SCRM Supplier Compliance & Risk Management

Home

TPRM · third parties with access to data and processes

Third-party risk management counts the ones who deliver nothing.

The payroll bureau, the data centre, the SaaS tool in marketing, the cleaning firm with a key: none appear in a supplier register, all carry risk.

Third-party risk management is the international term for governing risk arising from relationships with outside parties. It is deliberately broader than supplier management: it captures every external party with access to data, systems, premises or critical processes.

The distinction is not academic. Security incidents regularly arrive through providers who appear on no procurement list because they never delivered anything. Looking only at goods received leaves part of your attack surface unknown.

Who is typically missing

  • IT providers with remote access to servers and workstations.
  • Cloud tools a department bought for itself.
  • Fiduciary, payroll and external accounting handling personal data.
  • Maintenance and cleaning firms with physical access.
  • Your providers’ subcontractors, whom you never selected.

The lifecycle

Inventory
A complete register of all third parties, not only payables.
Classification
Data category, depth of access and process relevance set the level of scrutiny.
Assessment
Before signing, with a documented result and an approval decision.
Contract
Security requirements, audit rights, notification duties, subcontractors, termination.
Monitoring
Recurring review, incident tracking, changes to service and subcontractors.
Exit
Access removal, data return or deletion, verifiably completed.

How SCRM covers it

One register for all third parties

Goods suppliers and service providers in one set, classified differently.

Data category and access

Fields that decide how deeply you assess – and explain why in the audit.

Subcontractors visible

The chain behind your provider as part of the record.

Exit evidence

Termination with documented access removal instead of a contract quietly lapsing.

Frequently asked

Is TPRM the same as supplier management?

They overlap heavily, but TPRM is broader. Supplier management starts from goods received, TPRM starts from access. In practice the second view produces a considerably longer register.

Where to start with an incomplete register?

From two sources: the payables list and the list of all accounts and access rights. The difference between them is usually the interesting part.

How does this relate to ISO 27001?

Controls A.5.19 to A.5.23 are TPRM requirements at heart. Set up TPRM properly and that part of the ISMS is largely done.

Contact

Request a consultation

A few details is all we need. We reply within one working day with an honest read on whether SCRM fits your situation.

  • A free seven-day demo account on request
  • Reply within one working day
  • No newsletter, no sharing with third parties
  • An honest read, including when we are not the fit
What drives your supply chain monitoring? *

Select all that apply

How can we reach you? *

Either one of the two is enough.

No leading zero, e.g. 79 123 45 67

* Required