Third-party risk management
Also called: TPRM
ELI5
How assessing and controlling risks created by suppliers, partners and other external parties.
Used in conversation
“Can we remove the ambiguity around third-party risk management before the process changes?”
Definition
The process of assessing and controlling risks created by suppliers, partners and other external parties.
Here “Third-party risk management” means: The process of assessing and controlling risks created by suppliers, partners and other external parties.
Pitch context
You will see “Third-party risk management” in board papers, contracts, policies, risk registers and compliance reports when the discussion reaches regulatory, ethics & conduct compliance.
Why it matters: In regulatory, ethics & conduct compliance, a loose definition can change rights, obligations, approval, disclosure or enforceability.
Caution
Meaning, enforceability and required process vary by jurisdiction and agreement; this definition is not legal advice.
Sources & evidence · 3
Direct term-level sources and supporting source families.
- OECD — G20/OECD Principles of Corporate Governance 2023Direct source · institutional · checked 2026-08-16
- National Institute of Standards and Technology — Computer Security Resource Center GlossaryDirect source · primary · checked 2026-08-16
- U.S. Securities and Exchange Commission — EDGAR and filing resourcesSupporting source family · primary · checked 2026-08-16