Search Results
Search this site
495 results found with an empty search
Blog Posts (114)
- Budgeting for TPRM Success
If you've worked in third party risk management (TPRM) for any length of time, you know budget season rarely gets easier. Third party populations continue to grow. Business units expect reviews to move faster. Regulations continue to evolve, and AI has introduced new considerations into third party due diligence. Regulators have also made something else clear. Effective TPRM requires appropriate staffing, expertise, governance, and ongoing oversight. Leadership is responsible for ensuring those resources are available. The challenge, of course, is that leadership can't fund what it doesn't understand. It's up to TPRM leaders to demonstrate where the program stands today, where the gaps exist, and what resources are needed to support the business. That's where a well-built budget becomes one of the most important tools in your program. Start with Actual Spending Before building next year's budget, understand where this year's money actually went. Last year's approved budget is only part of the picture. Actual spending often tells a different story. Software renewals increase. A hiring freeze leaves a key position vacant longer than expected. An unplanned third party event requires outside expertise. Break spending into broad categories such as: Technology and software Outsourced assessments Staffing Training and certifications Consulting and audit support Some of these costs may be buried inside shared enterprise budgets, so partnering with finance early can save hours of reconstruction. Once you've organized the numbers, identify the largest variances. Those differences often reveal where the program is changing and provide the strongest justification for next year's request. Pro Tip: Compare at least two years of actual spending. Trends usually tell a stronger story than a single year's variance. Measure the Gaps The next question is whether your program is keeping pace with demand. Has your third party population grown? Are reassessments staying on schedule? Has your backlog increased? Are business units waiting longer for reviews? Are the risk domains you are assessing covering the right risks? If you aren't tracking these metrics yet, start now, even if it's only in a spreadsheet. Whenever possible, convert the problem into numbers. If third party growth resulted in forty additional assessments this year, estimate the effort required to support that increase. Finance can evaluate measurable impacts much more easily than general statements about workload. Quick Check How many third parties were added this year? What's your average assessment turnaround time? Where is your largest backlog? Which bottleneck would disappear first if your budget were approved tomorrow? How Does Your Program Compare? Every organization has different priorities, but it helps to understand where other TPRM programs are investing. According to KPMG's 2026 Global Third Party Risk Management Survey of 851 organizations, the top investment areas are risk assessments and due diligence (52%), TPRM technology (51%), cybersecurity and data protection (49%), and regulatory audits (45%). More than 80% of organizations outsource at least part of their TPRM activities, while only 17% reported having fully reliable TPRM data. These findings aren't a blueprint for your budget, but they provide a useful benchmark. Pro Tip: If your investment priorities look very different from your peers, be prepared to explain why. Sometimes there's a good reason and being able to articulate it to leadership is essential. Think about it this way... What level of third party risk does the organization need to manage, and what people, technology, intelligence, and assurance capabilities are required to manage it effectively? AI Is Expanding the Scope of TPRM AI is becoming part of more third party products every month, including products many organizations already use. As a result, existing third party relationships now require additional scrutiny. Questions about training data, model governance, customer information, and contractual protections have become routine parts of due diligence. Many organizations also expect AI to reduce costs and staffing needs. That expectation has largely outpaced reality. According to KPMG's survey, only 22% of organizations rated their AI initiatives as very effective. Finance may expect efficiency gains that haven't materialized, while TPRM teams face additional review work. Budget for the resources needed to support that growth. Budget Checklist Update AI due diligence questionnaires. Review AI-specific contract language. Invest in team training. Consider managed services or specialized expertise. Evaluate tools that improve assessment efficiency. Headcount May Not Be the Only Answer When workloads increase, it's easy to assume another team member is the answer. Sometimes that's true. Sometimes the real issue is an inefficient process, a technology gap, or the need for specialized skills. Before requesting another position, step back and identify what's actually slowing the program down. You can also ask which TPRM activities are consuming human capacity without requiring human judgement. Then consider all of the available options. Improve or redesign an existing workflow. Use capabilities already available in your technology stack. Automate repetitive administrative tasks. Outsource TPRM processes such as due diligence document collection or reviews Bring in part-time contractors during peak periods. Share platforms or subscriptions with Procurement, Information Security, or Compliance to reduce total cost of ownership. If another employee is still the right solution, you'll have a much stronger business case because you've already evaluated the alternatives. Pro Tip: Before requesting another FTE, ask whether the problem is capacity, process, technology, skills, or temporary workload. The answer will help you determine which investment will drive the improvement you need. Don't Overlook the Small Line Items Some of the easiest budget items to miss are also the ones most likely to create problems later. Recurring costs often increase over time, and one-time projects have a way of becoming recurring if they aren't clearly identified. Spending a little extra time reviewing your assumptions now can prevent mid-year surprises. Commonly Forgotten Budget Items Platform renewals and licensing increases Team training and certifications AI-specific assessment tools or questionnaire updates Fourth-party risk initiatives One-time consulting or implementation projects Pro Tip: Separate one-time investments from recurring operating expenses. It makes future budgeting easier and helps finance understand your long-term costs. Separate Needs from Nice-to-Haves Few organizations receive everything they request. Before budget discussions begin, decide which investments are essential and which would simply improve the program. Those decisions are much easier to make before you're sitting across the table from finance. A simple prioritization exercise can save time later. Must Have Regulatory or contractual obligations Minimum staffing requirements Critical platform renewals Required operational activities Reasonable Due Diligence capacity to support the business Nice to Have Additional reporting capabilities New dashboards Premium platform features Nice efficiency improvements that can wait another budget cycle Pro Tip: Ask yourself one question: If finance approved only half of this request tomorrow, what would stay? If you know that answer before the meeting, you're already ahead of the conversation. Build a Business Case, Not Just a Budget Budgets are approved because they support business objectives, not because a department needs more money. Rather than focusing on workload, explain what the investment enables the business to accomplish. Support your request with measurable outcomes whenever possible. For example: Improve supplier onboarding. If assessments currently take 90 days and your goal is 60, estimate how many projects or contracts could move forward 30 days sooner. Reduce operational risk. Estimate the potential impact of a supplier disruption, delayed implementation, or security incident, then compare it to the cost of earlier detection through stronger due diligence and monitoring. Strengthen regulatory readiness. If audit findings or manual processes require recurring remediation, estimate the effort required to address those issues today versus preventing them in the future. Support business growth. If the organization expects significant third party growth, estimate the additional assessment workload and show how your request will help maintain service levels and avoid backlogs. The stronger your data, the stronger your business case. Third party growth, assessment volumes, turnaround times, backlog trends, and remediation effort all provide objective evidence that leadership can evaluate. Pro Tip: Don't ask for more money. Ask for the ability to deliver a measurable business outcome. Keep Tracking Throughout the Year Budget season shouldn't be the only time you look at your numbers. Review spending throughout the year and compare actual expenses against your budget. Track trends such as assessment volume, cost per assessment, outsourced versus internal work, and unexpected costs resulting from third party incidents. Those metrics become the starting point for next year's budget instead of forcing you to rebuild the story from memory. Track These Metrics Quarterly Budget versus actual spending Third party growth Assessment turnaround time Assessment backlog Cost per assessment Outsourced versus internal work Final Thoughts No organization gets every budget request approved. The goal isn't to win every budget discussion. The goal is to build a request that's grounded in data, tied to business priorities, and realistic about where the program needs to grow. Organizations that consistently track workload, spending, and performance throughout the year rarely start from scratch when budget season arrives. They already have the data to explain where resources are needed and how those investments support the business. Budgeting is never just about the numbers. It's about demonstrating that your program understands its risks, knows where it needs to improve, and has a practical plan for getting there. Author Bio Hilary Jewhurst Sr. Membership & Education Coordinator at TPRA Hilary Jewhurst is a seasoned expert in third party risk and risk operations, with nearly two decades of experience across financial services, fintech, and the nonprofit sector. She has built and scaled third party risk programs from the ground up, designed enterprise-wide training initiatives, and developed widely respected content that helps organizations navigate regulatory complexity with clarity and confidence. Known for turning insight into action, Hilary’s thought leadership and educational work have become go-to resources for professionals looking to mature their TPRM programs. She regularly publishes articles, frameworks, and practical guides that break down complicated risk topics into meaningful, accessible strategies. Hilary recently joined the Third Party Risk Association (TPRA) as a staff member, supporting industry-wide education, peer learning, and advancing best practices. She is also the founder of TPRM Success, a boutique consultancy that helps organizations strengthen their third party risk management capabilities through targeted training, tools, and strategic guidance.
- Sanctions and Third Party Risk: What Every TPRM Practitioner Should Know || TPRM Exchange Podcast – Episode 4
Sanctions compliance may traditionally sit with legal, trade compliance, or another specialized function, but it has direct implications for third party risk management. A prohibited relationship can expose an organization to blocked transactions, frozen payments, regulatory enforcement, financial penalties, operational disruption, and reputational damage. In this episode of the TPRM Exchange, host Hilary Jewhurst speaks with Michael Volkov of The Volkov Law Group about how sanctions apply to third parties, where sanctions risk appears throughout the lifecycle, and what practitioners can do to build a practical and defensible process. Sanctions Risk Does Not Stop at the Border One of the most common—and potentially costly—misunderstandings is that U.S. sanctions no longer apply when a transaction is routed through an entity outside the United States. As Volkov explains, a U.S. company cannot avoid its sanctions obligations simply by working through a third party in another country. “The risk continues from wherever you’re located. If you’re a U.S. person or a U.S. company, it continues through your third parties, no matter where they are located.” — Michael Volkov Sanctions may target particular activities, individuals, entities, industries, or entire countries. Regardless of the specific program, the practical question for an organization is whether it is permitted to conduct business or complete a financial transaction with the party involved. Screening Should Begin During Onboarding Sanctions issues can emerge at several points in the third party lifecycle, but onboarding is the most important place to establish a control. Before a vendor, supplier, customer, distributor, or other third party is entered into an organization’s master database or approved for payment, the party should be screened. Building screening into the existing approval workflow allows the organization to identify potential issues before a contract is signed, goods are shipped, or money changes hands. Waiting until a bank blocks a payment puts the organization in a much more difficult position. By that point, goods may already have been delivered, contractual commitments may have been made, and funds may be frozen while the parties investigate. The Entity Name Is Only the Beginning Screening the contracting entity is an essential first step, but it may not reveal the full risk. Organizations may also need to examine the company’s beneficial owners, officers, directors, or other principals. Under certain sanctions rules, an entity can be treated as blocked when one or more sanctioned persons own 50% or more of it—even if the entity itself does not appear by name on a sanctions list. Ownership structures can also obscure the individuals who ultimately control or benefit from a company. When an initial screen produces a red flag, practitioners may need to gather additional ownership information and work with legal or compliance specialists to determine whether the relationship is permissible. Sanctions Exposure Extends to Nth Parties The conversation also highlights the importance of looking beyond direct contractual relationships. Sanctioned goods, materials, entities, or individuals may appear several levels down a supply chain or later in a distribution channel. Volkov uses supply chain and transshipment examples to illustrate how an organization can face liability even when it does not directly contract with the sanctioned party. Risk may arise when prohibited materials enter the supply chain through a subcontractor or when a distributor redirects a product to a sanctioned destination. Managing that exposure may require: Risk-based supply chain due diligence Appropriate sanctions and trade-compliance clauses End-use and end-user controls Supplier representations and certifications Supply chain audits Escalation procedures for geographic or ownership concerns The appropriate level of diligence will depend on the organization’s products, markets, geographic reach, distribution model, and overall exposure. Build Forward Instead of Trying to Fix Everything at Once Organizations implementing formal sanctions screening may discover that hundreds or thousands of existing third parties have never been screened. That does not mean the program must resolve the entire backlog before introducing an effective control. “You’re not going to boil the ocean over this. We don’t have time for that, nor the resources.” — Michael Volkov A more manageable approach is to establish a clear implementation date and screen every new third party from that point forward. The organization can then address its existing population using a risk-based plan. Higher-priority reviews may include third parties with: Operations in higher-risk countries or regions Significant organizational spend or revenue Exposure to known transshipment locations Complex or unclear ownership structures Access to regulated products, technology, or services Roles deeper within critical supply or distribution chains This approach allows the organization to establish a consistent control immediately while addressing historical exposure in a deliberate, defensible order. Screening Is Not a One-Time Activity A third party that passes screening today may be added to a sanctions list tomorrow. Sanctions designations can change quickly in response to geopolitical events, national security concerns, criminal activity, or changes in government policy. Automated screening platforms can help by retaining screened parties and issuing alerts when a party’s status changes. Organizations without an automated tool may begin with available government screening resources or seek assistance from qualified legal or compliance professionals, but manual screening becomes harder to sustain as international activity grows. Regardless of the technology used, the process should define: Who is screened When screening occurs Which lists and data sources are used How potential matches are reviewed Who can clear or reject a match How decisions are documented How active relationships are monitored When issues must be escalated The tool supports the control, but it does not replace a clear workflow and accountable decision-making. TPRM Does Not Have to Own the Process—but It Must Understand It Sanctions screening may be performed by compliance, legal, procurement, trade compliance, sustainability, or another team. Organizational structures vary, and there is no single operating model that works for every company. However, TPRM practitioners should understand how the process works even when another function owns it. They should know who makes sanctions decisions, what tools or information that team uses, what evidence confirms that screening occurred, and how an issue is escalated. That knowledge is necessary to explain the organization’s controls to business stakeholders, auditors, examiners, and leadership. It also prevents gaps between functions—particularly when onboarding involves several teams with different approval responsibilities. Compliance Must Be Positioned as a Business Partner Business stakeholders may view sanctions screening as another obstacle standing between them and a time-sensitive transaction. Volkov recommends approaching those conversations as a partner focused on helping the business proceed safely. The message should be straightforward: involve the appropriate risk and compliance teams early, and they can identify concerns, explore permissible options, and help prevent transactions from being blocked later. TPRM and compliance teams should also establish reasonable turnaround expectations. A well-designed screening process should support timely decision-making while ensuring that unresolved red flags do not pass unnoticed into the vendor master or payment process. When an Existing Supplier Triggers an Alert If a long-term supplier appears on a sanctions notice, the organization must act promptly. The immediate response should generally include pausing business and financial activity, notifying the appropriate internal stakeholders, and investigating the alert. The organization should contact the third party for an explanation while legal or trade-compliance personnel determine whether the notice is accurate and whether the relationship can lawfully continue. Contracts and purchase orders should contain sanctions-compliance language that supports the organization’s ability to suspend or terminate prohibited activity. These protections are particularly important when a designation occurs in the middle of a transaction or during a multiyear agreement. Practitioners should not assume that every alert establishes a confirmed violation. False positives and explainable matches occur. Nevertheless, activity should not resume until qualified personnel have reviewed the issue and documented a defensible decision. Two Practical Priorities Volkov closes with two primary actions for practitioners: Implement a sanctions-screening capability that supports onboarding and continued monitoring. Provide annual sanctions training to employees whose responsibilities may bring them into contact with sanctions-related issues. Training does more than communicate rules. It creates an opportunity for employees to raise questions, describe emerging business activities, and identify transactions or relationships that might otherwise remain outside the risk team’s view. Ultimately, effective sanctions compliance depends on visibility, defined ownership, appropriate technology, and cooperation across the organization. By embedding screening into onboarding, monitoring active relationships, accounting for beneficial ownership and nth parties, and responding quickly to alerts, TPRM practitioners can help protect the organization while still enabling the business to move forward.
- Beyond Third Parties: Eight Actions to Tackle Fourth‑ and Nth‑Party Risk
If you spend enough time in third party risk, you’ll notice something unfair. Your third parties have their own third parties, and when those downstream providers fail, your organization still feels the impact, even though you never signed a contract with them. This leads to a common question: “How are we supposed to manage those third parties?” The short answer is that you don’t manage them directly. Instead, you focus on reducing the risks that come with these extended relationships. Fourth- and nth-party risk means knowing where these downstream dependencies are, how their failures could disrupt your services or affect your customers, and making sure your TPRM program identifies, analyzes, and reduces those risks where it matters most. Who is a 4th or nth party? In third party risk management (TPRM), “third party” usually means any external organization or supplier under contract to deliver a product, service, or process. That is the part everyone is used to tracking. A “fourth party” is any provider your third party relies on. These can be cloud platforms, sub‑processors, subcontractors, and upstream suppliers that sit behind the scenes but can still disturb your operations, affect your customers, or negatively impact your compliance posture when something goes wrong. “Nth‑party risk” is the more general term for the additional layers beyond that, including the third parties supporting those fourth parties and further out in the chain. Taken together, this extended chain of third, fourth, and nth parties is part of what many practitioners now refer to as extended enterprise risk, the risks that arise across the wider network of external relationships that support your organization’s products and services. Why fourth- and nth-party risks are getting attention Fourth- and nth-party relationships are getting more attention because shared dependencies are now easier to see. For example, one cloud platform, KYC provider, or infrastructure service can affect several third parties at once, turning a single incident into a disruption across multiple services. Regulators and boards are also asking more specific questions about sub‑processors, concentration risk, and resilience. Once you accept that fourth and nth‑party relationships can materially affect your organization, the next question is what to do about it in practice. You cannot manage every downstream provider directly, but you can absolutely design a TPRM program that properly addresses fourth‑ and nth‑party risk. Here are eight practical actions you can take to help your organization more effectively identify, analyze, and mitigate those extended‑ecosystem risks. 1: Determine How Far You Will Go If you try to map your whole supply chain, you’ll end up with too much information and little value. It’s usually better to set clear criteria for what’s in scope, like access to customer data, critical services, or when the same downstream provider is used by several third parties. Start by deciding how deep you are willing to go. A reasonable standard for many programs is your direct third parties, plus their critical sub‑processors and major shared platforms that would materially affect your business if disrupted. Make sure your final decision is reviewed and documented. If someone asks why a certain downstream provider is included or not, you should be able to explain it easily. 2: Know How to Identify Your 4th And Nth Parties After you decide how deep to look, the next step is finding those downstream entities. Some third parties will give you a clear list of sub-processors, but many will not. A practical way to do this is to gather information from several sources: SOC 2 Type II reports, especially the system description and subservice organization sections. External risk intelligence tools that map hosting providers, DNS, IP ranges, and technology stacks. Public trust centers and compliance pages that list sub‑processors or infrastructure partners. Regulatory or industry disclosures that reference key providers. Internal insight from Architecture, Security, and Operations teams that already know which shared platforms sit underneath important services. You are not trying to build an exhaustive inventory. You are trying to identify the downstream relationships that can materially impact your operations, customers, compliance, or reputation. 3: Think In Terms of Fourth‑Party Failure and Concentration When you look past your direct third parties, it helps to break fourth-party risk into two simple questions. Fourth‑party failure risk Start with a single third party and ask, “What if one of their critical fourth parties fails?” For that third party: Which fourth‑party providers are critical to the service they deliver to you? What parts of your operations stop working if one of those fourth parties has an outage or incident? How quickly would the third party detect and communicate that issue to you, and who owns the response on your side? What options exist if that fourth party is unavailable for an extended period (alternate providers, workarounds, manual processes)? This approach keeps the focus on a specific relationship: your third party, their key fourth party, and how it affects your organization. Fourth‑party concentration risk Then step back and ask, “How many of our third parties rely on the same fourth parties?” Across your third party portfolio: Which fourth‑party providers appear repeatedly in different third party relationships? How many critical services in your inventory ultimately depend on the same fourth‑party cloud, KYC, payments, or messaging provider? Are there specific fourth‑party entities that, if impaired, would create issues across multiple third parties at once? Here, you’re mapping shared fourth-party dependencies across your third parties . The result should be a short list of fourth-party providers and the services or third parties they support, so leadership can see where the biggest exposures are. By looking at fourth-party failure risk for each third party and concentration risk across your whole portfolio, you get a clearer view of where extended-ecosystem risk is acceptable and where you need to focus more attention. 4: Understand How Your Third Parties Manage Their Third Parties Since you can’t manage all your third parties’ third parties, one of your best controls is making sure your third parties have strong TPRM practices themselves. This means asking if your third parties identify and rank their own third parties, separate critical providers from less important ones, do proper due diligence, and monitor those relationships over time. Third parties with mature TPRM programs are more likely to spot their own dependencies, catch issues early, and alert you to important problems. If your third party does a weak job managing its own supply chain, you inherit that weakness. If they are disciplined about risk tiers, due diligence, and ongoing monitoring, you gain a layer of protection and visibility you could not create on your own. 5: Build Visibility into the TPRM Lifecycle It’s easier to manage downstream risk when you include it in your existing processes, instead of tracking it separately in a spreadsheet. This can be as simple as asking the right questions or gathering key information at each stage of the lifecycle: Risk Assessment: Identify your critical products and services and focus on their sub processors. Due Diligence: Ask third parties about material sub‑processors and critical upstream services during due diligence. Record those entities in your third party/supplier record so they can be tracked over time. Contracting: Ensure clauses cover disclosure of critical sub-processors and notifications when they change. Monitoring: Update the record when sub‑processors change, new dependencies appear, or incidents affect key downstream providers. Exit: Capture what you learned about the third party’s downstream footprint and use it in future assessments. By including fourth- and nth-party oversight in your regular processes, you create consistent risk checkpoints and collect data that helps you make better decisions. 6: Contract For Downstream Control You might not have contracts with fourth- or nth-party entities, but you do have contracts with your third parties who rely on them. That’s where you have leverage. Useful terms include the requirement to disclose material sub‑processors, notice before changes, flow‑down obligations for security and resilience, incident notification when a sub‑processor issue affects your service, and independent assurance where appropriate. You obviously can’t dictate how someone else’s third party or supplier program operates. You can hold your third parties accountable for managing their own downstream relationships in line with your risk expectations. 7: Use Risk Alerts and Threat Intelligence for Key Downstream Providers You don’t need a contract with a downstream provider to keep an eye on public risk information about them. Risk alert services, external monitoring platforms, and threat intelligence feeds use public and open-source data, making them helpful for key nth-party relationships. For higher-impact downstream entities, you can monitor domains, infrastructure, leaked credentials, breach chatter, major vulnerabilities, and other warning signs. This monitoring won’t replace good third party management, but it gives you another way to spot issues with important shared providers. This is especially useful when a downstream provider supports several third parties in your environment. In these cases, a single alert can tell you more than multiple questionnaires. 8: Embed Downstream Risk into Governance Fourth- and nth-party risk management works best when it’s included in the same governance channels as your other key risks. This could mean including shared dependencies in outsourcing discussions, resilience reports, third party portfolio reviews, and contract playbooks. When it’s part of regular reporting and oversight, it becomes a normal part of your program instead of a special topic. Conclusion Fourth- and nth-party risk falls somewhere between your third parties’ responsibilities and your own. You can’t control every downstream provider, but you also can’t ignore how those relationships might affect your organization and your customers. The eight actions in this blog are designed to give you a practical starting point. If you pick a few and add them to your program, you’ll get better visibility into the downstream relationships that matter most and a more consistent way to manage their risks. You don’t have to solve everything at once. Focus on bringing the right extended relationships into view and handling them with processes you can explain, repeat, and improve over time. That’s what real progress on fourth- and nth-party risk looks like in a TPRM program. Author Bio Hilary Jewhurst Sr. Membership & Education Coordinator at TPRA Hilary Jewhurst is a seasoned expert in third party risk and risk operations, with nearly two decades of experience across financial services, fintech, and the nonprofit sector. She has built and scaled third party risk programs from the ground up, designed enterprise-wide training initiatives, and developed widely respected content that helps organizations navigate regulatory complexity with clarity and confidence. Known for turning insight into action, Hilary’s thought leadership and educational work have become go-to resources for professionals looking to mature their TPRM programs. She regularly publishes articles, frameworks, and practical guides that break down complicated risk topics into meaningful, accessible strategies. Hilary recently joined the Third Party Risk Association (TPRA) as a staff member, supporting industry-wide education, peer learning, and advancing best practices. She is also the founder of TPRM Success, a boutique consultancy that helps organizations strengthen their third party risk management capabilities through targeted training, tools, and strategic guidance.
Other Pages (375)
- VIRTUAL CONFERENCE | TPRA
Join TPRA’s free 2025 Virtual Conference on September 10 to explore continuous improvement in Third Party Risk Management. Attend expert-led sessions, earn CPE credits, and enhance your TPRM strategy. 2026 Virtual Conference Emerging Risks & Operational Resiliency Wednesday, September 9, 2026 • 9:00 AM - 4:00 PM Central Open to All • Free • 6 CPE Credits Available Register Now Join the Third Party Risk Association (TPRA) for our 2026 Virtual Conference: " Emerging Risks & Operational Resiliency " on Wednesday, September 9 , 2026, from 9:00 AM to 4:00 PM CT . What to Expect As organizations navigate an increasingly complex risk landscape, this conference will explore the latest emerging threats—from evolving regulatory expectations to third party vulnerabilities and operational disruptions. Attendees will gain actionable guidance on strengthening resilience, enhancing risk frameworks, and proactively addressing uncertainties that can impact business continuity. Through expert-led sessions, participants will leave better equipped to anticipate challenges, adapt to change, and build more robust, future-ready organizations. Who Should Attend? This conference is ideal for: TPRM professionals seeking to enhance their programs Risk management and compliance officers Procurement and vendor management specialists IT and cybersecurity professionals involved in third party risk Whether you’re focused on third-party risk, enterprise risk, or operational continuity, this event offers valuable perspectives and tools to help you stay ahead in a rapidly shifting environment. Register Now TRACK 1 Driving Resilience Through Continuous Improvement TRACK 2 Driving TPRM Transformation Through Innovation TRACK 3 Navigating Emerging Risks & Regulatory Change Agenda Fliter by: Track 8:55 AM - 9:00 AM 5 minutes Welcome & Kick-Off Julie Gaiaschi, CEO & Co-founder, TPRA Zoom Lobby General Session Kick off this virtual conference with a few words from Julie Gaiaschi , CEO & Co-founder… Read More 9:00 AM - 9:50 AM 50 minutes Beyond the Checklist: Building a Unified Third-Party Control Framework Jan Stappers, LL.M., PgD EVP, GRC Solutions Strategy, Mitratech Room 3 Track 3: Navigating Emerging Risks & Regulatory Change The TPRM landscape has become a maze of overlapping mandates, standards, and stakeholder expectations, and… Read More 10:00 AM - 10:50 AM 50 minutes Moving at Attacker's Speed: How to Rethink TPRM for the Post-Mythos Era Jake Olcott, Bitsight Room 2 Track 2: Driving TPRM Transformation Through Innovation Third-party risk management was built for a slower world. Today, organizations face a growing volume… Read More 10:00 AM - 10:50 AM 50 minutes Gaining c-suite acceptance of emerging risks: regulation is your friend Rachel Elliott, DRI Room 3 Track 3: Navigating Emerging Risks & Regulatory Change Navigating emerging supply chain risks is becoming evermore complex, particularly with events become concurrent. The… Read More 11:00 AM - 11:50 AM 50 minutes The Two-Front Threat: Using AI to Govern Vendors in a Post-Quantum World Room 1 Track 1: Driving Resilience Through Continuous Improvement The third-party risk function is caught between two converging threats and most programs are equipped… Read More 11:00 AM - 11:50 AM 50 minutes Staying One Step Ahead: Why Intelligence Is Replacing Traditional Third-Party Risk Management Austin Starowicz, RiskRecon Room 2 Track 2: Driving TPRM Transformation Through Innovation Cybersecurity isn't becoming more difficult because organizations have more vendors—it's becoming more difficult because adversaries… Read More 12:00 PM - 1:00 PM 60 minutes Lunch Meal Take a break to enjoy some lunch before jumping back into learning with our next… Read More 1:00 PM - 1:50 PM 50 minutes When Risk Evolves, Agility Wins: AI Transforms Third-Party Risk Management Bryn Sedlacek, Aravo Room 2 Track 2: Driving TPRM Transformation Through Innovation Today's TPRM programs must support resilient operations, secure IT, ethical business practices, regulatory compliance, and… Read More 1:00 PM - 1:50 PM 50 minutes Third-Party Risks and Sanctions Michael Volkov, Volkov Law Group Room 3 Track 3: Navigating Emerging Risks & Regulatory Change With the beginning of the aggressive trade enforcement era, companies need to focus on third-party… Read More 2:00 PM - 2:50 PM 50 minutes Fourth-Party Risk: The Exposure You Can’t Always See Tracey Forney, previously Sr Information Security Manager with Federal Reserve Room 1 Track 1: Driving Resilience Through Continuous Improvement Dependencies on sub-contractors and upstream providers can introduce risk that is not obvious from primary… Read More 2:00 PM - 2:50 PM 50 minutes From Finding to Fixing: Managing Third-Party Issues, Exceptions & Performance Kholofelo Mothibi, Corebride Financial Room 2 Track 2: Driving TPRM Transformation Through Innovation Identifying a vendor risk is only the beginning. The real test of a TPRM program… Read More 3:00 PM - 3:50 PM 50 minutes The AI-Enabled Vendor: Building a Third-Party AI Risk Assessment Aligned to NIST AI RMF Nitin Agarwal, Luminace Room 1 Track 1: Driving Resilience Through Continuous Improvement Third-party vendors are rapidly embedding generative and agentic AI into the services organizations already consume,… Read More 3:50 PM - 4:00 PM 10 minutes Conference Conclusion Julie Gaiaschi, CEO & Co-founder, TPRA Zoom Lobby General Session We will close out this event with a few announcements and drawings for raffle prizes! 3:00 PM - 3:50 PM 50 minutes Continuous Monitoring That Improves Oversight Ken Wolckenhauer, Nordea Bank Room 3 Track 3: Navigating Emerging Risks & Regulatory Change Turning on risk monitoring and alert feeds is easy but turning them into better decisions… Read More Speakers Apply to Speak Tracey Forney previously Sr Information Security Manager Federal Reserve Bryn Sedlacek VP, Product Management Aravo Solutions, Inc Michael Volkov CEO The Volkov Law Group PC Austin Starowicz Director, Solutions Consulting Mastercard Cybersecurity Rachel Elliott Director of Global Strategy and Innovation DRI International Jake Olcott VP Government Affairs Bitsight Jan Stappers LL.M., PgD EVP, GRC Solutions Strategy Mitratech Prevalent Julie Gaiaschi CEO & Co-founder Third Party Risk Association (TPRA) Thank you to our Sponsors ! Interested Sponsors Be sure to visit their virtual booths during the event!
- TPRM Service Providers | TPRA
Leverage this list of third party risk management service providers in various categories to find the right vendor for your needs. TPRM Tools At the Third Party Risk Association, we know that finding the right vendor for your needs can be a challenge. Often, organizations may not even be aware of the potential vendors in the space. We're aiming to compile an exhaustive list of TPRM vendors across various categories to make your life a little easier. This list of TPRM Vendors is not affiliated with the TPRA, and the TPRA does not receive any monetary gain from listing them below. If you are a TPRM Vendor and would like to be included in the list below, please email Heather Kadavy at heather.kadavy@tprassociation.org . Filter by Tool Category Filter by TPRA Membership Status Filter by Organization Name Number found: 164 Search Clear Filters CATEGORY ORGANIZATION TPRA MEMBER URL TPRM Platform Aravo Yes https://www.aravo.com Risk Ratings/Intelligence Bitsight Yes https://www.bitsight.com TPRM Platform Mitratech Yes https://mitratech.com/ TPRM Platform ProcessUnity Yes https://www.processunity.com Risk Ratings/Intelligence RiskRecon by Mastercard Yes https://www.riskrecon.com Risk Ratings/Intelligence Supply Wisdom Yes https://www.supplywisdom.com/ Risk Ratings/Intelligence Black Kite Yes https://blackkite.com/ TPRM Platform Certa Yes https://certa.ai TPRM Platform SecurityScorecard Yes https://www.securityscorecard.io TPRM Services S&P Global Market Intelligence Yes https://www.spglobal.com/marketintelligence/en/mi/products/ky3p.html TPRM Platform Aprovall Yes https://www.aprovall.com/en/ TPRM Platform BlueVoyant Yes https://www.bluevoyant.com/ GRC Platform Drata Yes https://drata.com/ TPRM Services HITRUST Yes https://hitrustalliance.net/ Risk Ratings/Intelligence Interos Yes https://www.interos.ai/ TPRM Platform Lema Yes https://www.lema.ai/ Risk Ratings/Intelligence NetRise, Inc. Yes https://www.netrise.io/ TPRM Platform OneTrust Yes https://www.onetrust.com Risk Ratings/Intelligence PromptArmor Yes https://www.promptarmor.com TPRM Platform Safe Security Yes https://safe.security/ TPRM Platform Sayari Yes https://sayari.com/ GRC Platform Tandem Yes https://tandem.app/ TPRM Platform Tenchi Security Yes https://www.tenchisecurity.com/en TPRM Platform Vanta Yes https://vanta.com Risk Ratings/Intelligence Veridion Yes https://veridion.com/ TPRM Services Next Peak Yes https://nextpeak.net/ TPRM Services RSM US Yes https://rsmus.com/ TPRM Services Risk Tide Solutions Yes https://www.risktide.com/ TPRM Services Third Party Threat Hunting LLC Yes https://thirdpartythreathunting.com/ TPRM Services Vendor Centric Yes https://www.vendorcentric.com TPRM Services Ventara Risk Solutions Yes https://www.ventararisksolutions.com/ TPRM Platform Anqa Yes https://www.anqa.ai/ TPRM Services CRFQ Yes https://www.crfqnow.com/ Risk Ratings/Intelligence Continuity Strength Yes https://continuitystrength.com/corporate-support TPRM Platform Coverbase Yes https://coverbase.ai/ Risk Ratings/Intelligence CyberCert Yes https://cybercert.ai TPRM Platform DocuBark Yes https://docubark.com/ TPRM Platform Fabrik Yes https://www.thetrustfabrik.com/ TPRM Platform FusionAIrre Yes https://www.fusionairre.ai/ TPRM Platform Locktivity Yes https://www.locktivity.com/ TPRM Platform Portend AI Yes https://portend.ai/ TPRM Integration Tool PsyberCog Labs Yes https://www.psybercog.com TPRM Platform SecureOS Yes https://www.secureos.co/ TPRM Services Securis360 Inc. Yes https://securis360.com TPRM Platform Shift Security Yes https://www.shift.security/ TPRM Platform Tekrisq Yes https://tekrisq.com/home TPRM Platform ThirdOrbit Yes https://thirdorbit.io TPRM Services Center for Financial Professionals (CeFPro) Yes https://cefpro.com/ Research & Educational Community Cloud Security Alliance (CSA) Yes https://cloudsecurityalliance.org/ TPRM Services Cyber Future Foundation Yes https://cyberfuturefoundation.org/ TPRM Services DRI International Yes https://www.tprassociation.org/vendor-profiles/dri-international Research & Educational Community FAIR Institute Yes https://www.fairinstitute.org Research & Educational Community Fintech Training Center Yes https://fintechtrainingcenter.com/ Research & Educational Community Global Resilience Federation (GRF) Yes https://www.grf.org/ TPRM Services Secure Controls Framework (SCF) Yes https://securecontrolsframework.com/ GRC Platform 360Factors Inc No https://www.360factors.com TPRM Services AML RightSource No http://www.amlrightsource.com GRC Platform Acuity Risk Management No http://acuityrm.com GRC Platform Archer Integrated Risk Management No https://www.archerirm.com/third-party-governance Risk Ratings/Intelligence Argos Risk No https://argosrisk.com TPRM Platform Atlas Systems No https://www.atlassystems.com/solutions/third-party-risk-management TPRM Services BDO USA No https://www.bdo.com Risk Ratings/Intelligence Blackwired Pte Ltd No https://www.blackwired.com TPRM Platform Blue Umbrella No http://www.blueumbrella.com TPRM Services BraunWeiss Inc. No https://www.braunweiss.net/ Risk Ratings/Intelligence BreachSiren No https://breachsiren.com TPRM Services Cadre No https://www.cadre.net TPRM Services CastleHill Risk No https://www.castlehillrisk.com TPRM Platform Censinet No https://www.censinet.com TPRM Services Certificial, Inc. No http://www.certificial.com TPRM Platform Clarity360 (Kroll) No https://www.krollclarity.com/ TPRM Services ComplyScore No https://www.complyscore.com TPRM Services Continuity Solutions No https://www.continuitysolutions.org/ TPRM Services Copeland BUHL No https://www.copelandbuhl.com/ GRC Platform CoreStream No http://corestreamplatform.com TPRM Platform Crossword Cybersecurity No https://www.crosswordcybersecurity.com/ TPRM Services Crowe No https://www.crowe.com/services/consulting/third-party-risk-management TPRM Platform CyberGRX (now ProcessUnity) No https://www.cybergrx.com Risk Ratings/Intelligence Cyberwrite No https://www.cyberwrite.com/ TPRM Platform DSALTA No https://www.dsalta.com/ GRC Platform DVV Solutions TPRM No https://www.dvvs.co.uk Risk Ratings/Intelligence Dark Sky Technology, Inc. No http://www.darkskytechnology.com TPRM Services Defentrix No https://www.defentrix.com/ GRC Platform Diligent No https://www.diligent.com/ TPRM Services Dixon Hughes Goodman No https://www.dhg.com/services/advisory TPRM Platform DoubleCheck Software No http://www.doublechecksoftware.com Risk Ratings/Intelligence Dun & Bradstreet No https://www.dnb.com/solutions/manage-supplier-risk.html Research & Educational Community Dynamic Standards International (DSI) No https://dsi.org/about GRC Platform Ethico No http://www.ethico.com TPRM Platform EthixBase360 (formerly EthixBase) No https://ethixbase360.com/ TPRM Services Evident ID No https://www.evidentid.com TPRM Platform Exiger No https://www.exiger.com/ TPRM Platform Findings No https://findings.co/ TPRM Platform FlowForma No http://www.flowforma.com/flowassure Risk Ratings/Intelligence FortifyData No http://www.fortifydata.com TPRM Platform Fortress No https://fortress.ai/ Risk Ratings/Intelligence GRMS | Global Risk Management Solutions No http://www.GlobalRMS.com/Difference TPRM Platform Gatekeeper No https://www.gatekeeperhq.com TPRM Services Grant Thorton No https://www.grantthornton.com/services/advisory-services/cybersecurity-and-privacy/third-party-risk TPRM Platform GraphiteConnect No https://www.graphiteconnect.com/ TPRM Services GuidePoint Security No http://www.guidepointsecurity.com TPRM Platform Halo Ai No https://gohalo.ai/ TPRM Platform Hellios Information No https://hellios.com/ TPRM Platform Hyperproof No https://hyperproof.io/product/third-party-risk-management/ Risk Ratings/Intelligence ISS Corporate Solutions No https://www.isscorporatesolutions.com/solutions/security-suite/ TPRM Services ITPN No http://www.ITPeopleNetwork.com Risk Ratings/Intelligence Ionix previously Cyberpion No https://www.ionix.io/ Risk Ratings/Intelligence KHARON No https://www.kharon.com/ TPRM Platform Kobalt Labs No https://www.kobaltlabs.com/ GRC Platform LogicGate No https://www.logicgate.com/solutions/third-party-risk-management/ TPRM Platform LogicManager No https://www.logicmanager.com/ GRC Platform MetricStream No https://www.metricstream.com TPRM Platform MyRiskShield No https://www.myriskshield.com/ GRC Platform Navex No https://www.navex.com/en-us/products/navex-irm-integrated-risk-management/third-party-risk-management/ TPRM Platform Ncontracts No https://www.ncontracts.com/ Risk Ratings/Intelligence Nova Technology Limited No https://nova-doc.com/ GRC Platform Onspring No https://onspring.com/solutions/governance-risk-compliance/third-party-risk-management/ GRC Platform OpenPages GRC by IBM No https://www.ibm.com/products/openpages-with-watson?utm_content=SRCWW&p1=Search&p4=43700070084211913&p5=p&gclid=f61d865decc71a305683e4bf26ab6b2c&gclsrc=3p.ds GRC Platform Optro (pka Auditboard) No https://optro.ai/ Risk Ratings/Intelligence Orpheus Cyber No https://www.orpheus-cyber.com Risk Ratings/Intelligence Owlin No http://www.owlin.com TPRM Services PRAXIS Technology Escrow, LLC No https://praxisescrow.com GRC Platform PROXORA No https://www.proxora.com/en/ Risk Ratings/Intelligence Panorays No https://www.panorays.com TPRM Platform Perimeter (formally ProcessBolt) No https://perimeter.net/ TPRM Platform Protecht No https://www.protechtgroup.com/en-us/ Risk Ratings/Intelligence RapidRatings No https://www.rapidratings.com/ GRC Platform Reasonable Risk No https://www.reasonablerisk.com/ Risk Ratings/Intelligence Recorded Future No https://www.recordedfuture.com TPRM Platform Resilinc No http://www.resilinc.ai TPRM Platform Risk Ledger No https://riskledger.com/ GRC Platform RiskOptics formerly Reciprocity No https://reciprocity.com/ GRC Platform SAI 360 GRC No https://www.sai360.com/ GRC Platform SAP Risk Management No https://www.sap.com/products/financial-management/risk-management.html TPRM Services Schneider Downs No https://www.schneiderdowns.com/third-party-risk-management TPRM Services SecureCrest No https://www.securecrest.com Risk Ratings/Intelligence Semantic Visions No https://www.semantic-visions.com/ Risk Ratings/Intelligence Sentrisk No https://www.marshmclennan.com/sentrisk.html GRC Platform ServiceNow GRC No https://www.servicenow.com/products/governance-risk-and-compliance.html TPRM Services Sidekick Security No https://sidekicksecurity.io/third-party-risk-management/ TPRM Platform Smarsh (formerly Privva) No https://www.smarsh.com/platform/cybersecurity-risk-management/vendor-risk-management TPRM Services Source Callé No https://www.sourcecalle.com TPRM Platform Sphera (formerly RiskMethods) No https://sphera.com/supply-chain-risk-management/ GRC Platform Standard Fusion No https://www.standardfusion.com/ TPRM Platform Start No https://www.startvrm.com/ TPRM Platform TDI No https://tdinternational.com/ Risk Ratings/Intelligence TRaiCE No https://www.traice.io TPRM Services TUV OpenSky No https://www.tuvopensky.com Risk Ratings/Intelligence The Smart Cube, a WNS company No https://www.thesmartcube.com/solutions/procurement-supply-chain/supplier-risk-intelligence/ TPRM Platform ThirdPartyTrust (a Bitsight company) No https://www.thirdpartytrust.com TPRM Platform Trust Your Supplier No https://trustyoursupplier.com/ TPRM Platform TrustExchange No https://www.trustexchange.com TPRM Services Truvo Cyber No http://truvocyber.com GRC Platform TutelaSolutions No https://www.tutela-solutions.com/ Risk Ratings/Intelligence UpGuard No https://www.upguard.com/ TPRM Platform VISO TRUST No https://www.visotrust.com TPRM Services VIVIDedge No https://www.vivid-edge.com/ TPRM Platform Velocity (Stern Security) No https://www.velocitysec.com/ Risk Ratings/Intelligence Vendict No https://www.vendict.com/ TPRM Platform VendorRisk No https://www.vendorrisk.com TPRM Platform Vendorly No https://www.vendorly.com/ TPRM Platform Whistic No https://www.whistic.com TPRM Platform myCYPR No https://www.mycypr.com/ TPRM Services Continuiti Solutions No https://continuitisolutions.com/
- VENDOR MEMBER PLANS | TPRA
Learn about TPRA's available Vendor Member plans, the benefits included in each one, and how to join! TPRA Vendor Membership Becoming a TPRA Vendor Member isn't just about gaining leads and promoting your organization, it's about helping to further the industry of Third Party Risk Management (TPRM) by becoming an integral part of a community that establishes TPRM guidance, resources, and tools, and works to promote the value that TPRM professionals add to their organizations. INQUIRE ABOUT MEMBERSHIP This page is specific to Vendor Membership, but TPRA offers three types of membership to TPRM Service Providers depending on their needs, maturity, and/or revenue. A brief overview of each option can be found below, with links to explore further. Vendor Membership For established TPRM Service Provider organizations (TPRM Platform, GRC Platform, Risk Rating/Intelligence Tool, TPRM Services, etc.). Learn More Consultant Catalyst For single Independent Consultants or Boutique Advisory Firms specializing in third-party risk management services, typically with limited marketing budgets but high expertise. Learn More Incubator Program For Start-Up TPRM Service Provider Organizations looking to gain insight, support, and promotion. Learn More Vendor Member Benefits Connect with Targeted Audience Build relationships with third party risk professionals across industries through direct engagement opportunities, collaborative forums, and curated networking channels. Access Member-Only Insights Stay ahead of industry trends and challenges with exclusive access to community-driven insights, resources, and discussions. Highlight Your Solutions Showcase your tools, services, and innovations to the TPRM community through exclusive presentation and visibility opportunities designed to spark meaningful connections. Share Your Expertise Contribute your knowledge and thought leadership to the broader community through educational content and resource-sharing opportunities. Strengthen Your Brand Presence Enhance your brand recognition across TPRA platforms and communication channels through welcome features, spotlight opportunities, and tailored visibility touchpoints. Promote Events & Opportunities Expand your reach by promoting your relevant events, job openings, and initiatives directly to the TPRA practitioner network. Our Members Why Join? As a TPRA Vendor Member, you are recognized as an organization that believes in the mission of furthering the Third Party Risk Management profession through knowledge sharing and networking . Working together with Practitioners, you are an integral part of building a community that establishes TPRM guidance, resources, and tools, and works to promote the value that TPRM professionals add to their organizations. While the Third Party Risk Association is vendor-agnostic, we absolutely recognize the value our Vendor Members create not only in our profession, but also in the organizations our practitioners represent as well. Vendor Members are invited to leverage the Third Party Risk Association as a platform for increased brand recognition within our industry – we’ll support you with priority sponsorship opportunities , expedited customer support , and our partnership in providing you a voice within the larger TPRM community. Our membership and leadership can also serve as a resource offering unique insights into practitioner pain points and domain-specific challenges to inform your product offerings and prioritize your roadmaps. As we continue to grow, adding to our ever-evolving community of verified TPRM practitioners, the Third Party Risk Association will continue consulting our Vendor Membership for guidance on industry trends , emerging risks , and enhanced program automation effort s. The TPRA looks forward to working with you on furthering the profession of Third Party Risk Management together! INQUIRE ABOUT MEMBERSHIP Ready to Join? If you are looking to move forward with Vendor Membership, complete this form to begin the process! Our team will reach out soon with plan and pricing options. Contact Heather directly using the contact info below. Heather Kadavy Senior Membership Success Coordinator heather.kadavy@tprassociation.org Vendor Membership Inquiry Complete this form if you are interested in one of TPRA's Service Provider Membership options (Vendor Membership, Incubator Program, Consultant Catalyst). Our team will reach out to you as soon as possible with further details on plan benefits and pricing. First name* Last name* Job Title* Organization* Email* Phone Which membership option are you interested in? Vendor Membership – For established TPRM Service Provider organizations (TPRM Platform, GRC Platform, Risk Rating/Intelligence Tool, TPRM Services, etc.). Incubator Program – For Start-Up TPRM Service Provider Organizations looking to gain insight, support, and promotion. Consultant Catalyst – For single, Independent Consultants or Boutique Advisory Firms specializing in third-party risk management services. Other Anything else we should know? Submit







