top of page

Search Results

516 results found with an empty search

Blog Posts (113)

  • Sanctions and Third Party Risk: What Every TPRM Practitioner Should Know || TPRM Exchange Podcast – Episode 4

    Sanctions compliance may traditionally sit with legal, trade compliance, or another specialized function, but it has direct implications for third party risk management. A prohibited relationship can expose an organization to blocked transactions, frozen payments, regulatory enforcement, financial penalties, operational disruption, and reputational damage. In this episode of the TPRM Exchange, host Hilary Jewhurst speaks with Michael Volkov of The Volkov Law Group about how sanctions apply to third parties, where sanctions risk appears throughout the lifecycle, and what practitioners can do to build a practical and defensible process. Sanctions Risk Does Not Stop at the Border One of the most common—and potentially costly—misunderstandings is that U.S. sanctions no longer apply when a transaction is routed through an entity outside the United States. As Volkov explains, a U.S. company cannot avoid its sanctions obligations simply by working through a third party in another country. “The risk continues from wherever you’re located. If you’re a U.S. person or a U.S. company, it continues through your third parties, no matter where they are located.” — Michael Volkov Sanctions may target particular activities, individuals, entities, industries, or entire countries. Regardless of the specific program, the practical question for an organization is whether it is permitted to conduct business or complete a financial transaction with the party involved. Screening Should Begin During Onboarding Sanctions issues can emerge at several points in the third party lifecycle, but onboarding is the most important place to establish a control. Before a vendor, supplier, customer, distributor, or other third party is entered into an organization’s master database or approved for payment, the party should be screened. Building screening into the existing approval workflow allows the organization to identify potential issues before a contract is signed, goods are shipped, or money changes hands. Waiting until a bank blocks a payment puts the organization in a much more difficult position. By that point, goods may already have been delivered, contractual commitments may have been made, and funds may be frozen while the parties investigate. The Entity Name Is Only the Beginning Screening the contracting entity is an essential first step, but it may not reveal the full risk. Organizations may also need to examine the company’s beneficial owners, officers, directors, or other principals. Under certain sanctions rules, an entity can be treated as blocked when one or more sanctioned persons own 50% or more of it—even if the entity itself does not appear by name on a sanctions list. Ownership structures can also obscure the individuals who ultimately control or benefit from a company. When an initial screen produces a red flag, practitioners may need to gather additional ownership information and work with legal or compliance specialists to determine whether the relationship is permissible. Sanctions Exposure Extends to Nth Parties The conversation also highlights the importance of looking beyond direct contractual relationships. Sanctioned goods, materials, entities, or individuals may appear several levels down a supply chain or later in a distribution channel. Volkov uses supply chain and transshipment examples to illustrate how an organization can face liability even when it does not directly contract with the sanctioned party. Risk may arise when prohibited materials enter the supply chain through a subcontractor or when a distributor redirects a product to a sanctioned destination. Managing that exposure may require: Risk-based supply chain due diligence Appropriate sanctions and trade-compliance clauses End-use and end-user controls Supplier representations and certifications Supply chain audits Escalation procedures for geographic or ownership concerns The appropriate level of diligence will depend on the organization’s products, markets, geographic reach, distribution model, and overall exposure. Build Forward Instead of Trying to Fix Everything at Once Organizations implementing formal sanctions screening may discover that hundreds or thousands of existing third parties have never been screened. That does not mean the program must resolve the entire backlog before introducing an effective control. “You’re not going to boil the ocean over this. We don’t have time for that, nor the resources.” — Michael Volkov A more manageable approach is to establish a clear implementation date and screen every new third party from that point forward. The organization can then address its existing population using a risk-based plan. Higher-priority reviews may include third parties with: Operations in higher-risk countries or regions Significant organizational spend or revenue Exposure to known transshipment locations Complex or unclear ownership structures Access to regulated products, technology, or services Roles deeper within critical supply or distribution chains This approach allows the organization to establish a consistent control immediately while addressing historical exposure in a deliberate, defensible order. Screening Is Not a One-Time Activity A third party that passes screening today may be added to a sanctions list tomorrow. Sanctions designations can change quickly in response to geopolitical events, national security concerns, criminal activity, or changes in government policy. Automated screening platforms can help by retaining screened parties and issuing alerts when a party’s status changes. Organizations without an automated tool may begin with available government screening resources or seek assistance from qualified legal or compliance professionals, but manual screening becomes harder to sustain as international activity grows. Regardless of the technology used, the process should define: Who is screened When screening occurs Which lists and data sources are used How potential matches are reviewed Who can clear or reject a match How decisions are documented How active relationships are monitored When issues must be escalated The tool supports the control, but it does not replace a clear workflow and accountable decision-making. TPRM Does Not Have to Own the Process—but It Must Understand It Sanctions screening may be performed by compliance, legal, procurement, trade compliance, sustainability, or another team. Organizational structures vary, and there is no single operating model that works for every company. However, TPRM practitioners should understand how the process works even when another function owns it. They should know who makes sanctions decisions, what tools or information that team uses, what evidence confirms that screening occurred, and how an issue is escalated. That knowledge is necessary to explain the organization’s controls to business stakeholders, auditors, examiners, and leadership. It also prevents gaps between functions—particularly when onboarding involves several teams with different approval responsibilities. Compliance Must Be Positioned as a Business Partner Business stakeholders may view sanctions screening as another obstacle standing between them and a time-sensitive transaction. Volkov recommends approaching those conversations as a partner focused on helping the business proceed safely. The message should be straightforward: involve the appropriate risk and compliance teams early, and they can identify concerns, explore permissible options, and help prevent transactions from being blocked later. TPRM and compliance teams should also establish reasonable turnaround expectations. A well-designed screening process should support timely decision-making while ensuring that unresolved red flags do not pass unnoticed into the vendor master or payment process. When an Existing Supplier Triggers an Alert If a long-term supplier appears on a sanctions notice, the organization must act promptly. The immediate response should generally include pausing business and financial activity, notifying the appropriate internal stakeholders, and investigating the alert. The organization should contact the third party for an explanation while legal or trade-compliance personnel determine whether the notice is accurate and whether the relationship can lawfully continue. Contracts and purchase orders should contain sanctions-compliance language that supports the organization’s ability to suspend or terminate prohibited activity. These protections are particularly important when a designation occurs in the middle of a transaction or during a multiyear agreement. Practitioners should not assume that every alert establishes a confirmed violation. False positives and explainable matches occur. Nevertheless, activity should not resume until qualified personnel have reviewed the issue and documented a defensible decision. Two Practical Priorities Volkov closes with two primary actions for practitioners: Implement a sanctions-screening capability that supports onboarding and continued monitoring. Provide annual sanctions training to employees whose responsibilities may bring them into contact with sanctions-related issues. Training does more than communicate rules. It creates an opportunity for employees to raise questions, describe emerging business activities, and identify transactions or relationships that might otherwise remain outside the risk team’s view. Ultimately, effective sanctions compliance depends on visibility, defined ownership, appropriate technology, and cooperation across the organization. By embedding screening into onboarding, monitoring active relationships, accounting for beneficial ownership and nth parties, and responding quickly to alerts, TPRM practitioners can help protect the organization while still enabling the business to move forward.

  • Beyond Third Parties: Eight Actions to Tackle Fourth‑ and Nth‑Party Risk

    If you spend enough time in third party risk, you’ll notice something unfair. Your third parties have their own third parties, and when those downstream providers fail, your organization still feels the impact, even though you never signed a contract with them. This leads to a common question: “How are we supposed to manage those third parties?” The short answer is that you don’t manage them directly. Instead, you focus on reducing the risks that come with these extended relationships. Fourth- and nth-party risk means knowing where these downstream dependencies are, how their failures could disrupt your services or affect your customers, and making sure your TPRM program identifies, analyzes, and reduces those risks where it matters most. Who is a 4th or nth party? In third party risk management (TPRM), “third party” usually means any external organization or supplier under contract to deliver a product, service, or process. That is the part everyone is used to tracking. A “fourth party” is any provider your third party relies on. These can be cloud platforms, sub‑processors, subcontractors, and upstream suppliers that sit behind the scenes but can still disturb your operations, affect your customers, or negatively impact your compliance posture when something goes wrong. “Nth‑party risk” is the more general term for the additional layers beyond that, including the third parties supporting those fourth parties and further out in the chain. Taken together, this extended chain of third, fourth, and nth parties is part of what many practitioners now refer to as extended enterprise risk, the risks that arise across the wider network of external relationships that support your organization’s products and services. Why fourth- and nth-party risks are getting attention Fourth- and nth-party relationships are getting more attention because shared dependencies are now easier to see. For example, one cloud platform, KYC provider, or infrastructure service can affect several third parties at once, turning a single incident into a disruption across multiple services. Regulators and boards are also asking more specific questions about sub‑processors, concentration risk, and resilience. Once you accept that fourth and nth‑party relationships can materially affect your organization, the next question is what to do about it in practice. You cannot manage every downstream provider directly, but you can absolutely design a TPRM program that properly addresses fourth‑ and nth‑party risk. Here are eight practical actions you can take to help your organization more effectively identify, analyze, and mitigate those extended‑ecosystem risks. 1: Determine How Far You Will Go If you try to map your whole supply chain, you’ll end up with too much information and little value. It’s usually better to set clear criteria for what’s in scope, like access to customer data, critical services, or when the same downstream provider is used by several third parties. Start by deciding how deep you are willing to go. A reasonable standard for many programs is your direct third parties, plus their critical sub‑processors and major shared platforms that would materially affect your business if disrupted. Make sure your final decision is reviewed and documented. If someone asks why a certain downstream provider is included or not, you should be able to explain it easily. 2: Know How to Identify Your 4th And Nth Parties After you decide how deep to look, the next step is finding those downstream entities. Some third parties will give you a clear list of sub-processors, but many will not. A practical way to do this is to gather information from several sources: SOC 2 Type II reports, especially the system description and subservice organization sections. External risk intelligence tools that map hosting providers, DNS, IP ranges, and technology stacks. Public trust centers and compliance pages that list sub‑processors or infrastructure partners. Regulatory or industry disclosures that reference key providers. Internal insight from Architecture, Security, and Operations teams that already know which shared platforms sit underneath important services. You are not trying to build an exhaustive inventory. You are trying to identify the downstream relationships that can materially impact your operations, customers, compliance, or reputation. 3: Think In Terms of Fourth‑Party Failure and Concentration When you look past your direct third parties, it helps to break fourth-party risk into two simple questions. Fourth‑party failure risk Start with a single third party and ask, “What if one of their critical fourth parties fails?” For that third party: Which fourth‑party providers are critical to the service they deliver to you? What parts of your operations stop working if one of those fourth parties has an outage or incident? How quickly would the third party detect and communicate that issue to you, and who owns the response on your side? What options exist if that fourth party is unavailable for an extended period (alternate providers, workarounds, manual processes)? This approach keeps the focus on a specific relationship: your third party, their key fourth party, and how it affects your organization. Fourth‑party concentration risk Then step back and ask, “How many of our third parties rely on the same fourth parties?” Across your third party portfolio: Which fourth‑party providers appear repeatedly in different third party relationships? How many critical services in your inventory ultimately depend on the same fourth‑party cloud, KYC, payments, or messaging provider? Are there specific fourth‑party entities that, if impaired, would create issues across multiple third parties at once? Here, you’re mapping shared fourth-party dependencies across your third parties . The result should be a short list of fourth-party providers and the services or third parties they support, so leadership can see where the biggest exposures are. By looking at fourth-party failure risk for each third party and concentration risk across your whole portfolio, you get a clearer view of where extended-ecosystem risk is acceptable and where you need to focus more attention. 4: Understand How Your Third Parties Manage Their Third Parties Since you can’t manage all your third parties’ third parties, one of your best controls is making sure your third parties have strong TPRM practices themselves. This means asking if your third parties identify and rank their own third parties, separate critical providers from less important ones, do proper due diligence, and monitor those relationships over time. Third parties with mature TPRM programs are more likely to spot their own dependencies, catch issues early, and alert you to important problems. If your third party does a weak job managing its own supply chain, you inherit that weakness. If they are disciplined about risk tiers, due diligence, and ongoing monitoring, you gain a layer of protection and visibility you could not create on your own. 5: Build Visibility into the TPRM Lifecycle It’s easier to manage downstream risk when you include it in your existing processes, instead of tracking it separately in a spreadsheet. This can be as simple as asking the right questions or gathering key information at each stage of the lifecycle: Risk Assessment: Identify your critical products and services and focus on their sub processors. Due Diligence: Ask third parties about material sub‑processors and critical upstream services during due diligence. Record those entities in your third party/supplier record so they can be tracked over time. Contracting: Ensure clauses cover disclosure of critical sub-processors and notifications when they change. Monitoring: Update the record when sub‑processors change, new dependencies appear, or incidents affect key downstream providers. Exit: Capture what you learned about the third party’s downstream footprint and use it in future assessments. By including fourth- and nth-party oversight in your regular processes, you create consistent risk checkpoints and collect data that helps you make better decisions. 6: Contract For Downstream Control You might not have contracts with fourth- or nth-party entities, but you do have contracts with your third parties who rely on them. That’s where you have leverage. Useful terms include the requirement to disclose material sub‑processors, notice before changes, flow‑down obligations for security and resilience, incident notification when a sub‑processor issue affects your service, and independent assurance where appropriate. You obviously can’t dictate how someone else’s third party or supplier program operates. You can hold your third parties accountable for managing their own downstream relationships in line with your risk expectations. 7: Use Risk Alerts and Threat Intelligence for Key Downstream Providers You don’t need a contract with a downstream provider to keep an eye on public risk information about them. Risk alert services, external monitoring platforms, and threat intelligence feeds use public and open-source data, making them helpful for key nth-party relationships. For higher-impact downstream entities, you can monitor domains, infrastructure, leaked credentials, breach chatter, major vulnerabilities, and other warning signs. This monitoring won’t replace good third party management, but it gives you another way to spot issues with important shared providers. This is especially useful when a downstream provider supports several third parties in your environment. In these cases, a single alert can tell you more than multiple questionnaires. 8: Embed Downstream Risk into Governance Fourth- and nth-party risk management works best when it’s included in the same governance channels as your other key risks. This could mean including shared dependencies in outsourcing discussions, resilience reports, third party portfolio reviews, and contract playbooks. When it’s part of regular reporting and oversight, it becomes a normal part of your program instead of a special topic. Conclusion Fourth- and nth-party risk falls somewhere between your third parties’ responsibilities and your own. You can’t control every downstream provider, but you also can’t ignore how those relationships might affect your organization and your customers. The eight actions in this blog are designed to give you a practical starting point. If you pick a few and add them to your program, you’ll get better visibility into the downstream relationships that matter most and a more consistent way to manage their risks. You don’t have to solve everything at once. Focus on bringing the right extended relationships into view and handling them with processes you can explain, repeat, and improve over time. That’s what real progress on fourth- and nth-party risk looks like in a TPRM program. Author Bio Hilary Jewhurst Sr. Membership & Education Coordinator at TPRA Hilary Jewhurst is a seasoned expert in third party risk and risk operations, with nearly two decades of experience across financial services, fintech, and the nonprofit sector. She has built and scaled third party risk programs from the ground up, designed enterprise-wide training initiatives, and developed widely respected content that helps organizations navigate regulatory complexity with clarity and confidence. Known for turning insight into action, Hilary’s thought leadership and educational work have become go-to resources for professionals looking to mature their TPRM programs. She regularly publishes articles, frameworks, and practical guides that break down complicated risk topics into meaningful, accessible strategies. Hilary recently joined the Third Party Risk Association (TPRA) as a staff member, supporting industry-wide education, peer learning, and advancing best practices. She is also the founder of TPRM Success, a boutique consultancy that helps organizations strengthen their third party risk management capabilities through targeted training, tools, and strategic guidance.

  • 5 Tips on Continuous Monitoring

    Staying on top of third party risks doesn’t stop at onboarding. Ongoing monitoring is crucial for ensuring your third parties remain compliant and resilient over time. Review the infographic below for actionable tips to enhance your continuous monitoring strategy. Interested in learning more about Continuous Monitoring? Check out our Free TPRM 101 Guidebook: https://www.tprassociation.org/guidebook Download the infographic:

View All

Other Pages (397)

  • TPRA – Third Party Risk Management Resources, Certification & Networking

    Join the TPRM community at TPRA for expert resources, training, templates, and tools to strengthen your third party risk program and grow your network. Join the only not-for-profit, vendor-agnostic professional association uniting thousands of TPRM professionals worldwide. Furthering the profession of third party risk management through knowledge-sharing & networking. Learn More Join Now The all-in-one source for Third Party Risk Management (TPRM) tools, templates, training, networking, certifications & industry best practices. MEMBERSHIP CONNECT & DISCOVER Individuals & organizations working together to advance the industry. More > EDUCATION MEETINGS & TRAINING Certifications & training for risk professionals to advance their careers & enhance their programs. More > RESOURCES INFORMATION SHARING SITE White papers, templates, guidance & more to enhance your program. More > TOOLS & AUTOMATION EXPLORE & CONTACT Detailed profiles of trusted TPRM service provider organizations & their offerings. More > Advance Your Career in Risk Management: Learn About the Benefits of TPRA Membership > Practitioner Plans Standard: FREE Premium: $199/yr BENEFITS Member Meetings Interactive monthly calls to discuss a variety of third party risk topics decided upon by members. Conferences In-person and virtual conferences dedicated solely to third party risk topics. Networking Online interaction with your peers through membership forums and document databases. Industry-Specific Meetings Quarterly special interest calls based on your industry. Demos, Surveys, Webinars Access to third party risk management service provider demos, surveys, & webinars. Certifications TPRM professional certifications that establish credibility and demonstrate your commitment to mastering your skills and knowledge within the industry. Join Now Vendor Plans 4 available plans starting at $8,000/yr BENEFITS Priority & Discount Sponsorship Opportunities Be the first to sponsor conferences and receive discounted member rates, as well as priority positioning. Networking & Collaboration Attend monthly and quarterly meetings with TPRM practitioners and other service providers to network, collaborate, create resources, share insights, and more! Promotional Opportunities Work with the TPRA staff to communicate to Practitioner Members the your organization's webinars, surveys, demos, blog posts, and white papers. Advisory Councils Join our TPRM Service Provider Advisory Council, as well as other groups, dedicated to collaborating, sharing insights, and providing strategic guidance. Quarterly Updates Receive quarterly updates with industry innovators to collaborate on practitioner needs. Join Now Meetings Open to All Meetings Open to All Member Meetings & Events On-Demand Meetings Thursday, August 13, 2026 10:00 – 11:00 AM CT Roundtable: Budgeting for TPRM Success Register > Tuesday, August 18, 2026 1:00 – 2:00 PM CT Women In TPRM Meeting Register > Wednesday, August 19, 2026 9:00 AM to 4:00 PM CT Q3 Demo Day Register > Monday, August 24, 2026 9:00 AM – 4:00 PM CT TPRMP August Training Only Register > CONTACT US OUR INFORMATION Address: P.O. Box 824 Ankeny, Iowa 50021 USA Email: info@tprassociation.org For any general inquiries, please fill out the contact form. First name* Last name* Email* Subject* Message* Yes, subscribe me to TPRA communications. Submit

  • Veridion | Vendor Member Profile

    Learn more about Veridion, a TPRA , through this comprehension profile, including a bio, product functionality, contact info, and more. < Main Page < Previous Next > Veridion Risk Ratings/Intelligence Advocate Member CONTACT INFORMATION cosmin.pirvu@veridion.com Veridion provides the continuously refreshed company intelligence that powers third-party risk management. We track 642 million companies globally, including 135 million operating companies and 507 million legal entities, across 166 million function-typed locations. By combining legal registry information with current digital and operational signals, we create a complete and continuously updated view of each counterparty. TPRM platforms and risk teams use Veridion to improve entity resolution, perpetual KYB, corporate ownership analysis, sanctions exposure assessment, supplier monitoring, facility-level disruption analysis, ESG compliance, and dormant-shell detection. Our APIs and batch data products help organizations identify material changes across supplier ownership, locations, activities, products, certifications, and risk signals. Show More TOP PRODUCT FUNCTIONALITY CATEGORIES Third-Party Entity Resolution Continuous Supplier Monitoring Perpetual KYB and Business Verification Corporate Ownership and Ultimate Parent Mapping Sanctions Exposure and Corporate-Family Analysis Facility-Level Risk and Disruption Intelligence Supplier and Counterparty Data Enrichment ESG and Sustainability Risk Intelligence Dormant Company and Shell Detection Adverse Media and Operational Risk Signals RESOURCES FROM THIS VENDOR MEMBER Load More EVENTS FROM THIS VENDOR MEMBER NEWS & UPDATES ADDITIONAL OPPORTUNITIES Previous Next

  • INCUBATOR PROGRAM (Start-Ups) | TPRA

    TPRM Service Provider start-ups are invited to join the TPRA as Incubator Members! Apply now! TPRA Incubator Program Welcome to the TPRA Incubator Program, created to be a catalyst for transformative innovation in third party risk management (TPRM) Read More Inquire About Membership About Mission Empower and accelerate the success of innovative third party risk management startups through a comprehensive incubator program. We strive to foster a collaborative ecosystem that provides mentorship, resources, and networking opportunities, enabling startups to navigate challenges, develop cutting-edge solutions, and establish a robust presence in the evolving landscape of risk management. Vision To be a catalyst for transformative innovation in third party risk management, fostering a dynamic ecosystem where startups thrive in pioneering solutions that redefine industry standards. We aspire to build a global community of resilient and adaptive risk management leaders who contribute to a secure and trustworthy business environment. Through our incubator program, we envision a future where emerging startups play a pivotal role in shaping the evolution of risk management practices, driving sustainability, and ensuring resilience in an ever-changing landscape. Transforming the Industry Together Incubator Participants Who Can Participate Inquire About Membership Innovative Third Party Risk Management Startups Only start-up organizations within the Third Party Risk Management space Start-up must be five years old or less and/or within the pre-seed, seed, or early stage (Series A and Series B) Start-ups must not bring in more than $500,000 of revenue annually from product/service offerings Must complete an application and potentially an interview Must provide evidence of the revenue the organization generates from products/services within their last and/or current financial year TPRA retains the right to deny any organization and/or individual entry into the Incubator Program for any reason Goals & Activities The goals and activities of the Incubator Program are to assist with removing roadblocks within the community to allow for better communication, tighten feedback loops to ensure community needs are addressed, and to be a catalyst for innovation within the community. The program will also allow for a common lexicon when speaking about TPRM programs and the value they bring to organizations. Below are the goals and activities related to the TPRA’s Innovator Program: 1 TPRA Vendor Membership Receive “Incubator Status” Vendor Membership based on the Program Tier structure below. Would receive all of the benefits of an “Advocate” Member. Benefits include: Orientation & On-boarding Three website accounts Quarterly updates Invitations to practitioner meetings Website Access Service Provider Profile LinkedIn Welcome Message Share your resources, events, surveys, & job openings with TPRA members Newsletter Spotlight & Links to Blogs Write blogs for TPRA 3 Access to Resources Share TPRA resources, webinars, and training opportunities. TPRA will create a website to share external resources for Incubator Program members only (to include company names and URLs for investment firms, other incubator programs, and other start-up accelerators). 5 Training & Skill Development Incubator participants may attend TPRA webinars, events, and activities on the website to enhance TPRM skill development. 7 Lead Generation Opportunities TPRA to provide incubator participants with discounts on conference sponsorships and demo opportunities. Sponsorships come with opt-in lists. TPRA to create a site for Practitioners to submit RFPs for TPRM tools and for incubator participants (as well as TPRA Vendor Members) to respond to them. 9 Feedback & Improvement of Incubator Program From time to time, participants will receive surveys that request feedback on the Incubator Program. Responses will be used to continually enhance the program. 2 Start-Up Advisory Council Set up regular 1:1 meetings (most likely quarterly) with select practitioners (based on industry and company size) to provide program participants with feedback on their products/services. This can also assist with the incubator program participant figuring out their product market fit, target market, and product/service pitch. Can also assist with the participant better understanding if they are addressing their market’s TPRM pain points. TPRA to create a site for Practitioners to note TPRM pain points and/or note request for innovation. (Note: Can have the community vote on what they would like to see the most.) Incubator Participants would be able to access this list. 4 Network Opportunities TPRA will create network opportunities to introduce incubator program participants other program participants, practitioners, and other service providers. 6 Brand Awareness TPRA to note the incubator participant’s organization on the TPRA website (within Service Provider Profile), highlight the organization on LinkedIn, and note the organization as a spotlight within one of the TPRA’s quarterly newsletters. 8 Collaboration on Additional Resources In collaboration with TPRA, may participate in educational trainings, research, & content creation (such as blog posts, whitepapers, & videos). Inquire About Membership Heather Kadavy Senior Membership Success Coordinator heather.kadavy@tprassociation.org Follow on LinkedIn > Vendor Membership Inquiry Complete this form if you are interested in one of TPRA's Service Provider Membership options (Vendor Membership, Incubator Program, Consultant Catalyst). Our team will reach out to you as soon as possible with further details on plan benefits and pricing. First name* Last name* Job Title* Organization* Email* Phone Which membership option are you interested in? Vendor Membership – For established TPRM Service Provider organizations (TPRM Platform, GRC Platform, Risk Rating/Intelligence Tool, TPRM Services, etc.). Incubator Program – For Start-Up TPRM Service Provider Organizations looking to gain insight, support, and promotion. Consultant Catalyst – For single, Independent Consultants or Boutique Advisory Firms specializing in third-party risk management services. Other Anything else we should know? Submit

View All
bottom of page