Vendor-Provided Resources
Here you can find links to resources supplied by TPRA Vendor Members (TPRM Service Providers). Some of these resources require you to input information to obtain the document.
Note: TPRA does not support one particular service provider over another, nor do we benefit from providing you the links below. Read and implement at your own risk.
If you are a TPRA Vendor Member and have a resource or link you would like to see added to this page, please submit through our Vendor Submissions form, or send it to Meghan Schrader at meghan.schrader@tprassociation.org for review.
Filter by Resource Type
RiskRecon by Mastercard
Risk Management Insights from 10 Years of Breach Event Monitoring | Whitepaper | RiskRecon
September 11, 2025
The research team from RiskRecon have cataloged publicly reported breach events between 2012-2021 across a population of over 5 million companies to offer insights to risk management and cybersecurity professionals for better handling of cyber risks.
Venminder
Final Interagency Third-Party Risk Management Guidance: 4 Actions to Comply | Blog | Venminder
September 11, 2025
A couple years ago, The Federal Reserve Board, FDIC, and OCC proposed joint third-party risk management (TPRM) guidance to provide a more consistent approach for how banking organizations should manage third-party relationships. This 68-page interagency guidance has just been finalized and put into effect. It replaces their separate past guidance (the Board’s 2013 guidance, the FDIC’s 2008 guidance, and the OCC’s 2013 guidance and its 2020 frequently asked questions). Check out this blog post to learn four suggested actions to comply with this new guidance as well as three additions to implement into your existing TPRM program.
Aravo
The Power of Oversight: The German Due Diligence Act & the Push for Supply Chain Transparency
September 11, 2025
Supply chains are intricate fibers in a complex global economy. Sadly, pull on a few threads and the fabric unravels, revealing unnoticed or ignored human rights and poor environmental standards. Between Covid-19, conscious consumerism, and ESG, tensions have grown, leading to increased regulation around supply chains and third parties. An example is the new German Supply Chain Due Diligence Act, which will lead to stricter global governance in the future. In their latest white paper, Aravo breaks down need-to-know information regarding this Act and key takeaways to help organizations meet the rising demand for supply chain transparency.
Supply Wisdom
Cascading Risks & Best Practices for Risk Mitigation
September 11, 2025
As the Lunar New Year celebration in China approaches, what potential cascading risks from the recent COVID-19 surge must you prepare for? Supply Wisdom risk and resilience experts share a resilience playbook for staying ahead of the situation.
CyberGRX
Security Assessments: Waste of Time or Worth It? | Blog | CyberGRX
September 11, 2025
It’s the million-dollar question: is the juice from security assessments worth the squeeze? We all know third-party security assessments take a lot of time and significant human resources. And after you finish an assessment, should you be making decisions based on what could be faulty data? Given these factors, is it even worth it? CyberGRX sat down with two people from opposite ends of the assessment dynamic to get both the vendor's and company's perspectives.
Venminder
Reinventing the Third-Party Risk Management Lifecycle | Blog Post | Venminder
September 11, 2025
We can all agree there’s been an evolution of third-party risk management. Those shifts have been necessary to keep up with emerging risks, rapid-fire changes and technological advancements that are part of today's business world. And, while keeping up with these changes keeps us all busy, one particular element of third-party risk management hasn't changed: the third-party risk management lifecycle. That is… it hasn't changed until now.
CyberGRX
What Cyber Risk Isn’t Third-Party Risk? | Blog | CyberGRX
September 11, 2025
Risk management is no longer about protecting your own attack surface, but understanding the security practices and vulnerabilities of all the other companies you do business with. When you think about it, what cyber risk isn’t third party risk?
CyberGRX
The 4 Essential Pillars of a Scalable TPCRM Program | Blog | CyberGRX
September 11, 2025
Regardless of how tight an organization’s internal cybersecurity measures are, nearly anyone can fall victim to an attack via one of their vendors. CyberGRX partnered with cyber risk experts to dive into what it takes to build a scalable TPCRM program, breaking it down into four pillars.