Third-Party Risk Management

Effectively Manage Third-Party Risks.

Harmonisierung mit BAIT

The more your organization works with external service providers, cloud providers, and technology partners, the more important it becomes to maintain transparency over critical dependencies. Today, many organizations need to know more than which service providers they use. They also need to assess the risks these providers create, which requirements apply, and whether controls, contracts, and evidence stand up to audit scrutiny.  

Third-Party Risk Management (TPRM), also known as vendor risk management, ICT third-party risk, supply chain security, or information security for supplier relationships, provides the foundation for this. It helps you capture third-party relationships in a structured way, assess risks transparently, and manage service providers throughout their lifecycle. This ranges from the initial risk analysis and due diligence to Service Provider Audits, monitoring, and exit strategies.

Regulatory Requirements and Standards for TPRM

In addition to the need to effectively manage risks from third-party relationships, regulatory requirements and recognized standards add further expectations for Third-Party Risk Management. Organizations must be able to provide audit-proof evidence showing which third parties are critical, which risks arise from these relationships, and how these risks are assessed, managed, and monitored.

The core objective remains the same: identify risks from external dependencies early, assess them appropriately, manage them effectively, and provide reliable evidence. Key requirements include in particular:

PCI Zertifizierungsprozess Kick-off

NIS-2: Supply Chain Security

NIS-2 requires organizations to include risks from service provider and supplier relationships in their cybersecurity risk-management measures. This also includes security-related aspects concerning relationships with direct suppliers and service providers. The NIS-2 Directive explicitly names supply chain security as part of cybersecurity risk-management measures.
 

PCI Zertifizierungsprozess Kick-off

DORA: Management of ICT Third-Party Risk

DORA requires financial entities to identify, assess, and continuously monitor ICT third-party risk as part of their ICT risk management. This includes, among other things, a strategy on ICT third-party risk, contractual arrangements covering security and resilience requirements, and a continuously maintained register of information covering all ICT third-party service providers.

 

PCI Zertifizierungsprozess Kick-off

Minimum Requirements for Risk Management (MaRisk)

MaRisk sets requirements for assessing, managing, and monitoring outsourcing arrangements and other external procurement of services. This makes Third-Party Risk Management particularly relevant when external service providers support material processes, IT services, or control functions. Important: The latest MaRisk amendment resolves previous overlaps between DORA and MaRisk. If a service provider falls under both MaRisk and DORA, DORA applies. 

PCI Zertifizierungsprozess Kick-off

ISO 27001 and ISO 27036: Information Security for Supplier Relationships

ISO 27001 and ISO 27036 provide guidance on how organizations can address information security risks in supplier and service provider relationships in a structured way. This includes requirements for suppliers, responsibilities, security measures, and evidence.

Why usd for Your Third-Party Risk Management

Keep Business-Critical Risks in View

You gain transparency over which third parties
your business processes depend on and where specific
security or compliance risks arise.

Create Audit-Ready Evidence

We translate requirements from DORA, NIS-2, MaRisk,
and ISO 27001 into transparent controls, documentation,
and a sound basis for decision-making.

TPRM with the Right Sense of Proportion

We design your Third-Party Risk Management to fit your
requirements, risks, and organizational context. Our focus
is on the measures that are actually relevant for your
organization.

Integrate TPRM into Existing Processes

We integrate your Third-Party Risk Management into
procurement, IT, compliance, and business departments
so it works in day-to-day business.

Assess Third-Party Risks on a Sound Basis

We bring experience from security consulting, audits, and
regulated industries. This helps us assess third-party
risks with a clear view of security and resilience.

Why usd for Your Third-Party Risk Management?

Keep Business-Critical Risks in View

You gain transparency over which third parties your business processes depend on and where specific security or compliance risks arise.

Create Audit-Ready Evidence

We translate requirements from DORA, NIS-2, MaRisk, and ISO 27001 into transparent controls, documentation, and a sound basis for decision-making.

TPRM with the Right Sense of Proportion

We design your Third-Party Risk Management to fit your requirements, risks, and organizational context. Our focus is on the measures that are actually relevant for your organization.

Integrate TPRM into Existing Processes

We integrate your Third-Party Risk Management into procurement, IT, compliance, and business departments so it works in day-to-day business.

Assess Third-Party Risks on a Sound Basis

We bring experience from security consulting, audits, and regulated industries. This helps us assess third-party risks with a clear view of security and resilience.

How usd AG Supports You in Third-Party Risk Management

Third-Party Risk Management must fit your organization. Only when processes, responsibilities, assessments, and evidence work in everyday practice does TPRM become more than a regulatory obligation. We support you in establishing, further developing, and operating your Third-Party Risk Management.

Ihr Titel

Your content goes here. Edit or remove this text inline or in the module Content settings. You can also style every aspect of this content in the module Design settings and even apply custom CSS to this text in the module Advanced settings.

Gap Analysis and Maturity Assessment

We analyze how your existing Third-Party Risk Management is set up and where action is needed. To do this, we review relevant policies, processes, roles, documentation, and control mechanisms based on regulatory requirements, internal specifications, and recognized standards. Interviews and workshops help us understand not only the documentation but also the actual implementation. 

You receive a structured assessment of your TPRM maturity level, specific areas for action, and a reliable basis for further prioritization.

Establish and Further Develop Your Third-Party Risk Management

Together with you, we develop a TPRM approach that aligns regulatory requirements, organizational structures, and operational processes. We define roles and responsibilities, develop policies and assessment methods, and create a structured framework for managing third-party risks. 

You receive Third-Party Risk Management that translates requirements into processes, responsibilities, and decisions in a transparent way. 

Depending on the maturity level and stability of your processes, we assess the automation potential of your TPRM process and advise and support you during implementation. 

Transition Third-Party Risk Management into Regular Operations

We support you in putting TPRM processes into practice: from identifying and classifying relevant third parties to conducting risk assessments and ongoing monitoring. We integrate TPRM into existing governance, risk, procurement, and compliance processes and take requirements for supporting tools into account. 

You receive clear workflows, defined responsibilities, and a TPRM setup that works in day-to-day business and can be operated on an ongoing basis. 

Supplier Monitoring and Supplier Audits

As part of risk-based monitoring of third parties, we assess whether service providers comply with regulatory requirements, internal specifications, and agreed security measures. To do this, we analyze self-assessments, certifications, evidence, and other information from the collaboration. In cases of increased risk or specific requirements, our auditors conduct in-depth Supplier Audits. 

You receive reliable insights into risks, deviations, and required actions among your service providers. This creates a sound basis for further measures, management decisions, and regulatory evidence.

Learn More About Supplier Audits

Operational Support in Third-Party Risk Management

We help reduce the operational workload for your teams along the TPRM process. This includes identifying relevant service providers, conducting risk assessments, reviewing self-assessments, certificates, and evidence, as well as coordinating and tracking measures. We also support you with reporting, monitoring, and escalation processes. 

You receive scalable TPRM operations that relieve internal resources and ensure continuous assessment and monitoring of your third parties.

More Information on Third-Party Risk Management 

Information Security in Third-Party Risk Management

 

How to Build a TPRM Program

 

How to Monitor Your TPRM Program

 

Third‑Party Risk Management under DORA

 

Felix Schmidt

 

Felix Schmidt
Executive Board Member usd Security Consulting

 

📞 +49 6102 8631-190
📧 sales@usd.de
🔐 S/MIME