Third-Party and Vendor Risk Management
Third-Party and Vendor Risk Management is the process of identifying and reducing the risks that can arise when an organization relies on outside parties, such as vendors, suppliers, and business partners, to provide products or services. It aims to understand what could go wrong in these relationships and to put controls in place to manage those risks. Vendor Risk Management is generally treated as a subset focused specifically on the suppliers and vendors an organization uses.
Third-Party Risk Management (TPRM) is a form of risk management focused on identifying, assessing, and mitigating risks arising from an organization's use of third parties, implemented through a structured program that spans the third-party relationship lifecycle. Vendor Risk Management (VRM) is a narrower discipline concerned specifically with evaluating vendors, suppliers, and business partners and managing the risks associated with them; it is typically characterized as a subset of the broader TPRM domain, which may also intersect with enterprise risk management (ERM). In a data protection context, such programs are commonly used to support oversight of processors and other recipients of personal data, though the specific legal obligations governing those relationships (for example, controller-processor arrangements) derive from applicable law and instruments rather than from the risk-management program itself, and readers should verify those requirements against the current official text.
Why it matters
Organizations rarely operate in isolation. They rely on vendors, suppliers, and business partners to deliver products and services, and in a data protection context these third parties frequently process personal data on the organization's behalf or receive it as recipients. When something goes wrong within one of these relationships, the consequences can flow back to the organization that engaged the third party, which is why identifying and reducing third-party risk is a core governance concern rather than a purely operational one.
In the GDPR framework, a controller that engages a processor generally remains accountable for ensuring that appropriate safeguards are in place, and controller-processor arrangements are typically required to be governed by a written contract or other legal act. A TPRM or VRM program can help operationalize the oversight and due diligence that support these obligations, but the program itself does not create the legal requirements. Those obligations derive from applicable law and instruments, and the specific article references, contractual content requirements, and any national derogations should be verified against the current official text.
Because the discipline spans the full lifecycle of a third-party relationship, from selection and onboarding through ongoing monitoring and offboarding, weaknesses at any stage can expose an organization to privacy, security, operational, and compliance risk. The appropriate depth of assessment is generally risk-based and context-dependent, so a program should be calibrated to the nature of the data involved and the role each third party plays rather than applied uniformly.
Who it's relevant to
Inside TPRM
Common questions
Answers to the questions practitioners most commonly ask about TPRM.