Third-party Risk Management reference
Reference topics provide detailed descriptions of tables, properties, forms, and roles that are installed with the Third-party Risk Management application.
- Terminology
Learn more about the key concepts and terms that are used in the TPRM application. - Roles in Third-party Risk Management
Roles determine permissions and access in TPRM. - Unique ID numbers for TPRM records
When you create (or the system generates) a new record (for example, a request for due diligence or a task), the system auto-assigns a unique ID number that helps to identify the type of data in the record. You can use the ID number to search for or filter the item you want to work on. - Results of migrating a template to a TPRM SAE template
You can view the templates that were migrated to Smart Assessment format. - Guidelines for importing spreadsheet data
Before you try to import the questionnaire data from a Microsoft Excel spreadsheet into Third-party Risk Management tables, you must verify that its format meets particular guidelines. - Sample questionnaires
The questionnaire that you use can depend on your industry, geographic area, jurisdiction, or the particular nature of your operations. These questionnaires are provided as part of the base system and are samples that shouldn’t be implemented into your risk management program without first being reviewed and approved by your legal team. - Due diligence request process management
From the Details tab, you can view and adjust the due diligence request information for a third party. You can also log external-facing comments and private work notes, attach files, and track request updates in the activity stream. - IRQ process management
The first internal step after an engagement request is approved is to start the IRQ process to scope the risk by determining the third party's risk score. - Third-party (external) risk assessment management
After the IRQ process is complete, you send questionnaires and document requests to the third-party contact. You manage the third-party risk assessment by working with the contacts to help ensure that the responses are complete and accurate. - Approval process management
You can view the list of users who can approve or reject a DD request and also view the details of their approval actions. In addition, you can view the approval levels for a request. - Risk intelligence report requests management
You can view a list of risk intelligence report (RIR) requests, their associated providers, scores, and report URLs. In addition, you can create requests and make updates by using the Third-party Risk Management application. - Scoring calculations using the classic assessment engine
Perform a comprehensive external risk assessment when calculating multiple ratings and scores by using the Third-party Risk Management application. You can gain a deeper understanding of the overall calculation process and learn how user-defined parameters and configurations influence the results of the questionnaires. - Third-party risk management data model
Use the Third-party Risk Management (TPRM) data model to assess, monitor, and mitigate the risks for your risk management program. - Domain separation and Third-party Risk Management
Domain separation is supported for TPRM. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data. - Vendor Risk Overview reports — Legacy view
The Vendor Risk Overview page is replaced by the third-party risk reports on the Vendor Management Workspace.
Parent Topic:Governance, Risk, and Compliance