Manage third-party risk across the full relationship—not just at onboarding. Define what the provider will do and what could go wrong, assess evidence that fits the service, put workable protections in the agreement, monitor for meaningful changes, and plan how to exit. The depth of each step should reflect the relationship’s risk, criticality, and context; there is no single review cadence or checklist that fits every provider.
What third-party risk management covers
Third-party risk management (TPRM) is the governance and work used to understand and manage risks arising from relationships with external providers. A provider may supply a useful capability, but relying on it can reduce your organization’s direct operational control and introduce or increase risk. The relevance and scale of that risk depend on the relationship. The OCC’s community-bank guide explains this in the banking context, rather than establishing a universal template for every organization (OCC, Federal Reserve Board, and FDIC, May 3, 2024).
TPRM is broader than cybersecurity supply-chain risk management (C-SCRM). NIST SP 800-161 Rev. 1 Update 1 focuses on cybersecurity risks across products and services in the supply chain. It is a useful technical resource, not a universal TPRM law (NIST publication page).
The five lifecycle stages below are set out in U.S. interagency banking guidance. That guidance is for banking organizations; organizations in other sectors can use the lifecycle as a practical model, but should not treat it as a rule that automatically applies to them (OCC, Federal Reserve Board, and FDIC, June 6, 2023).
#1 Best Overall
| Stage | Purpose | Output to carry forward |
|---|---|---|
| Planning | Define the service, its context, dependencies, and plausible effects if it fails. | Service requirements and a proportionate assessment plan. |
| Due diligence and selection | Evaluate whether a provider can meet required outcomes and manage relevant risks. | A documented selection decision, including material gaps. |
| Contract negotiation | Make service expectations, oversight, remedies, and exit workable. | An agreement aligned to the actual relationship and its risks. |
| Ongoing monitoring | Check whether performance, exposure, or dependencies have changed. | Review, escalation, and remediation decisions. |
| Termination | End, replace, or transition the service while managing its effects. | An executed exit or transition plan and closure of relevant access and obligations. |
Set ownership, scope, and records
Before assessing providers, decide who owns the business relationship, who is accountable for its risk, who can approve exceptions, and how significant concerns reach senior management. Make responsibilities clear enough that a finding has an owner and a route to a decision.
Maintain an inventory that helps teams see the portfolio and its dependencies. Useful fields to consider include:
- Provider, service, internal business owner, and accountable risk owner.
- Data handled, systems or facilities accessed, and relevant subcontracting or dependencies.
- Business criticality and plausible effects on operations, compliance, finances, and customers if the service is disrupted.
- Assessment status, material findings, contract status, review triggers, and planned end date.
This is a practical starting set, not a regulator-mandated universal inventory template. Tailor it to your organization and the relationships it manages.
Plan before choosing a provider
Describe the outcome the organization needs, the work the provider will perform, and how the service fits into internal processes. Map the information, systems, people, and other providers it depends on. Consider what would happen if the service were unavailable, changed materially, or could no longer be used.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Use that context to decide what evidence to request, who must review it, what risks require approval, and what monitoring will be needed after onboarding. NIST’s C-SCRM guidance supports a multilevel approach in which assessment scope is tailored to the use case and criticality rather than applied uniformly (NIST SP 800-161 Rev. 1 Update 1, November 1, 2024).
Conduct due diligence and make a selection decision
Ask for evidence tied to the service’s actual risks. Depending on the relationship, useful topics to investigate may include how the provider governs security and resilience, protects relevant information, handles incidents, manages subcontractors, and supports continuity. These are adaptable evidence categories, not an exhaustive official checklist.
Evaluate providers against consistent, service-specific criteria. For each candidate, consider:
- Whether the provider can deliver the required outcomes and meet operational needs.
- What data and systems it can access, and how sensitive or consequential that access is.
- Relevant security and resilience evidence, including how well claims can be independently verified.
- Dependencies, subcontracting, and what those dependencies mean for continuity or oversight.
- Relevant financial and operational viability evidence.
- Contract and assurance terms, and whether a transition would be feasible if the provider failed or the relationship ended.
Weight those criteria according to the use case and the consequences of disruption. The cited sources support tailoring and transition planning, but do not prescribe a universal numerical score or weighting scheme. Record material evidence gaps, how they were addressed, and why the decision is acceptable—or why a different provider or delivery approach is needed.
Negotiate protections that work in practice
A contract should reflect the service being purchased and the risks identified during planning and diligence. Involve the appropriate business and legal owners, and consider which obligations are necessary under applicable law and the relationship’s context.
In particular, determine how the agreement will support:
- Clear service expectations and how performance problems will be addressed.
- Notice and cooperation when a material incident or change could affect the organization.
- Appropriate assurance or information needed to oversee relevant risks.
- Remediation, escalation, and remedies if agreed obligations are not met.
- Data and operational transition, return or disposition of information, and other exit duties.
Do not assume that broad contract language alone makes oversight effective. Check whether the organization can actually obtain the information, make decisions, and carry out the transition the agreement anticipates.
Monitor changes and act on findings
Choose a review cadence and triggers based on the relationship’s risk and importance. A single annual review should not be treated as a universal requirement: the sources support risk-based management, not one schedule for every provider.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Rank #4
Monitoring can include service performance, material incidents or changes, unresolved findings, relevant financial or operational concerns, updated assurance evidence, and changes in dependencies. Set ownership for reviewing each signal, escalating deterioration, and tracking remediation to a decision. Reassess when the use of a service changes, its criticality grows, or an important dependency shifts—not only when a scheduled review comes around.
Make termination and transition operational
Plan exit options early for important services, rather than waiting for a provider failure or contract expiry. Consider whether the activity will move to another provider, be brought in-house, or stop. Identify the people, time, access, records, information, and replacement capacity needed to carry out the chosen path.
When a relationship ends, address access removal, information return or disposition, records, continuity, customer effects, and contractual duties as applicable. The Federal Reserve’s May 2024 material specifically identifies operational, compliance, financial, and customer impacts as transition considerations (Federal Reserve, Third Party Risk Management).
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Improve the program with evidence from the lifecycle
Use review results, incidents, provider performance, and exit exercises to adjust risk tiers, evidence requests, contract standards, and monitoring. A completed questionnaire or score can help organize information, but does not by itself demonstrate effective oversight. Look for a traceable chain from service context to evidence, decision, action, and follow-up.
For organizations developing a C-SCRM program, NIST describes an integrated, multilevel approach that incorporates strategy, plans, policies, and risk assessments. Its publication page records a December 2, 2025 note announcing a fillable SCRM assessment-scoping questionnaire; the underlying publication remains a cybersecurity supply-chain resource, not a complete TPRM program for every domain (NIST SP 800-161 Rev. 1 Update 1).
Understand the current U.S. banking guidance status
The June 6, 2023 interagency document is published final guidance for banking organizations. A September 2026 joint agency release says the FDIC, Federal Reserve Board, NCUA, and OCC sought comment on proposed replacement guidance. The release describes the proposal as principles-based and non-binding and says the agencies plan to rescind existing guidance and replace it once guidance is finalized; it is not a final or effective replacement rule (joint agency release, September 2026). The release gives the comment deadline as 60 days after Federal Register publication, so its announcement alone does not establish a calendar due date.
The 2024 community-bank guide is voluntary. It says relevance depends on a bank’s size, complexity, risk profile, and the nature of the relationship, and that material may be useful to banks of any size. Neither that scope nor banking guidance should be generalized into a legal requirement for all sectors.
Optional: capture public web evidence
If a TPRM team needs a dated visual record of a provider’s public-facing web pages, a screenshot API can capture the page as an artifact. A screenshot is only one possible record: it does not establish that a provider meets security, resilience, contractual, or other due-diligence requirements. ScreenshotNeo is a website screenshot API and MCP server; its documentation and stated features are available at ScreenshotNeo.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOr skip the browser setup
One GET request can return a screenshot; see the ScreenshotNeo API documentation for options and response details.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
- Cookie or consent banners are accepted and more than 60 known consent platforms, newsletter popups, and chat widgets are removed before capture; each step can be turned off.
- Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed; response headers report the page verdict and billing status.
- An MCP server provides
take_screenshot,get_page_info, andcapture_pdftools for AI agents and MCP clients. - The Free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000 screenshots.
Sign up for ScreenshotNeo’s free plan: 1,000 screenshots a month, no card required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




