{"id":70149,"date":"2026-09-24T11:20:52","date_gmt":"2026-09-24T09:20:52","guid":{"rendered":"https:\/\/www.usd.de\/?page_id=70149"},"modified":"2026-09-24T11:20:53","modified_gmt":"2026-09-24T09:20:53","slug":"third-party-risk-management-tprm","status":"publish","type":"page","link":"https:\/\/www.usd.de\/en\/security-consulting\/third-party-risk-management-tprm\/","title":{"rendered":"Third-Party Risk Management (TPRM)"},"content":{"rendered":"<p>[et_pb_section fb_built=\"1\" _builder_version=\"4.16\" _module_preset=\"default\" custom_padding=\"0px||0px||true|false\" locked=\"off\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_row _builder_version=\"4.16\" _module_preset=\"default\" width=\"100%\" custom_padding=\"0px||||false|false\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_column type=\"4_4\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_text _builder_version=\"4.27.9\" _module_preset=\"default\" text_text_color=\"#FFFFFF\" text_font_size=\"30px\" text_line_height=\"1.2em\" header_font=\"Roboto||||||||\" header_text_color=\"#F07F1D\" header_font_size=\"50px\" background_color=\"RGBA(255,255,255,0)\" background_image=\"https:\/\/www.usd.de\/wp-content\/uploads\/usd-security-audits-header-tprm.jpg\" background_blend=\"multiply\" custom_margin=\"-25px||0px||false|false\" custom_padding=\"95px||60px||false|false\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<h1 style=\"text-align: center;line-height: 120%;font-weight: 400\"><span class=\"NormalTextRun SCXW103211197 BCX0\" data-ccp-parastyle=\"heading 1\">Third<\/span><span class=\"NormalTextRun SCXW103211197 BCX0\" data-ccp-parastyle=\"heading 1\">-<\/span><span class=\"NormalTextRun SCXW103211197 BCX0\" data-ccp-parastyle=\"heading 1\">Party Risk Management<\/span><\/h1>\n<p style=\"text-align: center;line-height: 130%\"><span data-contrast=\"none\" xml:lang=\"DE-DE\" lang=\"DE-DE\" class=\"TextRun SCXW131194876 BCX0\"><span class=\"NormalTextRun SCXW131194876 BCX0\"><span data-contrast=\"none\" xml:lang=\"EN-US\" lang=\"EN-US\" class=\"TextRun SCXW23976044 BCX0\"><span class=\"NormalTextRun SCXW23976044 BCX0\">Effectively Manage Third-Party Risks<\/span><\/span>.<\/span><\/span><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=\"1_2,1_2\" _builder_version=\"4.27.7\" _module_preset=\"default\" custom_padding=\"10px||32px|||\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_column type=\"1_2\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_image src=\"https:\/\/www.usd.de\/wp-content\/uploads\/usd-security-audits-kachel-tprm.jpg\" alt=\"Harmonisierung mit BAIT\" title_text=\"usd-security-audits-kachel-tprm\" _builder_version=\"4.27.9\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][\/et_pb_image][\/et_pb_column][et_pb_column type=\"1_2\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_text _builder_version=\"4.27.7\" _module_preset=\"default\" background_color=\"RGBA(0,0,0,0)\" custom_margin=\"0px|0px|0px|0px|true|true\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<p><span>The more your organization works with external service providers, cloud providers, and technology partners, the more important it becomes to maintain transparency over critical dependencies. Today, many organizations need to know more than which service providers they use. They also need to assess the risks these providers create, which requirements apply, and whether controls, contracts, and evidence stand up to audit scrutiny. &nbsp;<\/span><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=\"4.16\" _module_preset=\"default\" custom_padding=\"12px||0px|||\" locked=\"off\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_column type=\"4_4\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_text _builder_version=\"4.27.9\" _module_preset=\"default\" background_color=\"RGBA(0,0,0,0)\" custom_margin=\"0px|0px|0px|0px|true|true\" custom_padding=\"||17px|||\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<p><strong><span data-contrast=\"auto\" xml:lang=\"EN-US\" lang=\"EN-US\" class=\"TextRun SCXW56347440 BCX0\"><span class=\"NormalTextRun SCXW56347440 BCX0\" data-ccp-parastyle=\"Heading 2\">Third-Party Risk Management (<\/span><\/span><span data-contrast=\"auto\" xml:lang=\"EN-US\" lang=\"EN-US\" class=\"TextRun SCXW56347440 BCX0\"><span class=\"NormalTextRun SCXW56347440 BCX0\" data-ccp-parastyle=\"Heading 2\">TPRM)<\/span><\/span><\/strong><span data-contrast=\"auto\" xml:lang=\"EN-US\" lang=\"EN-US\" class=\"TextRun SCXW56347440 BCX0\"><span class=\"NormalTextRun SCXW56347440 BCX0\" data-ccp-parastyle=\"Heading 2\">, also known as<span data-contrast=\"auto\" xml:lang=\"EN-US\" lang=\"EN-US\" class=\"TextRun SCXW247526481 BCX0\"><span class=\"NormalTextRun SCXW247526481 BCX0\"> vendor risk management, ICT third-party risk, supply chain security, or information security for supplier relationships, <\/span><\/span>provides the foundation for this. It helps you capture third-party relationships in a structured way, assess risks transparently, and manage service providers throughout their lifecycle. This ranges from <\/span><span class=\"NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW56347440 BCX0\" data-ccp-parastyle=\"Heading 2\">the initial<\/span><span class=\"NormalTextRun SCXW56347440 BCX0\" data-ccp-parastyle=\"Heading 2\"> risk analysis and due diligence to <\/span><span class=\"NormalTextRun SCXW56347440 BCX0\" data-ccp-parastyle=\"Heading 2\">S<\/span><span class=\"NormalTextRun SCXW56347440 BCX0\" data-ccp-parastyle=\"Heading 2\">ervice <\/span><span class=\"NormalTextRun SCXW56347440 BCX0\" data-ccp-parastyle=\"Heading 2\">P<\/span><span class=\"NormalTextRun SCXW56347440 BCX0\" data-ccp-parastyle=\"Heading 2\">rovider <\/span><span class=\"NormalTextRun SCXW56347440 BCX0\" data-ccp-parastyle=\"Heading 2\">A<\/span><span class=\"NormalTextRun SCXW56347440 BCX0\" data-ccp-parastyle=\"Heading 2\">udits, monitoring, and <\/span><span class=\"NormalTextRun SCXW56347440 BCX0\" data-ccp-parastyle=\"Heading 2\">exit strategies<\/span><\/span>.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=\"4.24.1\" _module_preset=\"default\" custom_margin=\"30px||||false|false\" custom_padding=\"0px||0px|||\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_column type=\"4_4\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_text _builder_version=\"4.27.7\" _module_preset=\"default\" custom_padding=\"9px|||||\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<h2><span class=\"NormalTextRun SCXW74275456 BCX0\" data-ccp-parastyle=\"heading 2\"><span data-contrast=\"none\" xml:lang=\"EN-US\" lang=\"EN-US\" class=\"TextRun SCXW65818542 BCX0\"><span class=\"NormalTextRun SCXW65818542 BCX0\" data-ccp-parastyle=\"Heading 2\">Regulatory Requirements and Standards for<\/span><\/span>&nbsp;<\/span><span class=\"NormalTextRun SCXW74275456 BCX0\" data-ccp-parastyle=\"heading 2\">TPRM<\/span><\/h2>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=\"4.27.7\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_column type=\"4_4\" _builder_version=\"4.27.7\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_text _builder_version=\"4.27.7\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<p><span class=\"NormalTextRun SCXW161666948 BCX0\">In addition to the need to effectively manage risks from third-party relationships, regulatory requirements and recognized standards add further expectations for Third-Party Risk Management. Organizations must be able to provide audit-proof evidence showing which third parties are critical, which risks arise from these relationships, and how these risks are assessed, managed, and <\/span><span class=\"NormalTextRun SCXW161666948 BCX0\">monitored.<\/span><\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=\"4.27.7\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<p><span data-contrast=\"auto\">The core objective remains the same: identify risks from external dependencies early, assess them appropriately, manage them effectively, and provide reliable evidence.<\/span><span data-ccp-props=\"{}\"> <\/span><span style=\"font-size: 16px\">Key requirements include in particular:<\/span><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=\"1_4,3_4\" _builder_version=\"4.24.1\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_column type=\"1_4\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_image src=\"https:\/\/www.usd.de\/wp-content\/uploads\/tprm-regulatorische-anforderungen-nis-2.svg\" alt=\"PCI Zertifizierungsprozess Kick-off\" title_text=\"tprm-regulatorische-anforderungen-nis-2\" align=\"center\" _builder_version=\"4.27.9\" _module_preset=\"default\" background_color=\"RGBA(0,0,0,0)\" width=\"60%\" width_tablet=\"20%\" width_phone=\"30%\" width_last_edited=\"on|tablet\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][\/et_pb_image][\/et_pb_column][et_pb_column type=\"3_4\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_text _builder_version=\"4.27.9\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<h3>NIS-2: <span data-contrast=\"auto\" xml:lang=\"EN-US\" lang=\"EN-US\" class=\"TextRun SCXW111428358 BCX0\"><span class=\"NormalTextRun SCXW111428358 BCX0\"> Supply Chain Security<\/span><\/span><\/h3>\n<p><span data-contrast=\"auto\" xml:lang=\"EN-US\" lang=\"EN-US\" class=\"TextRun SCXW91427100 BCX0\"><span class=\"NormalTextRun SCXW91427100 BCX0\">NIS-2 requires organizations to include risks from service provider and supplier relationships in their cybersecurity risk-management measures. This also includes security-related aspects concerning relationships with direct suppliers and service providers. The NIS-2 Directive explicitly names supply chain security as part of cybersecurity risk-management measures<\/span><\/span>.<br \/>&nbsp;<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=\"1_4,3_4\" _builder_version=\"4.24.1\" _module_preset=\"default\" custom_padding=\"0px||15px|||\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_column type=\"1_4\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_image src=\"https:\/\/www.usd.de\/wp-content\/uploads\/tprm-regulatorische-anforderungen-dora.svg\" alt=\"PCI Zertifizierungsprozess Kick-off\" title_text=\"tprm-regulatorische-anforderungen-dora\" align=\"center\" _builder_version=\"4.27.9\" _module_preset=\"default\" background_color=\"RGBA(0,0,0,0)\" width=\"60%\" width_tablet=\"20%\" width_phone=\"30%\" width_last_edited=\"on|tablet\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][\/et_pb_image][\/et_pb_column][et_pb_column type=\"3_4\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_text _builder_version=\"4.27.9\" _module_preset=\"default\" custom_margin=\"||0px||false|false\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<h3>DORA: <span data-contrast=\"auto\" xml:lang=\"EN-US\" lang=\"EN-US\" class=\"TextRun SCXW26167243 BCX0\"><span class=\"NormalTextRun SCXW26167243 BCX0\">Management of ICT Third-Party Risk<\/span><\/span><\/h3>\n<p><span data-contrast=\"auto\" xml:lang=\"EN-US\" lang=\"EN-US\" class=\"TextRun SCXW183774959 BCX0\"><span class=\"NormalTextRun SCXW183774959 BCX0\">DORA requires financial entities to <\/span><span class=\"NormalTextRun SCXW183774959 BCX0\">identify<\/span><span class=\"NormalTextRun SCXW183774959 BCX0\">, assess, and continuously <\/span><\/span><a class=\"Hyperlink SCXW183774959 BCX0\" href=\"https:\/\/www.usd.de\/en\/dora-reporting-ict-related-incidents\/\" target=\"_blank\" rel=\"noreferrer noopener\"><span data-contrast=\"none\" xml:lang=\"EN-US\" lang=\"EN-US\" class=\"TextRun Underlined SCXW183774959 BCX0\"><span class=\"NormalTextRun SCXW183774959 BCX0\" data-ccp-charstyle=\"Hyperlink\">monitor<\/span><\/span><\/a><span data-contrast=\"auto\" xml:lang=\"EN-US\" lang=\"EN-US\" class=\"TextRun SCXW183774959 BCX0\"><span class=\"NormalTextRun SCXW183774959 BCX0\"> ICT third-party risk as part of their ICT risk management. This includes, among other things, a strategy on ICT third-party risk, contractual arrangements covering security and resilience requirements, and a continuously maintained register of information covering all ICT third-party service providers<\/span><\/span>.<\/p>\n<p>&nbsp;[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=\"1_4,3_4\" _builder_version=\"4.24.1\" _module_preset=\"default\" custom_padding=\"0px||50px|||\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_column type=\"1_4\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_image src=\"https:\/\/www.usd.de\/wp-content\/uploads\/tprm-regulatorische-anforderungen-marisk.svg\" alt=\"PCI Zertifizierungsprozess Kick-off\" title_text=\"tprm-regulatorische-anforderungen-marisk\" align=\"center\" _builder_version=\"4.27.9\" _module_preset=\"default\" background_color=\"RGBA(0,0,0,0)\" width=\"60%\" width_tablet=\"20%\" width_phone=\"30%\" width_last_edited=\"on|tablet\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][\/et_pb_image][\/et_pb_column][et_pb_column type=\"3_4\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_text _builder_version=\"4.27.9\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<h3><span class=\"NormalTextRun SCXW63609447 BCX0\">Minimum<\/span><span class=\"NormalTextRun SCXW63609447 BCX0\"> Requirements for Risk Management<\/span>&nbsp;(MaRisk)<\/h3>\n<p><span class=\"NormalTextRun SCXW74981982 BCX0\">MaRisk <\/span><span class=\"NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW74981982 BCX0\">sets<\/span><span class=\"NormalTextRun SCXW74981982 BCX0\"> requirements for assessing, managing, and <\/span><span class=\"NormalTextRun SCXW74981982 BCX0\">monitoring<\/span><span class=\"NormalTextRun SCXW74981982 BCX0\"> outsourcing arrangements and other external procurement of services. This makes Third-Party Risk Management particularly relevant when external service providers support material processes, IT services, or control functions. Important: The latest MaRisk amendment resolves <\/span><span class=\"NormalTextRun SCXW74981982 BCX0\">previous<\/span><span class=\"NormalTextRun SCXW74981982 BCX0\"> overlaps between DORA and MaRisk. If a service provider falls under both MaRisk and DORA, DORA applies<\/span>.&nbsp;<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=\"1_4,3_4\" _builder_version=\"4.27.9\" _module_preset=\"default\" custom_padding=\"0px||10%||false|false\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_column type=\"1_4\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_image src=\"https:\/\/www.usd.de\/wp-content\/uploads\/tprm-regulatorische-anforderungen-iso.svg\" alt=\"PCI Zertifizierungsprozess Kick-off\" title_text=\"tprm-regulatorische-anforderungen-iso\" align=\"center\" _builder_version=\"4.27.9\" _module_preset=\"default\" background_color=\"RGBA(0,0,0,0)\" width=\"60%\" width_tablet=\"20%\" width_phone=\"30%\" width_last_edited=\"on|tablet\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][\/et_pb_image][\/et_pb_column][et_pb_column type=\"3_4\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_text _builder_version=\"4.27.9\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<h3>ISO 27001 and ISO 27036: <span data-contrast=\"auto\" xml:lang=\"EN-US\" lang=\"EN-US\" class=\"TextRun SCXW156506946 BCX0\"><span class=\"NormalTextRun SCXW156506946 BCX0\">Information Security for Supplier Relationships<\/span><\/span><\/h3>\n<p>I<span data-contrast=\"auto\" xml:lang=\"EN-US\" lang=\"EN-US\" class=\"TextRun SCXW81137999 BCX0\"><span class=\"NormalTextRun SCXW81137999 BCX0\">SO 27001 and ISO 27036 provide guidance on how organizations can address information security risks in supplier and service provider relationships in a structured way. This includes requirements for suppliers, responsibilities, security measures, and evidence<\/span><\/span>.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row disabled_on=\"on|on|off\" _builder_version=\"4.27.5\" _module_preset=\"default\" custom_padding=\"0px||0px|||\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_column type=\"4_4\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_text _builder_version=\"4.27.4\" _module_preset=\"default\" custom_margin=\"||0px||false|false\" custom_padding=\"9px||0px||false|false\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<h2 style=\"text-align: left\"><span data-contrast=\"none\" xml:lang=\"EN-US\" lang=\"EN-US\" class=\"TextRun SCXW229401292 BCX0\"><span class=\"NormalTextRun SCXW229401292 BCX0\">Why usd for Your Third-Party Risk Management<\/span><\/span><\/h2>\n<p>[\/et_pb_text][et_pb_slider show_content_on_mobile=\"off\" disabled_on=\"off|off|off\" _builder_version=\"4.27.9\" _module_preset=\"default\" body_text_align=\"center\" background_color=\"RGBA(0,0,0,0)\" background_image=\"https:\/\/www.usd.de\/wp-content\/uploads\/Slider-PCI-Beratung_BG.jpg\" background_size=\"contain\" custom_padding=\"60px||60px||true|false\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_slide _builder_version=\"4.27.9\" _module_preset=\"default\" header_level=\"h2\" body_text_align=\"left\" background_color=\"RGBA(0,0,0,0)\" background_enable_color=\"on\" text_orientation=\"left\" custom_padding=\"10%|||0px|false|false\" global_colors_info=\"{}\" sticky_transition=\"on\" theme_builder_area=\"post_content\"]<\/p>\n<h3 style=\"color: white;font-size: 140%;font-weight: 400;line-height: 140%;text-align: left\">Keep Business-Critical Risks in View <\/h3>\n<h3 style=\"color: white;font-size: 120%;font-weight: 300;line-height: 140%;text-align: left\">You gain transparency over which third parties<br \/>\nyour business processes depend on and where specific<br \/>\n security or compliance risks arise.<\/h3>\n<p>[\/et_pb_slide][et_pb_slide _builder_version=\"4.27.9\" _module_preset=\"default\" header_level=\"h2\" body_text_align=\"left\" background_color=\"RGBA(0,0,0,0)\" background_enable_color=\"on\" text_orientation=\"left\" custom_padding=\"10%|||0px|false|false\" global_colors_info=\"{}\" sticky_transition=\"on\" theme_builder_area=\"post_content\"]<\/p>\n<h3 style=\"color: white;font-size: 140%;font-weight: 400;line-height: 140%;text-align: left\">Create Audit-Ready Evidence <\/h3>\n<h3 style=\"color: white;font-size: 120%;font-weight: 300;line-height: 140%;text-align: left\">We translate requirements from DORA, NIS-2, MaRisk,<br \/>\nand ISO 27001 into transparent controls, documentation,<br \/>\nand a sound basis for decision-making.<\/h3>\n<p>[\/et_pb_slide][et_pb_slide _builder_version=\"4.27.9\" _module_preset=\"default\" header_level=\"h2\" body_text_align=\"left\" background_color=\"RGBA(0,0,0,0)\" background_enable_color=\"on\" text_orientation=\"left\" custom_padding=\"10%|||0px|false|false\" global_colors_info=\"{}\" sticky_transition=\"on\" theme_builder_area=\"post_content\"]<\/p>\n<h3 style=\"color: white;font-size: 140%;font-weight: 400;line-height: 140%;text-align: left\">TPRM with the Right Sense of Proportion <\/h3>\n<h3 style=\"color: white;font-size: 120%;font-weight: 300;line-height: 140%;text-align: left\">We design your Third-Party Risk Management to fit your<br \/>\nrequirements, risks, and organizational context. Our focus<br \/>\nis on the measures that are actually relevant for your<br \/>\norganization.<\/h3>\n<p>[\/et_pb_slide][et_pb_slide _builder_version=\"4.27.9\" _module_preset=\"default\" header_level=\"h2\" body_text_align=\"left\" background_color=\"RGBA(0,0,0,0)\" background_enable_color=\"on\" text_orientation=\"left\" custom_padding=\"10%|||0px|false|false\" global_colors_info=\"{}\" sticky_transition=\"on\" theme_builder_area=\"post_content\"]<\/p>\n<h3 style=\"color: white;font-size: 140%;font-weight: 400;line-height: 140%;text-align: left\">Integrate TPRM into Existing Processes <\/h3>\n<h3 style=\"color: white;font-size: 120%;font-weight: 300;line-height: 140%;text-align: left\">We integrate your Third-Party Risk Management into<br \/>\nprocurement, IT, compliance, and business departments<br \/>\nso it works in day-to-day business. <\/h3>\n<p>[\/et_pb_slide][et_pb_slide _builder_version=\"4.27.9\" _module_preset=\"default\" header_level=\"h2\" body_text_align=\"left\" background_color=\"RGBA(0,0,0,0)\" background_enable_color=\"on\" text_orientation=\"left\" custom_padding=\"10%|||0px|false|false\" global_colors_info=\"{}\" sticky_transition=\"on\" theme_builder_area=\"post_content\"]<\/p>\n<h3 style=\"color: white;font-size: 140%;font-weight: 400;line-height: 140%;text-align: left\">Assess Third-Party Risks on a Sound Basis <\/h3>\n<h3 style=\"color: white;font-size: 120%;font-weight: 300;line-height: 140%;text-align: left\">We bring experience from security consulting, audits, and<br \/>\nregulated industries. This helps us assess third-party<br \/>\nrisks with a clear view of security and resilience. <\/h3>\n<p>[\/et_pb_slide][\/et_pb_slider][\/et_pb_column][\/et_pb_row][et_pb_row disabled_on=\"off|off|on\" _builder_version=\"4.27.9\" _module_preset=\"default\" custom_padding=\"0px||0px|||\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_column type=\"4_4\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_text _builder_version=\"4.27.9\" _module_preset=\"default\" custom_margin=\"||0px||false|false\" custom_padding=\"9px||0px||false|false\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<h2>Why usd for Your Third-Party Risk Management?<\/h2>\n<p>[\/et_pb_text][et_pb_slider _builder_version=\"4.27.9\" _module_preset=\"default\" background_color=\"RGBA(255,255,255,0)\" custom_padding=\"24px||24px||true|false\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_slide _builder_version=\"4.27.9\" _module_preset=\"default\" global_colors_info=\"{}\" sticky_transition=\"on\" theme_builder_area=\"post_content\"]<\/p>\n<h3>Keep Business-Critical Risks in View <\/h3>\n<p>You gain transparency over which third parties your business processes depend on and where specific security or compliance risks arise.[\/et_pb_slide][et_pb_slide _builder_version=\"4.27.9\" _module_preset=\"default\" global_colors_info=\"{}\" sticky_transition=\"on\" theme_builder_area=\"post_content\"]<\/p>\n<h3>Create Audit-Ready Evidence <\/h3>\n<p>We translate requirements from DORA, NIS-2, MaRisk, and ISO 27001 into transparent controls, documentation, and a sound basis for decision-making. [\/et_pb_slide][et_pb_slide _builder_version=\"4.27.9\" _module_preset=\"default\" global_colors_info=\"{}\" sticky_transition=\"on\" theme_builder_area=\"post_content\"]<\/p>\n<h3>TPRM with the Right Sense of Proportion<\/h3>\n<p>We design your Third-Party Risk Management to fit your requirements, risks, and organizational context. Our focus is on the measures that are actually relevant for your organization. [\/et_pb_slide][et_pb_slide _builder_version=\"4.27.9\" _module_preset=\"default\" global_colors_info=\"{}\" sticky_transition=\"on\" theme_builder_area=\"post_content\"]<\/p>\n<h3>Integrate TPRM into Existing Processes <\/h3>\n<p>We integrate your Third-Party Risk Management into procurement, IT, compliance, and business departments so it works in day-to-day business. [\/et_pb_slide][et_pb_slide _builder_version=\"4.27.9\" _module_preset=\"default\" global_colors_info=\"{}\" sticky_transition=\"on\" theme_builder_area=\"post_content\"]<\/p>\n<h3>Assess Third-Party Risks on a Sound Basis <\/h3>\n<p>We bring experience from security consulting, audits, and regulated industries. This helps us assess third-party risks with a clear view of security and resilience.[\/et_pb_slide][\/et_pb_slider][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=\"4.27.9\" _module_preset=\"default\" custom_padding=\"45px||2%||false|false\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_column type=\"4_4\" _builder_version=\"4.27.9\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_text _builder_version=\"4.27.4\" _module_preset=\"default\" custom_margin=\"||0px||false|false\" custom_padding=\"9px||0px||false|false\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<h2 style=\"text-align: left\"><span data-contrast=\"none\" xml:lang=\"EN-US\" lang=\"EN-US\" class=\"TextRun SCXW72286804 BCX0\"><span class=\"NormalTextRun CommentStart CommentHighlightPipeHovered CommentHighlightHovered SCXW72286804 BCX0\">How usd AG Supports You in Third-Party Risk Management<\/span><\/span><\/h2>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=\"4.27.9\" _module_preset=\"default\" custom_padding=\"0px|||||\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_column type=\"4_4\" _builder_version=\"4.27.9\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_text _builder_version=\"4.27.9\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<p><span class=\"NormalTextRun SCXW90158803 BCX0\">Third-Party Risk Management must fit your organization. Only when processes, responsibilities, assessments, and <\/span><span class=\"NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW90158803 BCX0\">evidence<\/span><span class=\"NormalTextRun SCXW90158803 BCX0\"> work in everyday practice does TPRM become more than a regulatory obligation. We support you in establishing, further developing, and <\/span><span class=\"NormalTextRun SCXW90158803 BCX0\">operating<\/span><span class=\"NormalTextRun SCXW90158803 BCX0\"> your Third-Party Risk Management<\/span>.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=\"4.27.9\" _module_preset=\"default\" custom_padding=\"0px|||||\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_column type=\"4_4\" _builder_version=\"4.27.9\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_accordion open_toggle_background_color=\"#FFFFFF\" closed_toggle_background_color=\"#FFFFFF\" icon_color=\"#F07F1D\" use_icon_font_size=\"on\" icon_font_size=\"23px\" _builder_version=\"4.27.9\" _module_preset=\"default\" body_font=\"|300|||||||\" body_font_size=\"16px\" custom_margin=\"4px|0px|-1px|0px|false|true\" border_radii=\"on|5px|5px|5px|5px\" border_color_all=\"#F6F6F6\" box_shadow_style=\"preset1\" box_shadow_spread=\"-11px\" box_shadow_color=\"rgba(0,0,0,0.22)\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_accordion_item title=\"Ihr Titel\" open=\"on\" _builder_version=\"4.27.9\" _module_preset=\"default\" custom_css_main_element=\"display: none;\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<p>Your content goes here. Edit or remove this text inline or in the module Content settings. You can also style every aspect of this content in the module Design settings and even apply custom CSS to this text in the module Advanced settings.<\/p>\n<p>[\/et_pb_accordion_item][et_pb_accordion_item title=\"Gap Analysis and Maturity Assessment\" closed_toggle_text_color=\"#3C3C3C\" _builder_version=\"4.27.9\" _module_preset=\"default\" border_radii=\"on|5px|5px|5px|5px\" global_colors_info=\"{}\" closed_toggle_font=\"|300|||||||\" closed_toggle_font_size=\"16px\" toggle_text_color__hover_enabled=\"on|hover\" toggle_text_color__hover=\"#F07F1D\" open_toggle_text_color__hover_enabled=\"on|hover\" open_toggle_text_color__hover=\"#F07F1D\" theme_builder_area=\"post_content\" open=\"off\"]<\/p>\n<p><span data-contrast=\"auto\">We analyze how your existing Third-Party Risk Management is set up and where action is needed. To do this, we review relevant policies, processes, roles, documentation, and control mechanisms based on regulatory requirements, internal specifications, and recognized standards. Interviews and workshops help us understand not only the documentation but also the actual implementation.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">You receive a structured assessment of your TPRM maturity level, specific areas for action, and a reliable basis for further prioritization.<\/span><\/p>\n<p>[\/et_pb_accordion_item][et_pb_accordion_item title=\"Establish and Further Develop Your Third-Party Risk Management \" closed_toggle_text_color=\"#3C3C3C\" _builder_version=\"4.27.9\" _module_preset=\"default\" border_radii=\"on|5px|5px|5px|5px\" global_colors_info=\"{}\" closed_toggle_font=\"|300|||||||\" closed_toggle_font_size=\"16px\" toggle_text_color__hover_enabled=\"on|hover\" toggle_text_color__hover=\"#F07F1D\" open_toggle_text_color__hover_enabled=\"on|hover\" open_toggle_text_color__hover=\"#F07F1D\" theme_builder_area=\"post_content\" open=\"off\"]<\/p>\n<p><span data-contrast=\"auto\">Together with you, we develop a TPRM approach that aligns regulatory requirements, organizational structures, and operational processes. We define roles and responsibilities, develop policies and assessment methods, and create a structured framework for managing third-party risks.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">You receive Third-Party Risk Management that translates requirements into processes, responsibilities, and decisions in a transparent way.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Depending on the maturity level and stability of your processes, we assess the automation potential of your TPRM process and advise and support you during implementation.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p>[\/et_pb_accordion_item][et_pb_accordion_item title=\"Transition Third-Party Risk Management into Regular Operations \" closed_toggle_text_color=\"#3C3C3C\" _builder_version=\"4.27.9\" _module_preset=\"default\" border_radii=\"on|5px|5px|5px|5px\" global_colors_info=\"{}\" closed_toggle_font=\"|300|||||||\" closed_toggle_font_size=\"16px\" toggle_text_color__hover_enabled=\"on|hover\" toggle_text_color__hover=\"#F07F1D\" open_toggle_text_color__hover_enabled=\"on|hover\" open_toggle_text_color__hover=\"#F07F1D\" theme_builder_area=\"post_content\" open=\"off\"]<\/p>\n<p><span data-contrast=\"auto\">We support you in putting TPRM processes into practice: from identifying and classifying relevant third parties to conducting risk assessments and ongoing monitoring. We integrate TPRM into existing governance, risk, procurement, and compliance processes and take requirements for supporting tools into account.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">You receive clear workflows, defined responsibilities, and a TPRM setup that works in day-to-day business and can be operated on an ongoing basis.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p>[\/et_pb_accordion_item][et_pb_accordion_item title=\"Supplier Monitoring and Supplier Audits\" closed_toggle_text_color=\"#3C3C3C\" _builder_version=\"4.27.9\" _module_preset=\"default\" border_radii=\"on|5px|5px|5px|5px\" global_colors_info=\"{}\" closed_toggle_font=\"|300|||||||\" closed_toggle_font_size=\"16px\" toggle_text_color__hover_enabled=\"on|hover\" toggle_text_color__hover=\"#F07F1D\" open_toggle_text_color__hover_enabled=\"on|hover\" open_toggle_text_color__hover=\"#F07F1D\" theme_builder_area=\"post_content\" open=\"off\"]<\/p>\n<p><span data-contrast=\"auto\">As part of risk-based monitoring of third parties, we assess whether service providers comply with regulatory requirements, internal specifications, and agreed security measures. To do this, we analyze self-assessments, certifications, evidence, and other information from the collaboration. In cases of increased risk or specific requirements, our auditors conduct in-depth Supplier Audits.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">You receive reliable insights into risks, deviations, and required actions among your service providers. This creates a sound basis for further measures, management decisions, and regulatory evidence.<\/span><\/p>\n<p><a href=\"https:\/\/www.usd.de\/en\/security-audits\/supplier-audit\/\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\" xml:lang=\"EN-US\" lang=\"EN-US\" class=\"TextRun Highlight SCXW141932795 BCX0\"><span class=\"NormalTextRun SCXW141932795 BCX0\">Learn More About Supplier Audits<\/span><\/span><\/a><\/p>\n<p>[\/et_pb_accordion_item][et_pb_accordion_item title=\"Operational Support in Third-Party Risk Management \" closed_toggle_text_color=\"#3C3C3C\" _builder_version=\"4.27.9\" _module_preset=\"default\" border_radii=\"on|5px|5px|5px|5px\" global_colors_info=\"{}\" closed_toggle_font=\"|300|||||||\" closed_toggle_font_size=\"16px\" toggle_text_color__hover_enabled=\"on|hover\" toggle_text_color__hover=\"#F07F1D\" open_toggle_text_color__hover_enabled=\"on|hover\" open_toggle_text_color__hover=\"#F07F1D\" theme_builder_area=\"post_content\" open=\"off\"]<\/p>\n<p><span data-contrast=\"auto\">We help reduce the operational workload for your teams along the TPRM process. This includes identifying relevant service providers, conducting risk assessments, reviewing self-assessments, certificates, and evidence, as well as coordinating and tracking measures. We also support you with reporting, monitoring, and escalation processes.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">You receive scalable TPRM operations that relieve internal resources and ensure continuous assessment and monitoring of your third parties.<\/span><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.usd.de\/wp-content\/uploads\/TPRM-Infografik-EN.jpg\"><\/p>\n<p>[\/et_pb_accordion_item][\/et_pb_accordion][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=\"4.16\" _module_preset=\"default\" custom_margin=\"-8px||||false|false\" custom_padding=\"||2px|||\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_column type=\"4_4\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_divider color=\"#d8d8d8\" _builder_version=\"4.27.9\" _module_preset=\"default\" custom_margin=\"2%||||false|false\" custom_padding=\"2%||||false|false\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][\/et_pb_divider][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=\"4.16\" _module_preset=\"default\" custom_margin=\"|auto|18px|auto||\" custom_padding=\"0px||1px|||\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_column type=\"4_4\" _builder_version=\"4.16\" _module_preset=\"default\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"][et_pb_text _builder_version=\"4.27.9\" _module_preset=\"default\" custom_padding=\"9px|||||\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<h2><span data-contrast=\"none\" xml:lang=\"DE-DE\" lang=\"DE-DE\" class=\"TextRun SCXW24189099 BCX0\"><span class=\"NormalTextRun SCXW24189099 BCX0\"><span data-contrast=\"none\" xml:lang=\"EN-US\" lang=\"EN-US\" class=\"TextRun SCXW136410241 BCX0\"><span class=\"NormalTextRun SCXW136410241 BCX0\">More Information on <\/span><\/span>Third<\/span><span class=\"NormalTextRun SCXW24189099 BCX0\">-<\/span><span class=\"NormalTextRun SCXW24189099 BCX0\">Party Risk Management<\/span><\/span><span class=\"EOP Selected SCXW24189099 BCX0\" data-ccp-props=\"{}\">&nbsp;<\/span><\/h2>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=\"1_2,1_2\" use_custom_gutter=\"on\" gutter_width=\"2\" make_equal=\"on\" _builder_version=\"4.27.9\" _module_preset=\"default\" background_color=\"RGBA(0,0,0,0)\" custom_margin=\"0px|auto|1px|auto|false|false\" custom_padding=\"0px|7px|26px|7px|false|true\" hover_enabled=\"0\" global_colors_info=\"{}\" theme_builder_area=\"post_content\" sticky_enabled=\"0\"][et_pb_column type=\"1_2\" _builder_version=\"4.27.9\" _module_preset=\"default\" background_color=\"rgba(0,0,0,0.65)\" background_image=\"https:\/\/www.usd.de\/wp-content\/uploads\/usd-ag-third-party-risk-management.jpg\" background_blend=\"multiply\" background_enable_video_mp4=\"off\" custom_padding=\"0px|0px|0px|0px|true|true\" link_option_url=\"https:\/\/www.usd.de\/en\/third-party-risk-management-basics\/\" hover_enabled=\"0\" background_last_edited=\"off|desktop\" border_width_all=\"1px\" border_color_all=\"#F6F6F6\" global_colors_info=\"{}\" background__hover_enabled=\"off|hover\" background_enable_color__hover=\"off\" background_image__hover=\"https:\/\/www.usd.de\/wp-content\/uploads\/news-success-story-cashpoint.jpeg\" background_enable_image__hover=\"on\" theme_builder_area=\"post_content\" sticky_enabled=\"0\"][et_pb_text _builder_version=\"4.27.9\" _module_preset=\"51ae1141-d3aa-4d8e-88be-0448f8284f54\" background_color=\"RGBA(0,0,0,0)\" custom_margin=\"28px||3px||false|false\" custom_padding=\"9px|34px|0px|34px|false|true\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<h3 style=\"text-align: center\"><span style=\"color: #ffffff\"><\/span><\/h3>\n<h3 style=\"text-align: center\"><span style=\"color: #ffffff\">Information Security in Third-Party Risk Management<\/span><\/h3>\n<p>&nbsp;<\/p>\n<p>[\/et_pb_text][\/et_pb_column][et_pb_column type=\"1_2\" _builder_version=\"4.27.9\" _module_preset=\"default\" background_color=\"rgba(0,0,0,0.65)\" background_image=\"https:\/\/www.usd.de\/wp-content\/uploads\/usd-ag-third-party-risk-management.jpg\" background_blend=\"multiply\" background_enable_video_mp4=\"off\" custom_padding=\"0px|0px|0px|0px|true|true\" link_option_url=\"https:\/\/www.usd.de\/en\/third-party-risk-management-set-up-tprm-program\/\" hover_enabled=\"0\" background_last_edited=\"off|desktop\" border_width_all=\"1px\" border_color_all=\"#F6F6F6\" global_colors_info=\"{}\" background__hover_enabled=\"off|hover\" background_enable_color__hover=\"off\" background_image__hover=\"https:\/\/www.usd.de\/wp-content\/uploads\/news-success-story-cashpoint.jpeg\" background_enable_image__hover=\"on\" theme_builder_area=\"post_content\" sticky_enabled=\"0\"][et_pb_text _builder_version=\"4.27.9\" _module_preset=\"51ae1141-d3aa-4d8e-88be-0448f8284f54\" background_color=\"RGBA(0,0,0,0)\" custom_margin=\"28px||3px||false|false\" custom_padding=\"9px|34px|0px|34px|false|true\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<h3 style=\"text-align: center\"><span style=\"color: #ffffff\"><\/span><\/h3>\n<h3 style=\"text-align: center\"><span style=\"color: #ffffff\">How to Build a TPRM Program<\/span><\/h3>\n<p>&nbsp;<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=\"1_2,1_2\" use_custom_gutter=\"on\" gutter_width=\"2\" make_equal=\"on\" _builder_version=\"4.27.9\" _module_preset=\"default\" background_color=\"RGBA(0,0,0,0)\" custom_margin=\"0px|auto||auto|false|false\" custom_padding=\"0px|7px|40px|7px|false|true\" hover_enabled=\"0\" global_colors_info=\"{}\" theme_builder_area=\"post_content\" sticky_enabled=\"0\"][et_pb_column type=\"1_2\" _builder_version=\"4.27.9\" _module_preset=\"default\" background_color=\"rgba(0,0,0,0.65)\" background_image=\"https:\/\/www.usd.de\/wp-content\/uploads\/usd-ag-third-party-risk-management.jpg\" background_blend=\"multiply\" background_enable_video_mp4=\"off\" custom_padding=\"0px|0px|0px|0px|true|true\" link_option_url=\"https:\/\/www.usd.de\/en\/third-party-risk-management-monitoring-tprm-program\/\" hover_enabled=\"0\" background_last_edited=\"off|desktop\" border_width_all=\"1px\" border_color_all=\"#F6F6F6\" global_colors_info=\"{}\" background__hover_enabled=\"off|hover\" background_enable_color__hover=\"off\" background_image__hover=\"https:\/\/www.usd.de\/wp-content\/uploads\/news-success-story-cashpoint.jpeg\" background_enable_image__hover=\"on\" theme_builder_area=\"post_content\" sticky_enabled=\"0\"][et_pb_text _builder_version=\"4.27.9\" _module_preset=\"51ae1141-d3aa-4d8e-88be-0448f8284f54\" background_color=\"RGBA(0,0,0,0)\" custom_margin=\"28px||3px||false|false\" custom_padding=\"9px|34px|0px|34px|false|true\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<h3 style=\"text-align: center\"><span style=\"color: #ffffff\">How to Monitor Your TPRM Program<\/span><\/h3>\n<p>&nbsp;<\/p>\n<p>[\/et_pb_text][\/et_pb_column][et_pb_column type=\"1_2\" _builder_version=\"4.27.9\" _module_preset=\"default\" background_color=\"rgba(0,0,0,0.65)\" background_image=\"https:\/\/www.usd.de\/wp-content\/uploads\/usd-ag-third-party-risk-management.jpg\" background_blend=\"multiply\" background_enable_video_mp4=\"off\" custom_padding=\"0px|0px|0px|0px|true|true\" link_option_url=\"https:\/\/www.usd.de\/en\/third-party-risk-management-dora\/\" hover_enabled=\"0\" background_last_edited=\"off|desktop\" border_width_all=\"1px\" border_color_all=\"#F6F6F6\" global_colors_info=\"{}\" background__hover_enabled=\"off|hover\" background_enable_color__hover=\"off\" background_image__hover=\"https:\/\/www.usd.de\/wp-content\/uploads\/news-success-story-cashpoint.jpeg\" background_enable_image__hover=\"on\" theme_builder_area=\"post_content\" sticky_enabled=\"0\"][et_pb_text _builder_version=\"4.27.9\" _module_preset=\"51ae1141-d3aa-4d8e-88be-0448f8284f54\" background_color=\"RGBA(0,0,0,0)\" custom_margin=\"28px||3px||false|false\" custom_padding=\"9px|34px|0px|34px|false|true\" global_colors_info=\"{}\" theme_builder_area=\"post_content\"]<\/p>\n<h3 style=\"text-align: center\"><span style=\"color: #ffffff\">Third\u2011Party Risk Management under DORA<\/span><\/h3>\n<p>&nbsp;<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Third-Party Risk Management Effectively Manage Third-Party Risks.The more your organization works with external service providers, cloud providers, and technology partners, the more important it becomes to maintain transparency over critical dependencies. Today, many organizations need to know more than which service providers they use. They also need to assess the risks these providers create, which [&hellip;]<\/p>\n","protected":false},"author":92,"featured_media":0,"parent":11659,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","inline_featured_image":false,"footnotes":""},"class_list":["post-70149","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/pages\/70149","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/users\/92"}],"replies":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/comments?post=70149"}],"version-history":[{"count":5,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/pages\/70149\/revisions"}],"predecessor-version":[{"id":70240,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/pages\/70149\/revisions\/70240"}],"up":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/pages\/11659"}],"wp:attachment":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/media?parent=70149"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}