill out the contact form. First name* Last name* Email* Subject* Message* Yes, subscribe me to TPRA communications. Submit

  • TPCRA | TPRA

    The Third Party Cyber Risk Assessor (TPCRA) Certification validates your expertise in assessing third party cybersecurity controls, advancing your career in third party risk management. Third Party Risk Association's Third Party Cyber Risk Assessor (TPCRA) Certification The TPCRA Certification is a specialized qualification that validates expertise in assessing third-party cybersecurity controls, managing cyber risk assessments, and evidencing proficiency in cybersecurity assessment techniques, as well as establishing credibility for third-party risk management professionals. Register Now By clicking this button, you will be redirected to our Training & Certification Platform (Inspire360). Your TPRA website login credentials will not work on Inspire360, and a separate account is required to register for & access courses. What is the TPCRA? The TPCRA Certification is a specialized qualification designation which will: Confirm your understanding & skill in the assessment of third party cyber security controls and processes. Validate your competency in the creation, execution, & management of third party cyber risk assessments. Authenticate & add credibility to your expertise as a third party cyber risk assessor. Evidence your proficiency with various cyber security & information technology assessment terms & techniques. About TPCRA Register Domains Pricing Examination Overview Training Schedule FAQs Who is the TPCRA for? The TPCRA is the standard of achievement for those who assess, monitor, and review third party cyber security and information technology controls, as well as identify and mitigate risk related to said controls. Such roles may include, but not be limited to: Third Party Risk Management Practitioners Procurement Specialist Vendor Managers Auditors Information Security Professionals Privacy or Compliance Specialists Legal Professionals "The TPCRA Certification is foundational to achieving success as a third party risk management professional." Domains Building Core Competencies for Lasting Professional Excellence Cybersecurity & Third Party Risk Management Basics Pre-Contract Due Diligence Continuous Monitoring Physical Validation Disengagement Due Diligence Cloud Due Diligence Reporting & Analytics Practitioner Ethics Pricing Register Now Where will this button take me? Item TPRA Standard, Vendor, & Non-Members TPRA Premium Practitioner Members Examination $500 $425 Training $400 $340 Examination & Training Bundle $800 $700 Examination Retake Fee $200 $200 Certification Renewal $100 $85 Examination Overview Examination Outline The examination is a 150-question, multiple-choice assessment. Questions will include a variety of formats, such as scenario-based, true or false, and choose the best response. The time limit is 3 hours for the examination process, broken out into the following: 5 minutes to read and sign the NDA 10 minutes to complete the optional tutorial 160 minutes to complete the examination 5 minutes to complete the post-exam survey The examination is a closed-book assessment that will be monitored via an assigned proctor. Passing Score You must receive a score of 80% or higher to pass the TPCRA examination. Exam Scheduling The examination will be taken in person at a Pearson VUE testing facility. Examinations may be scheduled at a day/time that suits you via a Pearson VUE location. Pearson VUE offers over 5,000 test facilities worldwide and is ADA-compliant. Training Schedule SESSION DATE TIME LOCATION REGISTER TPCRA On-Demand Training Only REGISTER TPCRA On-Demand Training & Exam Bundle REGISTER TPCRA 4-Day November Training Only 11/16/2026 5 PM - 8 PM CT REGISTER TPCRA 4-Day November Training & Exam Bundle 11/16/2026 5 PM - 8 PM CT REGISTER PLEASE NOTE: When you click "Register" above, you will be redirected to our Training & Certification Platform ( Inspire360 ). Your TPRA website login credentials will not work on Inspire360, and a separate account is required to register for and access courses. Learn more on our FAQ page . " I thought the training was fantastic. I've been a TPRM practitioner for nearly 7 years now and still walked away with new knowledge and insight. I am so proud of the TPRA and honored to be a part of the board! " Nicole Makinney Product Owner, Third Party Risk | McKesson TPCRA Training Attendee TPCRA Frequently Asked Questions General TPCRA Information About TPCRA Certification TPCRA Requirements TPCRA Examination TPCRA Training Maintaining Your TPCRA Certification Examination Outline Certification Eligibility Criteria Certification Pricing TPCRA Training Instructor Certification Renewal Registration Certification Process Training Need Help? Visit our Support page for Frequently Asked Questions and, if that doesn't work, key contacts to reach out to for further assistance. Support & FAQs →

View All
bottom of page