TPRM · third parties with access to data and processes
Third-party risk management counts the ones who deliver nothing.
The payroll bureau, the data centre, the SaaS tool in marketing, the cleaning firm with a key: none appear in a supplier register, all carry risk.
Third-party risk management is the international term for governing risk arising from relationships with outside parties. It is deliberately broader than supplier management: it captures every external party with access to data, systems, premises or critical processes.
The distinction is not academic. Security incidents regularly arrive through providers who appear on no procurement list because they never delivered anything. Looking only at goods received leaves part of your attack surface unknown.
Who is typically missing
- IT providers with remote access to servers and workstations.
- Cloud tools a department bought for itself.
- Fiduciary, payroll and external accounting handling personal data.
- Maintenance and cleaning firms with physical access.
- Your providers’ subcontractors, whom you never selected.
The lifecycle
- Inventory
- A complete register of all third parties, not only payables.
- Classification
- Data category, depth of access and process relevance set the level of scrutiny.
- Assessment
- Before signing, with a documented result and an approval decision.
- Contract
- Security requirements, audit rights, notification duties, subcontractors, termination.
- Monitoring
- Recurring review, incident tracking, changes to service and subcontractors.
- Exit
- Access removal, data return or deletion, verifiably completed.
How SCRM covers it
One register for all third parties
Goods suppliers and service providers in one set, classified differently.
Data category and access
Fields that decide how deeply you assess – and explain why in the audit.
Subcontractors visible
The chain behind your provider as part of the record.
Exit evidence
Termination with documented access removal instead of a contract quietly lapsing.
Frequently asked
Is TPRM the same as supplier management?
They overlap heavily, but TPRM is broader. Supplier management starts from goods received, TPRM starts from access. In practice the second view produces a considerably longer register.
Where to start with an incomplete register?
From two sources: the payables list and the list of all accounts and access rights. The difference between them is usually the interesting part.
How does this relate to ISO 27001?
Controls A.5.19 to A.5.23 are TPRM requirements at heart. Set up TPRM properly and that part of the ISMS is largely done.