Regulatory, ethics & conduct compliance · Core

Third-party risk management

Also called: TPRM

ELI5

How assessing and controlling risks created by suppliers, partners and other external parties.

Used in conversation

“Can we remove the ambiguity around third-party risk management before the process changes?”

Definition

The process of assessing and controlling risks created by suppliers, partners and other external parties.

Here “Third-party risk management” means: The process of assessing and controlling risks created by suppliers, partners and other external parties.

Pitch context

You will see “Third-party risk management” in board papers, contracts, policies, risk registers and compliance reports when the discussion reaches regulatory, ethics & conduct compliance.

Why it matters: In regulatory, ethics & conduct compliance, a loose definition can change rights, obligations, approval, disclosure or enforceability.

Caution

Meaning, enforceability and required process vary by jurisdiction and agreement; this definition is not legal advice.

Sources & evidence · 3

Direct term-level sources and supporting source families.