Skip to main content

Third-Party Risk (TPRM)

The TPRM module manages the risk your vendors and other third parties carry, from the moment you consider one through to ongoing monitoring. You onboard a vendor, judge how much it matters to you, send it a security assessment it answers in a dedicated portal, review what comes back, log and remediate findings, track the contract, and keep watching for trouble after it's live.

This guide walks the whole vendor lifecycle, one stage at a time.

TPRM executive dashboard
The TPRM executive dashboard: portfolio KPIs, risk distribution, and your top-risk vendors at a glance.

The vendor lifecycle

A vendor moves through these stages. Each has its own page in this guide:

  1. Onboard vendors. Get a third party into the system as a vendor, and set how critical it is to you.
  2. Assess risk. See a vendor's inherent and residual risk, and escalate the serious ones.
  3. Send an assessment. Build a questionnaire and assign it to a vendor to answer.
  4. The vendor portal. What the third party sees: they log in, answer, attach evidence, and submit.
  5. Review and findings. Review the submission and turn gaps into tracked findings.
  6. Contracts. Record contracts and let AI check them against your baseline.
  7. Monitor continuously. Watch for external signals and drift after a vendor is live.
  8. Report out. Generate memos, export data, and push vendor risk into the enterprise register.

How a vendor's state is tracked

A vendor record carries three independent state axes, and it helps to keep them straight because they don't move together:

  • Status is the commercial relationship: prospective, active, dormant, or terminated.
  • Criticality is how much the vendor matters to your business: low, medium, high, or critical. SolveGRC suggests a tier from the service and data involved, and you confirm it.
  • Lifecycle stage is where the vendor sits in your governed review workflow, from intake through onboarding, monitoring, reassessment, and eventually offboarding. Advancing a stage can require a checklist to be complete and a second person to approve.

Status and criticality are quick labels; the lifecycle stage is the real end-to-end progression, with approval gates along the way.

Before you start

  • Access to the module. TPRM appears in the sidebar only if your role has permission for it. Onboarding vendors, assigning questionnaires, and reviewing submissions each need the right permission; if a page or button is missing, ask an administrator.
  • A clause library, for contracts. The contract coverage check compares each contract to your organization's required clause baseline. If you plan to use it, set that baseline up first (see Contracts).
  • Evidence in your library. As with the rest of SolveGRC, AI features draw on the documents and evidence you've already loaded, so richer inputs mean better narratives and memos.