top of page

Vendor-Provided Resources

Here you can find links to resources supplied by TPRA Vendor Members (TPRM Service Providers). Some of these resources require you to input information to obtain the document.

 

Note: TPRA does not support one particular service provider over another, nor do we benefit from providing you the links below. Read and implement at your own risk. 

If you are a TPRA Vendor Member and have a resource or link you would like to see added to this page, please submit through our Vendor Submissions form, or send it to Meghan Schrader at meghan.schrader@tprassociation.org for review.

Filter by Resource Type

Venminder

Third-Party Risk Management Guidance and Regulations

September 11, 2025

Third-party risk management guidelines and regulations are no longer only issued by financial services regulatory agencies. Many other industries are seeing the value in managing risk and looking at it with more scrutiny. And, it’s always recommended to look to one another and follow current third-party risk management best practices. This eBook contains helpful information and tips to comply with some of the third-party risk management best practices. 


Download the eBook to learn:

  • Industry regulators and guidance and regulations to be aware of

  • Key takeaways from each one

  • Tips to comply with TPRM guidance and regulations

Venminder

Third-Party Risk Management Policy Template

September 11, 2025

Writing and updating a third-party risk management policy can be a time-consuming process, and without guidance or help, it can be challenging to know where to start. 


These two valuable templates can be used as the foundation to customize and align to your organization’s third-party risk management framework. Each policy contains best practices and processes to meet regulatory requirements and/or follow the third-party risk management lifecycle. 


Download the templates for:  

  • Two customizable and fillable third-party risk management policy documents 

  • Instructions and supporting guides to assist 

  • Best practice structure and flow 

  • Following regulatory requirements in your third-party risk management policy 

  • Aligning to the third-party risk management lifecycle

Venminder

How to Do a Vendor Risk Assessment

September 11, 2025

Performing a vendor risk assessment can be intimidating, but it’s a worthwhile time investment and a necessary component of a third-party risk management program. You don’t know the risk elements and level of risk associated with a vendor until you do one. Learn the tried-and-true steps to completing a vendor risk assessment by downloading this infographic. 


Download the infographic to learn:

  • Steps to complete a vendor risk assessment 

  • Determining inherent and residual vendor risk

  • Next steps after the vendor risk assessment

Venminder

7 Steps of Risk-Based Vendor Due Diligence | Infographic & Matrix

September 11, 2025

Not all vendors have the same level of risk. Risk-based vendor due diligence will save you valuable time and resources in your vendor risk management program. To ensure your organization is more effectively managing vendor risk, it’s important to define the types, amounts, and frequencies of due diligence based on the vendor engagement’s risks. 


Download the infographic and matrix to learn: 

  • What risk-based vendor due diligence is and why it matters

  • The steps of performing risk-based vendor due diligence

  • Examples of risk-based vendor due diligence

  • A matrix that provides guidelines for the suggested frequency of due diligence reviews based on criticality and inherent risk

Venminder

Understanding the Differences Between a Vendor SOC 1, 2, 3

September 11, 2025

To verify your vendor has adequate internal control in place to protect your data, you must request and assess their SOC reports. It can get confusing what each SOC report covers and what each report means. To help guide you and your team in understanding what those differences are, here’s a simple one-page infographic. 


Download the infographic to learn:

  • What the SSAE 18 and SSAE 20 are

  • Definitions of each vendor SOC report and when to use them

  • How each SOC report benefits your organization

Venminder

What to Do If Your Vendor Has a Negative SOC Report

September 11, 2025

Even for seasoned professionals, reviewing a vendor’s SOC report can be a daunting task. It’s great if there are no red flags, but what do you do if the SOC report is filled with issues that the auditor found? Your organization must determine how to proceed with the vendor, whether that’s addressing the issues or passing on the vendor relationship. This infographic covers the key next steps after an unfavorable SOC report. 


Download the infographic to learn:

  • Next steps after an unfavorable vendor SOC report

  • Examples of responses to your vendor

  • Reminders to ensure your review of a vendor’s SOC report is effective

Venminder

The Third-Party Risk Management Lifecycle

September 11, 2025

Regardless of your industry, the third-party risk management lifecycle is a practical, risk-based framework to identify and mitigate issues that come from third-party relationships while also explaining ongoing and offboarding activities. Use this lifecycle to optimize your third-party risk management program resources, achieve regulatory compliance, and protect your organization and its customers from vendor risk. 


Download the full lifecycle toolkit that includes:

  • eBook: A comprehensive guide covering the third-party risk management lifecycle stages

  • Infographic: A more concise version of the stages of the third-party risk management lifecycle

  • PowerPoint Template: A customizable template to help train your team about key aspects of third-party risk

  • Printable 1-Page PDF: An easy-to-print overview of the third-party risk management lifecycle

Venminder

6 Third-Party Risk Management Reports to Maintain

September 11, 2025

Third-party risk management reports should be consistent, accurate, and easily accessible. Stakeholders, such as risk committees, senior leadership, and the board of directors, need high-quality reports that will support their decision-making. Use this infographic as a guideline for important data to collect and continuously update. 


Download the infographic to learn:

  • 6 types of third-party risk management reports to develop and maintain

  • Data to include in the reports

  • The purpose of each report and how to get started

  • Pro tips to be aware of

Venminder

Vendor Due Diligence

September 11, 2025

What are the vendor due diligence items you need to consider when reviewing your third parties? There are many due diligence related documents and information to gather. Use this handy checklist when thinking through the vendor due diligence you should be collecting and assessing. 


Download this checklist for: 

  • What items you should consider gathering

  • Keep track and check off each item as you complete your process

  • Have confidence thorough vendor due diligence is being performed

Venminder

How-to Guide: Creating a Vendor Risk Questionnaire

September 11, 2025

Understanding the risk, whether for a new or existing third-party product or service, often starts with a questionnaire. Creating a questionnaire in and of itself can be quite a large task. A questionnaire shouldn’t be confused with a risk assessment as they’re two distinct items. Download the guide to learn our recommended steps for how to create a vendor risk questionnaire. 


Download the eBook to learn:

  • Steps to creating your vendor questionnaire

  • Tailoring questionnaires to the type of vendor

  • Risk categories to consider

  • How vendor questionnaires lead to proper oversight

Venminder

Building an Effective Vendor Management Program

September 11, 2025

Financial, operational, and reputational risk are all fundamental negative exposure pain points you must be aware of and protect against. The number of data breaches reported lately is a reminder that the importance of third-party oversight has never been greater. In this infographic, learn the 9 steps to developing an effective vendor management program by placing emphasis on highlighting and mitigating risk. 


Download this infographic to learn:

  • 9 steps to developing an effective vendor risk management program

  • The importance of analyzing vendor due diligence documents

  • How your contract management program can impact your ability to truly manage a third party

Venminder

The Differences Between Vendor Assessments, Questionnaires, Due Diligence, and Continuous Monitoring

September 11, 2025

It’s not uncommon for vendor risk assessment terms to get mixed up or seem like the same thing. However, while all are important, there are differences to be aware of between questionnaires, risk assessments, due diligence, and continuous monitoring. These four activities will tell you the type and amount of risk associated with the vendor, the effectiveness of the vendor’s control environment, and whether the risk is changing. 


Download the infographic to learn:

  • The differences between inherent risk assessments, vendor risk questionnaires, due diligence, and vendor risk assessments

  • The what, why, and when of each

  • Ongoing activities such as continuous monitoring, risk re-assessments, and due diligence reviews

  • Tips to remember

bottom of page