Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Build and run a third-party / vendor risk management (TPRM) program aligned to NIST SP 800-161 C-SCRM and NIST CSF 2.0 GV.SC: inventory and tier vendors by risk, send the right due-diligence questionnaire (SIG, CAIQ), review evidence (SOC 2, ISO 27001, pen-test reports), set contractual security and right-to-audit clauses, monitor vendors continuously, manage Nth-party / subcontractor risk, and offboard securely. Use when an organization needs to assess a new vendor before onboarding, when stand
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-13 | ✗→✓ | ▲ Improved | 60% | 0% |
| case-15 | ✗→✓ | ▲ Improved | 108% | 0% |
| case-02 | ✓→✓ | = Same ✓ | 79% | 0% |
| case-03 | ✓→✓ | = Same ✓ | 174% | 0% |
| case-04 | ✓→✓ | = Same ✓ | 104% | 0% |
Catalog every third party and capture: data sensitivity handled, type of access (network, physical, none), business criticality, and regulatory scope. You cannot manage what you have not inventoried — shadow vendors are a common blind spot.
Score each vendor on inherent-risk factors (data sensitivity, access, criticality, regulatory scope, spend/concentration) and assign a tier (e.g., Critical / High / Moderate / Low). The tier drives how deep the assessment goes and how often you reassess. A payroll processor with PII and system access is not the same risk as a stock-photo subscription.
Don't just collect — read:
Compare findings against your control requirements. For each gap: accept, require remediation (with a date), add a compensating control on your side, or walk away. Record the residual risk and a risk-owner decision.
Bake requirements into the agreement: security control obligations, breach-notification timeline, data-handling and return/destruction terms, right-to-audit / right to assessment evidence, subcontractor (Nth-party) flowdown, and liability/insurance. Contracts are where TPRM gets teeth.
Tiering is not a one-time gate. For higher tiers: periodic reassessment, security-ratings feeds, breach/news monitoring, certificate-expiry tracking, and watching for material changes (acquisition, region change, new subprocessors). Re-tier on change.
Map critical fourth parties (your vendor's key subprocessors) and watch for concentration (many vendors riding on the same upstream provider) — a single upstream outage or breach can hit your whole portfolio at once.
On termination: revoke access and credentials, confirm data return or certified destruction, remove integrations/API keys, and update the inventory. Un-offboarded vendors are standing risk.
| Concept | Definition | |---|---| | Inherent risk | Risk a vendor poses before controls — drives tiering. | | Residual risk | Risk remaining after the vendor's (and your) controls. | | Vendor tier | Risk band (Critical/High/Moderate/Low) setting assessment depth and cadence. | | SIG | Shared Assessments Standardized Information Gathering questionnaire (full / Lite / Core). | | CAIQ | CSA Consensus Assessments Initiative Questionnaire (maps to the Cloud Controls Matrix). | | SOC 2 Type II | Attestation on control design and operating effectiveness over a period. | | Right to audit | Contractual right to assess the vendor or obtain assessment evidence. | | Nth-party / fourth-party | Your vendor's vendors (and beyond) — indirect supply-chain risk. | | Concentration risk | Many vendors depending on the same upstream provider. | | C-SCRM | Cybersecurity Supply Chain Risk Management (NIST SP 800-161). |
Produce a Vendor Risk Assessment using assets/template.md, containing:
Use scripts/process.py to compute a vendor's inherent-risk tier from a profile JSON, set the assessment depth and reassessment cadence, and flag missing evidence for the assigned tier.
Other measured skills in the registry, with their headline benchmark lift.