Use this adaptable third-party risk management policy template to set clear rules for planning, assessing, approving, contracting with, monitoring, and ending supplier relationships. It is a governance starting point, not a regulator-approved form: tailor it to your jurisdiction, industry, contracts, risk appetite, and operating model.
Who this template is for—and what it is not
This framework is useful to organizations that rely on outside providers for services, technology, data processing, operations, or customer-facing work. It is not a universal legal standard. The most complete lifecycle model reflected here comes from U.S. banking-sector interagency guidance, so organizations outside banking should use it as a reference and map its controls to their own applicable laws, regulatory obligations, contracts, and governance.
The Office of the Comptroller of the Currency (OCC) community-bank guide is voluntary; its relevance depends on an institution’s size, complexity, risk profile, and relationship circumstances. Do not automatically transplant bank-specific board or management arrangements into another organization. See the OCC community-bank guide and the 2023 interagency guidance.
Use the text below as a policy skeleton. Replace bracketed fields, assign owners, and connect it to existing procurement, privacy, security, business continuity, records-management, and incident-response procedures.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
Third-party risk management policy template
1. Purpose
Policy statement. [Organization name] manages risks arising from third-party relationships throughout their lifecycle. Before entering, renewing, materially changing, or ending a relationship, the organization will evaluate risks proportionately, assign accountable owners, document decisions, apply suitable contractual safeguards, monitor material risks, and plan for transition or termination.
The purpose of this policy is to protect [organization operations, customers, information, assets, and regulatory or contractual obligations] while enabling the organization to obtain services that support its objectives.
2. Scope
This policy applies to [employees, business units, subsidiaries, and other covered entities] that select, approve, manage, or oversee a third party. A third party is any external person or organization that provides a product, service, technology, or activity to or on behalf of [organization name]. Include providers with access to organizational systems, information, facilities, customers, or essential operations, as well as subcontractors and other dependencies where relevant to the service.
List exclusions explicitly rather than assuming they are out of scope: [for example, ordinary purchases with no meaningful operational, data, security, or customer impact]. An exclusion does not override a legal, contractual, or other internal requirement that applies to the purchase or relationship.
3. Related policies and terms
This policy operates alongside [procurement], [information security], [privacy], [business continuity and resilience], [records retention], [incident response], and [legal and compliance] requirements. If requirements conflict, [designated authority] will determine the applicable control in consultation with [legal/compliance].
Rank #2
- Third-party relationship: An arrangement under which an external provider supplies a product, service, or activity to or for the organization.
- Relationship owner: The person accountable for the business purpose, lifecycle decisions, and ongoing relationship oversight.
- Critical or important activity: An activity designated under the organization’s documented criteria as having significant consequences if disrupted, degraded, or compromised.
- Residual risk: Risk remaining after applicable controls and mitigations are considered.
4. Governance and responsibilities
Adapt responsibilities to the organization’s structure. In the U.S. banking guidance, management is responsible for implementing the risk-management program and the board provides oversight; other organizations should assign equivalent accountability without assuming the same structure applies.
| Role | Policy responsibility |
|---|---|
| Governing body or designated oversight group | Oversees the program at a level appropriate to the organization; reviews material exposures, significant exceptions, and systemic issues. |
| Executive sponsor | Ensures the program has authority and resources; approves or escalates risks and exceptions within delegated limits. |
| Relationship owner | Defines the business need, supplies accurate scope and impact information, coordinates lifecycle reviews, tracks performance and issues, and maintains relationship records. |
| Procurement or vendor management | Coordinates intake, tiering, diligence workflow, approvals, inventory, renewal controls, and standard contracting processes. |
| Legal | Reviews contract terms, regulatory or legal obligations, rights, remedies, and exit provisions as appropriate. |
| Information security and technology | Evaluates security, system access, technology dependencies, cyber controls, and relevant resilience evidence. |
| Privacy and compliance | Assesses personal or regulated data, permitted uses, compliance obligations, and relevant monitoring or reporting needs. |
| Business continuity or resilience | Reviews disruption scenarios, recovery arrangements, dependencies, and transition or contingency plans. |
| Independent review or audit | Provides independent assessment of program design or execution according to the organization’s governance and risk profile. |
Specify approval authority, deputies, escalation contacts, and segregation-of-duty expectations in [delegation schedule or procedure].
5. Risk tiering and approval
Before commitment, renewal, or a material change, the relationship owner and [procurement/vendor management] will document the service, its scope, and an initial risk tier. Apply a consistent method that considers the relationship’s actual impact and context, including:
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problems- Importance of the supported activity and consequences of failure or disruption.
- Data sensitivity, volume, location, and provider access to systems, facilities, customers, or information.
- Whether the provider acts in a customer-facing or regulated capacity.
- Substitutability, concentration, dependencies, and the feasibility of transition.
- Geography, subcontractor reliance, and the visibility available into the provider’s supply chain.
- Potential effects on legal, regulatory, contractual, financial, operational, or reputational obligations.
Record why the relationship received its tier and state how that tier changes due diligence, approval, contract review, monitoring cadence, and exit planning. A high-impact or critical relationship should receive more extensive review and oversight than a low-impact purchase, subject to the organization’s documented criteria.
No business unit may make a binding commitment before required approvals are complete. Exceptions must identify the unmet requirement, business rationale, compensating controls, residual risk, duration, and authorized risk acceptor. Escalate material findings to [role or committee] before approval. Maintain a register of covered relationships with, at minimum, provider, service, owner, tier, approval status, key dates, material dependencies, and current risk or issue status.
Lifecycle requirements
The policy follows five stages: planning; due diligence and selection; contract negotiation; ongoing monitoring; and termination. For each stage, record the decision, responsible owner, evidence considered, exceptions, and follow-up actions. This lifecycle reflects the 2023 interagency guidance.
6. Planning
Before soliciting or selecting a provider, the relationship owner will document:
Free tools Windows power users keep installed
One-click scans. No signup required.
- The business purpose, expected benefits, and alternatives considered, including whether the activity can be performed internally or through another arrangement.
- The proposed service and scope, organizational units affected, and any customer, data, system, facility, or operational access involved.
- Dependencies, including important subcontractors or technology components known at planning time.
- The consequences of provider failure, service degradation, data compromise, or interruption, and whether the activity meets the organization’s criteria for important or critical status.
- Expected duration, renewal or change points, and initial transition or exit considerations.
Obtain the required business and risk approvals to proceed to provider selection. Revisit the assessment if the service scope or expected access changes materially.
7. Due diligence and provider selection
Assess a proposed provider in proportion to the relationship’s risk, complexity, and scope. The review should cover the provider’s ability to deliver the specific service being considered—not merely its general reputation or organization-wide certifications. Depending on the relationship, evaluate:
- Alignment with the organization’s strategy, goals, and service requirements.
- Legal, regulatory, and contractual compliance relevant to the service and the parties.
- Financial condition and capacity to perform through the expected term.
- Relevant business experience, operating history, and key personnel.
- Risk management, internal controls, and the provider’s process for identifying and addressing issues.
- Information security, information systems, data handling, and access safeguards.
- Operational resilience, continuity and recovery arrangements, and the provider’s ability to respond to disruption.
- Subcontractors, material dependencies, concentration concerns, and other relationship-specific risks.
Record what evidence was reviewed, its date and scope, the service or systems it actually covers, identified gaps, and the disposition of each material finding. If evidence is missing, stale, limited, or outside the proposed service scope, document the limitation, determine what risk remains, and consider alternatives, additional evidence, mitigations, or rejection. A general assurance report should not be treated as proof that every service, location, system, or subcontractor is covered.
Rank #4
- Prep for PMI-RMP Cert
Document the selection decision and approval, including the provider’s suitability, unresolved issues, residual risk, and any conditions that must be satisfied before service begins.
8. Contract negotiation
Translate material diligence findings and service requirements into enforceable terms, with legal review as appropriate. Depending on risk and applicable law, address:
- Service scope, performance expectations, responsibilities, and remedies for failure.
- Required access to relevant records and information; audit, assessment, or examination rights where appropriate.
- Security, privacy, data-use, confidentiality, retention, return, and deletion obligations.
- Prompt incident notification, cooperation, investigation, remediation, and complaint handling.
- Subcontractor use, notice or approval requirements, flow-down obligations, and visibility into material changes.
- Continuity, resilience, recovery, and cooperation during disruption.
- Reporting, evidence delivery, material change notification, and cooperation with the organization’s oversight.
- Termination rights, transition assistance, data portability or return, access revocation, and handling of outstanding obligations.
Match contract requirements to the service and the organization’s legal and regulatory obligations. Do not assume a standard contract is sufficient where material risks require tailored terms. Record accepted limitations, legal advice or approval where required, and any risk that remains because a desired safeguard could not be obtained.
9. Ongoing monitoring
After onboarding, the relationship owner will monitor the provider and the relationship over time. The depth and frequency of review should reflect tier, service criticality, changes in risk, and the quality and relevance of available evidence. Monitoring may include:
- Service performance against agreed requirements and significant service issues.
- Changes in the provider’s financial condition, business, ownership, key personnel, or ability to deliver.
- Control evidence, security posture, compliance matters, and whether prior evidence remains current and in scope.
- Incidents, complaints, audit findings, remediation commitments, and overdue actions.
- Subcontractor or dependency changes, concentration exposures, and material service changes.
- Continuity, recovery, and resilience arrangements relevant to the service.
Document findings, decisions, assigned actions, owners, due dates, and escalation. Reassess the tier and risk when service scope, data access, dependencies, provider condition, or operating context changes materially. Escalate significant incidents, control failures, repeated performance issues, or unacceptable residual risks according to [incident and escalation procedure].
Best Value
10. Termination and transition
Plan for both ordinary expiry and unexpected termination, provider failure, or loss of suitability. The relationship owner will coordinate a documented exit plan proportionate to impact and complexity. Address:
- Continuity of the supported activity and transition to an alternative provider or internal operation.
- Return, transfer, or secure deletion of organizational data, subject to contract and applicable retention requirements.
- Revocation of user accounts, credentials, system connections, facility access, and other permissions.
- Transfer of records, documentation, configurations, and other assets needed to continue or reconstruct the service.
- Outstanding payments, disputes, incidents, remediation, complaints, and other contractual obligations.
- Required retention of relationship records and evidence under applicable law and organizational schedules.
Record completion of exit tasks, unresolved obligations, and any lessons that should change future selection, contracting, or oversight.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.ICT and cyber supply-chain supplement
For technology providers and dependencies, add focused questions to the broader lifecycle rather than substituting a cyber checklist for it. NIST’s SP 1326 quick-start guide, published July 8, 2026, identifies five assessment components for ICT suppliers: Foreign Ownership, Control, or Influence (FOCI); Provenance; Resilience; Foundational Cyber Practices; and Supply Chain Tiers. NIST describes the guide as aligned with SP 800-161 Rev. 1.
Use these components to prompt service-specific questions—for example, what entities or components contribute to delivery, how the supplier and its dependencies withstand disruption, and what foundational cyber practices are relevant. Apply them in proportion to the technology relationship and record evidence scope and limitations as with other diligence.
Recommended Free Tools
Records, reporting, and review
Maintain records sufficient to reconstruct lifecycle decisions and oversight, including the inventory, planning and tiering rationale, diligence evidence and limitations, approvals, contract and exceptions, monitoring findings, incidents, remediation, and exit records. Define retention and access in accordance with applicable law, contract, and records policy.
[Program owner] will provide [management or oversight group] reports on material relationships, significant risk concentrations, overdue remediation, exceptions, incidents, and relevant trends at a cadence appropriate to the organization. An independent review should assess whether the program is appropriately designed and operating, with scope and frequency proportionate to organizational size, complexity, risk profile, and third-party exposure.
Implementation checklist
- Replace bracketed fields and confirm policy scope, exclusions, related policies, and approval authority.
- Define risk tiers, criteria for important or critical activities, and the controls that each tier triggers.
- Assign lifecycle owners and escalation routes, including legal, security, privacy, continuity, and independent review roles.
- Create or update the third-party register and require approval before commitment or material change.
- Adopt evidence standards that capture date, scope, coverage, gaps, and treatment of limitations.
- Align contract standards with identified risks and establish a documented exception and risk-acceptance process.
- Set risk-based monitoring and exit-planning expectations, then schedule review of the policy and its effectiveness.
Regulatory status to verify before adoption
The 2023 interagency guidance was described by the agencies as final guidance on June 6, 2023. On September 11, 2026, the OCC announced proposed interagency guidance to revise and replace it; the Federal Register notice was published September 15, 2026. At the time of those announcements, the replacement was a proposal open for comment, not a final replacement. Check the current status and applicable requirements before relying on it as current supervisory guidance. See the OCC announcement and the Federal Register notice.
Or skip the browser setup
For a clean capture of policy pages or supplier evidence in a browser, ScreenshotNeo offers a website screenshot API. One GET request can return an image or PDF; its capture process can accept cookie banners and remove known consent banners, newsletter popups, and chat widgets before the shot. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, and responses identify the page verdict and billing status. An MCP server provides screenshot tools for AI agents. The free plan includes 1,000 screenshots a month without a card; paid plans start at $5 for 3,000 screenshots. See ScreenshotNeo.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteAPI documentation · Sign up free for 1,000 screenshots a month, no card required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




