Establishing the Operating Framework Involved in the Third Party Risk Life Cycle

Image of Third-Party Risk Life Cycle

SIG University  Certified  Third-Party Risk Management Professional  (C3PRMP) program graduate Erran Thomas discusses how to establish the operating framework of a Third-Party Risk life cycle


Regarding the Third Party Risk Management practice, we recognized that our organization performs many of the needed activities in a siloed manner. Many of the activities are happening in different ways to different levels of rigor, so there was a need to standardize the necessary actions, as we believe that it will help bring efficiency and support our organization in making better risk intelligent decisions, which in turn reduces time later.  

As a result, I will focus this essay on the learnings as it applies to establishing a formalized framework. The learnings covered in the C3PRMP course have helped by providing insights on some of the structured building blocks required in establishing a standardized Third Party Risk Management program (TPRM, which will be developed and piloted later this year). In one of the modules, Linda Tuck Chapman discussed the term’ operating framework’, which describes the necessary tasks and activities that organizations would go through within the TPRM lifecycle from the beginning of a relationship through termination or renewal. We’ve learned in the modules that the TPRM Framework (Operating Framework) sets out the requirements for effectively managing risks arising from Business Arrangements between our organization and Third Parties. This can range from arrangements that include products or services, business activities, functions, or processes that need to be undertaken.    

As a result, we organized our thought process by identifying the following stages in developing the program’s processes and procedures. The steps outlined should enable the ability for us to identify, assess and manage the risks that may arise from any of our new or existing Business Arrangements:

The first stage is determining the nature and complexity of the Third-Party business arrangement. Through the lessons, we learned about a helpful tool called Johari’s window, which allows the lines of business to understand clearly and additional thinking around business arrangements or requirements by adopting the principles of the following four pillars:

By adopting the principles around Johari’s window, we have a mechanism to collect essential information with the lines of business that would support critical business processes within our organization.

The next stage identifies specific risk characteristics applicable to the Business Arrangement. It ultimately determines the appropriate level of Due Diligence required. This stage is determined utilizing an Inherent Risk Questionnaire (IRQ). The Inherent risk determination will be conducted using a standardized assessment that Risk Owners complete to assess the inherent risk of a Business Arrangement. This mechanism allows for Due Diligence to be triggered through the summation of the score from each question resulting in an Inherent Risk score based on the thresholds below and for specific IRQ questions to auto-trigger risk domains based on their provided input.

The Due Diligence Questionnaire is the third stage facilitated by the Business Area in conjunction with the other Risk domain functions as required (e.g., Information Security, Privacy, Business Continuity, Corporate Security, Data Governance, etc.). Due Diligence would either be triggered by the answers to the specific IRQ questions or after all the Risk domain SMEs have reviewed the IRQ and indicate if Due Diligence is required to be included in the RFP package or not.  Once the Inherent Risk and Due Diligence scores have been determined, the Business Arrangements Residual Risk rating is determined by the Risk domain SMEs.

The residual risk rating indicates the remaining risk of the Arrangement after considering ‘compensating controls’ and is calculated by taking the inherent risk rating and deducting the Due Diligence ratings. In addition to individual residual risk ratings for each risk area, an overall residual risk rating is developed for the Business Arrangement itself by assigning a numerical value for the residual risk rating for each applicable risk area. The numerical values will be added to arrive at an aggregated value. The aggregated residual risk rating for the Arrangement is then determined based on where the aggregated value falls within a specified range.

Contractual Protections and Issues Management is the final step in the pre-contract phase of the TPRM lifecycle. Issues Management will be used to resolve all issues with a Third Party formally or to acknowledge any unique risks identified within the Due Diligence process to begin formally onboarding the Third Party. Contractual Protections are used to minimize the potential for loss by managing and controlling contract risks.  Based on the Due Diligence phase results, issues may arise due to a lack of controls or procedures observed within the Third-Party’s control environment.

The Issues Management component of the TPRM lifecycle aims to address these third-party issues, which compromises the identification of the problems, development of action plans, acceptance, monitoring, and closure of cases.  The Contractual Protections process will then be used to close out any outstanding issues with the Third-Party identified during risk assessments or to acknowledge the exceptional risks/issues identified through a revised legal agreement. Ongoing monitoring requirements will facilitate consistent, risk-based oversight of the Third Parties from contract execution to contract termination, ensuring that our organization enforces its rights and fulfills its obligations to the Third Party.

Ongoing monitoring cadence will be risk-adjusted and determined based on the risk of the Business Arrangement. Linda emphasized several times that we should always ensure that if there is a need to exit a relationship, back to the contracting process, we should make sure that we have a controlled exit because the third party will lose interest and will take their best people off the account when you’re exiting unless you cover for that right from the beginning. We will look to have this in place during negotiations to ensure we minimize any potential impacts to our organization, where possible.

In conclusion, we are in the conceptual phase process of designing the framework based on the stages discussed. We will adopt the notion of ‘starting with a start and keeping our end state in mind.’ Our program plans to have these stages/tools drafted by June. Once drawn, we will test these steps as part of a pilot with a small subset of procurements to ensure that the program allows us the mechanism to identify, assess, measure, control, and risk adjust the monitoring and reporting of our third-party risk in a dynamic and continuous process.


SIG University’s  Certified  Third-Party Risk Management Professional  (C3PRMP) program is a globally recognized certification that is the €œgold standard € in terms of relevance, scope and content. The C3PRMP  program was created by Linda Tuck Chapman, an advisor, educator, author and expert.