top of page

Search Results

Search this site

505 results found with an empty search

Blog Posts (118)

  • Standard Trust Portal Guidance for Third Party Risk Management (TPRM)

    The Third Party Risk Association (TPRA), in partnership with ten leading third party risk management service providers, is pleased to provide TPRM professionals with the Standard Trust Portal Guidance for Third Party Risk Management (TPRM). Definition A Trust Portal is a centralized hub that provides transparent, self-service access to security, compliance, privacy, and governance information. It enables collaborative due diligence activities by helping customers and other stakeholders quickly validate the effectiveness and maturity of your third-party risk program. Designed to unify how organizations demonstrate security, compliance, privacy, and governance maturity, the Trust Portal Guidance provides a standardized framework for building and managing trust portals, which are centralized hubs for evidence sharing and transparency between organizations and their third parties. The guidance aims to empower practitioners, vendors, regulators, and platform providers to align around a single, trusted model that reflects industry expectations and best practices for transparency, efficiency, and responsible evidence sharing. It also supports AI-driven TPRM technologies by standardizing evidence formats for automated review and analysis. Trust Portal Pillars TRANSPARENCY Open, accessible trust data for responsible risk decisions. EFFICIENCY Automated, reusable evidence. TRUST Verified information driving stronger partnerships. INNOVATION Enabling AI-ready, proactive due diligence. What It Can Do For You For Practitioners: Reduces questionnaire fatigue, improves review quality, and saves time through standardized, AI-friendly evidence formats. For Vendors/Third Parties: Demonstrates maturity and transparency; less time answering one-off questionnaires. For Regulators: Encourages uniformity and accountability in demonstrating control effectiveness. For Service Providers (Platforms): Provides a shared framework to enable AI and automation in TPRM workflows. Download Now This document is available for FREE download. How It Was Created Our TPRM Service Provider Advisory Council spent months working quietly behind the scenes, researching and collaborating to create a cohesive and comprehensive resource to be freely shared with all members of the TPRM community. Acknowledgements & Contributors Thank you to the following organizations, which contributed perspectives and subject matter expertise to help shape this guidance (displayed in alphabetical order): Their collective insights reflect practical experience across third-party risk management, compliance automation, trust assurance, and practitioner due diligence.

  • Build Yourself, Build Your Program: A TPRM Career Guide for the Age of AI

    Every few years a profession gets a moment where the ground shifts and the people who read it early pull away from the people who wait. Third party risk management is in one of those moments right now. The pressure is easy to feel and hard to name, so let me name it plainly: the part of your job that is easiest to automate is the part most programs still spend most of their time on. This is not a threat to fear. It is a map. It tells you exactly where to stop investing your career, and exactly where to start. The rest of this blog will discuss that map. Not the technology for its own sake, but what it means for how you should be building yourself and your program over the next two years. The skill that is quietly losing its value For most of our careers, questionnaire throughput was a real skill. Knowing the frameworks very well, moving assessments through the pipeline, keeping the register current, chasing third parties for responses. People built reputations on being fast and thorough at this, and they deserved to. That skill is depreciating, and the reason is simple. A third party can now generate a flawless questionnaire response in twenty minutes with an AI model. You can review it in twenty seconds with another one. When both sides automate the exchange of claims, the exchange stops carrying information. The output is fast, polished, confident, and empty. If your professional value is anchored to moving that exchange efficiently, your value is anchored to the one thing the technology just commoditized. This is uncomfortable to say out loud, and I say it because the practitioners who hear it early have time to move, and the ones who hear it late do not. The good news is that the skills replacing questionnaire throughput are more interesting, more durable, and far harder to automate. Where the value is moving Think of the modern TPRM skill set in three horizons. What you should acquire now, what you should build in parallel, and what you should aim to own over the next two to three years. This is as true for how you develop yourself as it is for how you develop your program. Acquire now: evidence literacy and AI judgment. The single highest-leverage move available to you is learning to read for evidence instead of attestation. That means reading a SOC 2 for the findings that hide outside the exceptions table, the complementary user entity controls that are quietly your obligations, and the subservice carve-outs that are a fourth-party map printed inside the report. It means telling the difference between a control that is enforced and one that is merely available, a distinction that lives in configuration exports, not questionnaires. And it means knowing where AI genuinely helps in your workflow and where it fails, so you can use it without being fooled by it. None of this requires a technical background. All of it requires unlearning the habit of treating a filled-in form as an answer. Build in parallel: governance and monitoring design. As volume rises and headcount stays flat, the analyst's job shifts from doing assessments to governing how they get done. That means designing which controls receive human review and which can be AI-accepted with spot-checks, documenting overrides in a way that survives an examiner, and building monitoring that fires on real signals instead of the calendar. Your assessment cycle takes weeks; public breach disclosure now averages well over a hundred days. Annual reassessment was never going to close that gap. The practitioners who can design event-driven monitoring, and defend it, become indispensable. Own long-term: program architecture and business translation. The most durable skills are the ones furthest from automation: designing an AI-augmented program from the ground up, and translating technical findings into the language a Chief Financial Officer (CFO) or a board risk committee will act on. These are the capabilities that turn a senior practitioner into a program leader, and they compound every year you hold them. Building the program, not just the résumé Everything above is also a blueprint for the program you are responsible for, because your career and your program advance through the same moves. Start by asking the question most programs never ask out loud: why does our program actually exist? Is it funded by regulatory mandate, by customer and market pressure, or by genuine conviction that the program prevents real losses? The honest answer shapes everything. A program that can only demonstrate documentation is now competing against infinitely cheap documentation and losing. A program that can demonstrate prevented loss has no such competition. If you cannot point to a single incident your program caught that would have cost the business real money, then the value of your program is reduced. This is the most important thing on your roadmap, not another questionnaire integration. Then, you will want to point your technology investments at evidence rather than attestations. The wave of automation has currently meant "faster questionnaires", which points current investments to the least informative part of the process. The programs that will matter most are shifting the object of automation from what a third party says to what can be observed: from documents to query-able data, from attestation to configuration, from annual cycles to continuous signals. And when you evaluate any AI-assisted tool, hold it to a standard of auditability. When an examiner asks you to reconstruct one decision, can the tool show the inputs, the model version, the citations, and the human who signed off? Most cannot. That question is the best filter you have for separating serious platforms from confident demos. Why this is bigger than our function The reason this deserves real attention, from you and from your leadership, is that delegated trust has become the largest attack surface most enterprises have. Companies outsource more of what they do every year. Every third party relationship, every integration, every AI agent granted standing access is a delegation of trust and an extension of the attack surface. The incidents that defined recent years were not perimeter failures; they were trust failures, a compromised build pipeline, a stolen integration token, a socially engineered supplier help desk. Enterprise resilience now rests on third party risk in a way it simply did not a decade ago. That is the opportunity hiding inside the disruption. A function that was often treated as a compliance cost center is becoming central to whether an organization can withstand the failure of the many parties it depends on. The practitioners who build the evidence-first skills, and the programs built on them, are the ones who will be in the room when it matters. Where to start this quarter Preparation does not require permission or budget. Pick your three most critical third parties and write down, honestly, what you actually know about their security posture versus what they attested. That gap is your starting point. Read the scope section of your next SOC 2 yourself, not the AI summary. Run one assessment you did manually through an AI tool and study where it agreed, missed, and surprised you. Build the habit of collecting one piece of observable evidence per critical third party per quarter. Small, unglamorous, and compounding. This conviction is why we built the "TPRM in the Age of AI" series with TPRA. Module 1, AI and the Future of Third-Party Risk, lays out what is changing and why, from first principles, and closes with concrete actions you can take this week and this quarter. Module 2, The Practitioner's Skill Stack, is the hands-on training for the evidence-first skills above: reading the artifacts, running AI with discipline, and designing monitoring that works. Both are CPE-eligible through the TPRA training platform. They exist to help you make exactly the moves this article describes. The questionnaire era is ending, and that is good news for anyone willing to build. The work ahead is not to fill out the form faster. It is to become the practitioner, and to build the program, that can tell whether the form was ever true. Start now, while it is still early. Being early is the whole advantage. Author Bio Clarence Chio Cofounder and CEO of Coverbase Clarence Chio is cofounder and CEO of Coverbase and has taught AI and security at UC Berkeley since 2019. He is the instructor for the "TPRM in the Age of AI" professional development series, available through TPRA. Coverbase is one platform for third-party risk and security, with AI that tailors to your program and controls and continuously evaluates every surface of exposure.

  • What TPRM Practitioners Need to Know About the IIA’s New Third-Party Topical Requirement

    A New Requirement Takes Effect September 15, 2026 On September 15, 2026, the Institute of Internal Auditors’ (IIA) new Third-Party Topical Requirement goes into effect, establishing a consistent, mandatory framework for internal auditors conducting assurance engagements that involve third party management (TPRM). For TPRM practitioners, the requirement provides greater clarity into what internal audit may examine and the types of practices, controls, and evidence organizations should be prepared to demonstrate. The IIA has published two core documents: Third-Party Topical Requirement – Provides the mandatory baseline of requirements internal auditors must follow when performing assurance engagements on third party management. Third-Party Topical Requirement User Guide – Provides guidance for implementing the requirement, including examples of evidence and controls internal auditors may consider. Additional information is available on the IIA Third-Party Topical Requirement resource page. Unlike a regulatory or industry-specific standard, the requirement establishes principles that can be applied across organizations and industries. Many align with existing regulatory guidance and established TPRM practices, while others extend beyond traditional TPRM activities into areas such as sourcing decisions and contract performance monitoring. Why This Matters: A Professional Perspective I’ve worked in third party and vendor risk management for more than 20 years, working with more than 100 organizations across financial services, healthcare, pharmaceuticals, energy, and other highly regulated industries. That experience has given me the opportunity to see TPRM programs at very different stages of maturity, as well as how the audits evaluating those programs have changed over time. Audits that once focused more narrowly on vendor due diligence and basic controls have expanded to examine how organizations govern third party relationships, manage risk across the lifecycle, and demonstrate that their processes are working as intended. The IIA’s new Third-Party Topical Requirement reflects much of that evolution. It also brings greater attention to several challenges I’ve encountered across organizations and industries over the years. With that perspective, here’s what TPRM practitioners should know about the new requirement, along with five areas that I believe deserve particular attention as organizations prepare. What the Topical Requirement Is The Third-Party Topical Requirement is a mandatory component of the IIA’s International Professional Practices Framework. When internal auditors perform an assurance engagement that addresses third party management, whether as part of a planned engagement or because third party risk becomes relevant during an audit, they are required to use the Topical Requirement as their framework. Each audit will still reflect the professional judgment, scope, and priorities of the team conducting it, but the requirement provides a consistent foundation from which to work. What Auditors Will Be Looking For The Topical Requirement contains 17 requirements organized into three categories: governance, risk management, and controls. Each category has defined criteria, supported by the User Guide with examples of evidence auditors may consider. Third Party Governance, 4 Requirements Governance focuses on whether the organization has a formalized approach to third party management. This includes documented policies and procedures covering the full lifecycle of the relationship, clearly defined roles and responsibilities, and communication protocols that keep appropriate stakeholders informed. Third Party Risk Management, 4 Requirements Risk management focuses on whether risk practices are standardized and comprehensive throughout the lifecycle. This includes how the organization identifies, assesses, prioritizes, and responds to third party risks, how issues are escalated and managed when they arise, and how risk information flows to leadership and oversight bodies. Third Party Controls, 9 Requirements Controls focus on operational execution throughout the lifecycle, including sourcing, due diligence, contracting, onboarding, monitoring, corrective action protocols, and offboarding. The requirements also address maintaining a complete, accurate, and current inventory of third party relationships, an area that can present practical challenges when third parties enter an organization through multiple channels. Five Areas That Deserve a Closer Look Based on my experience with TPRM programs across industries and at different stages of maturity, there are five areas I would pay particular attention to when preparing for the new requirement. 1. Lifecycle-Based Framework Across organizations, third party management frequently spans multiple business functions, each with its own policies, processes, systems, and responsibilities. That can make it difficult to create a cohesive view of third party management across the enterprise. The requirement calls for a formalized, documented approach that spans the full third party lifecycle. Organizations should consider whether activities across functions are sufficiently coordinated and whether policies, procedures, and responsibilities support a consistent enterprise approach. 2. Accurate, Documented Procedures Policies and procedures don’t always mature at the same pace. In many programs I’ve worked with, policies benefit from formal approval and regular review cycles, while the procedures supporting them may receive less attention over time. Procedures should clearly define roles, accountability, and documentation requirements and accurately reflect how the organization operates today. That review is particularly important as processes and technologies change, including the adoption of AI-enabled solutions. 3. Communications and Reporting Reporting can remain difficult even for well-established TPRM programs. Often, what appears to be a reporting problem begins further upstream with the quality and consistency of the underlying data. When third party data is captured by different functions without consistent fields, definitions, ownership, or collection practices, maintaining accurate and complete reporting becomes more difficult. Practitioners should consider both their reporting capabilities and the quality of the data supporting those reports. 4. Risk Domains Beyond Cyber Another pattern that has emerged over the years is the significant attention given to cybersecurity within third party risk programs. Regulatory requirements and established information security ownership have helped make cyber a well-defined component of TPRM in many organizations. The Topical Requirement, however, addresses a much broader set of risks, including strategic, reputational, financial, legal, operational, and geopolitical risks. Organizations should consider whether these additional risk domains have appropriate ownership, assessment processes, and oversight within the broader third party management framework. 5. Accurate Third Party Inventory Maintaining an accurate third party inventory continues to be a practical challenge for many organizations. One reason is structural: third parties may enter through procurement, accounts payable, corporate cards, or direct relationships established by individual business units. When those channels are not connected to a consistent process or system of record, gaps in the inventory can result. Organizations should evaluate whether they have clearly defined ownership, consistent processes for identifying and recording third parties, and a reliable system of record for third party relationships. What TPRM Practitioners Can Do Now The IIA has provided internal auditors with a clear framework to work from. For TPRM practitioners, preparation can focus on three things: Understand what's expected. Read the Topical Requirement and User Guide to understand the policies, practices and evidence auditors will look for. Evaluate your scope of operations. Focus on things you are responsible for within the third party management lifecycle and be honest about where you stand today. Coordinate with cross-functional peers. For those things outside your scope but within the Topical Requirement, work with your peers who own those activities to ensure responsibilities are clear, documented, and coordinated. Auditors will want to see a unified approach, not disconnected functions operating independently. The new requirement does not mean every element of third party management needs to sit within the TPRM function. It does mean organizations should be able to demonstrate how responsibilities and activities work together across the lifecycle. Starting that review now gives practitioners an opportunity to understand their current state, identify areas that may need attention, and coordinate with the other functions responsible for third party management before the requirement takes effect. Author Bio Tom Rogers Founder and CEO of Vendor Centric Tom Rogers is the Founder and CEO of Vendor Centric, a professional services firm that works exclusively with third-party and vendor management leaders to build, improve, mature and run their programs. With over 20 years in the field, Tom has worked with over 100 clients across financial services, healthcare, pharma, energy, and other highly regulated industries. He brings a practical, real-world perspective to helping leaders build operations that don't just hold up under scrutiny but actually deliver value. Tom and his team built a free self-assessment tool that maps to all 17 standards within the IIA’s Third-Party Topical Requirement. It takes about 15-20 minutes to complete and gives you an interactive gap analysis as soon as you’re done, along with a downloadable report you can share with the colleagues you’ll need to work with to close the gaps. You can access the tool here. You can connect with Tom on LinkedIn or reach him at trogers@vendorcentric.com.

View All

Other Pages (381)

  • TPCRA | TPRA

    The Third Party Cyber Risk Assessor (TPCRA) Certification validates your expertise in assessing third party cybersecurity controls, advancing your career in third party risk management. Third Party Risk Association's Third Party Cyber Risk Assessor (TPCRA) Certification The TPCRA Certification is a specialized qualification that validates expertise in assessing third-party cybersecurity controls, managing cyber risk assessments, and evidencing proficiency in cybersecurity assessment techniques, as well as establishing credibility for third-party risk management professionals. Register Now By clicking this button, you will be redirected to our Training & Certification Platform (Inspire360). Your TPRA website login credentials will not work on Inspire360, and a separate account is required to register for & access courses. What is the TPCRA? The TPCRA Certification is a specialized qualification designation which will: Confirm your understanding & skill in the assessment of third party cyber security controls and processes. Validate your competency in the creation, execution, & management of third party cyber risk assessments. Authenticate & add credibility to your expertise as a third party cyber risk assessor. Evidence your proficiency with various cyber security & information technology assessment terms & techniques. About TPCRA Register Domains Pricing Examination Overview Training Schedule FAQs Who is the TPCRA for? The TPCRA is the standard of achievement for those who assess, monitor, and review third party cyber security and information technology controls, as well as identify and mitigate risk related to said controls. Such roles may include, but not be limited to: Third Party Risk Management Practitioners Procurement Specialist Vendor Managers Auditors Information Security Professionals Privacy or Compliance Specialists Legal Professionals "The TPCRA Certification is foundational to achieving success as a third party risk management professional." Domains Building Core Competencies for Lasting Professional Excellence Cybersecurity & Third Party Risk Management Basics Pre-Contract Due Diligence Continuous Monitoring Physical Validation Disengagement Due Diligence Cloud Due Diligence Reporting & Analytics Practitioner Ethics Pricing Register Now Where will this button take me? Item TPRA Standard, Vendor, & Non-Members TPRA Premium Practitioner Members Examination $500 $425 Training $400 $340 Examination & Training Bundle $800 $700 Examination Retake Fee $200 $200 Certification Renewal $100 $85 Examination Overview Examination Outline The examination is a 150-question, multiple-choice assessment. Questions will include a variety of formats, such as scenario-based, true or false, and choose the best response. The time limit is 3 hours for the examination process, broken out into the following: 5 minutes to read and sign the NDA 10 minutes to complete the optional tutorial 160 minutes to complete the examination 5 minutes to complete the post-exam survey The examination is a closed-book assessment that will be monitored via an assigned proctor. Passing Score You must receive a score of 80% or higher to pass the TPCRA examination. Exam Scheduling The examination will be taken in person at a Pearson VUE testing facility. Examinations may be scheduled at a day/time that suits you via a Pearson VUE location. Pearson VUE offers over 5,000 test facilities worldwide and is ADA-compliant. Training Schedule SESSION DATE TIME LOCATION REGISTER TPCRA On-Demand Training Only REGISTER TPCRA On-Demand Training & Exam Bundle REGISTER TPCRA 4-Day November Training Only 11/16/2026 5 PM - 8 PM CT REGISTER TPCRA 4-Day November Training & Exam Bundle 11/16/2026 5 PM - 8 PM CT REGISTER PLEASE NOTE: When you click "Register" above, you will be redirected to our Training & Certification Platform ( Inspire360 ). Your TPRA website login credentials will not work on Inspire360, and a separate account is required to register for and access courses. Learn more on our FAQ page . " I thought the training was fantastic. I've been a TPRM practitioner for nearly 7 years now and still walked away with new knowledge and insight. I am so proud of the TPRA and honored to be a part of the board! " Nicole Makinney Product Owner, Third Party Risk | McKesson TPCRA Training Attendee TPCRA Frequently Asked Questions General TPCRA Information About TPCRA Certification TPCRA Requirements TPCRA Examination TPCRA Training Maintaining Your TPCRA Certification Examination Outline Certification Eligibility Criteria Certification Pricing TPCRA Training Instructor Certification Renewal Registration Certification Process Training Need Help? Visit our Support page for Frequently Asked Questions and, if that doesn't work, key contacts to reach out to for further assistance. Support & FAQs →

  • WNTPRM Recorded Meetings | TPRA

    Watch Women in TPRM recordings of past monthly meetings. Hear insights from women leaders and practitioners driving change in third party risk management. Meetings WNTPRM On-Demand Meetings Tuesday, August 18, 2026 1:00 – 2:00 PM CT Women In TPRM Meeting PowerPoint Watch Video Tuesday, June 16, 2026 1:00 – 2:00 PM CT Women In TPRM Meeting PowerPoint Watch Video Tuesday, May 19, 2026 1:00 – 2:00 PM CT Women In TPRM Meeting PowerPoint Watch Video Tuesday, April 28, 2026 1:00 – 2:00 PM CT Women In TPRM Meeting PowerPoint Watch Video Tuesday, March 17, 2026 1:00 – 2:00 PM CT Women In TPRM Meeting PowerPoint Watch Video Tuesday, February 17, 2026 1:00 – 2:00 PM CT Women In TPRM Meeting PowerPoint Watch Video LOAD MORE

  • TPRA – Third Party Risk Management Resources, Certification & Networking

    Join the TPRM community at TPRA for expert resources, training, templates, and tools to strengthen your third party risk program and grow your network. Join the only not-for-profit, vendor-agnostic professional association uniting thousands of TPRM professionals worldwide. Furthering the profession of third party risk management through knowledge-sharing & networking. Learn More Join Now The all-in-one source for Third Party Risk Management (TPRM) tools, templates, training, networking, certifications & industry best practices. MEMBERSHIP CONNECT & DISCOVER Individuals & organizations working together to advance the industry. More > EDUCATION MEETINGS & TRAINING Certifications & training for risk professionals to advance their careers & enhance their programs. More > RESOURCES INFORMATION SHARING SITE White papers, templates, guidance & more to enhance your program. More > TOOLS & AUTOMATION EXPLORE & CONTACT Detailed profiles of trusted TPRM service provider organizations & their offerings. More > Advance Your Career in Risk Management: Learn About the Benefits of TPRA Membership > Practitioner Plans Standard: FREE Premium: $199/yr BENEFITS Member Meetings Interactive monthly calls to discuss a variety of third party risk topics decided upon by members. Conferences In-person and virtual conferences dedicated solely to third party risk topics. Networking Online interaction with your peers through membership forums and document databases. Industry-Specific Meetings Quarterly special interest calls based on your industry. Demos, Surveys, Webinars Access to third party risk management service provider demos, surveys, & webinars. Certifications TPRM professional certifications that establish credibility and demonstrate your commitment to mastering your skills and knowledge within the industry. Join Now Vendor Plans 4 available plans starting at $8,000/yr BENEFITS Priority & Discount Sponsorship Opportunities Be the first to sponsor conferences and receive discounted member rates, as well as priority positioning. Networking & Collaboration Attend monthly and quarterly meetings with TPRM practitioners and other service providers to network, collaborate, create resources, share insights, and more! Promotional Opportunities Work with the TPRA staff to communicate to Practitioner Members the your organization's webinars, surveys, demos, blog posts, and white papers. Advisory Councils Join our TPRM Service Provider Advisory Council, as well as other groups, dedicated to collaborating, sharing insights, and providing strategic guidance. Quarterly Updates Receive quarterly updates with industry innovators to collaborate on practitioner needs. Join Now Meetings Open to All Meetings Open to All Member Meetings & Events On-Demand Meetings Monday, October 5, 2026 5:00 – 8:00 PM CT TPRMP October Training & Exam Bundle Register > Monday, October 5, 2026 5:00 – 8:00 PM CT TPRMP October Training Only Register > Thursday, October 8, 2026 10:00 – 11:00 AM CT Roundtable: Strengthening Risk Terms and Third Party Accountability Register > Wednesday, October 14, 2026 Fort Worth, Texas Vendor & Third Party Risk USA Register > CONTACT US OUR INFORMATION Address: P.O. Box 824 Ankeny, Iowa 50021 USA Email: info@tprassociation.org For any general inquiries, please fill out the contact form. First name* Last name* Email* Subject* Message* Yes, subscribe me to TPRA communications. Submit

View All
bottom of page