Skip to main content
ASI24 Logo
ASI24
Start Assessment
© 2026 ASI24 Ventures. All rights reserved.
PrivacyTermsCookies
Back to Assessments

Third-Party Risk Management

AI

Assess your vendor and supplier risk management program maturity.

Our Third-Party Risk assessment evaluates your organization's ability to identify, assess, and manage risks arising from vendor and supplier relationships. This assessment covers the full vendor lifecycle from due diligence through ongoing monitoring and exit planning.

Standards Alignment

Aligned to 5 standards: ISO 27036, NIST SP 800-161...
ISO 27036

Supplier Relationships Security

NIST SP 800-161

Supply Chain Risk Management

EBA Guidelines

Outsourcing Arrangements

DORA

ICT Third-Party Risk

Shared Assessments

SIG Questionnaire Framework

Domains Covered

1
TPRM Governance & Strategy

Evaluates the governance framework, strategic alignment, and organizational commitment to third-party risk management. Assesses board-level oversight, policy frameworks, resource allocation, and integration with enterprise risk management.

2
Third-Party Inventory & Classification

Assesses the organization's ability to maintain comprehensive inventories of third-party relationships, classify relationships based on risk and criticality, and identify concentration risks across the third-party portfolio.

3
Due Diligence & Selection

Evaluates the organization's processes for assessing prospective third parties, conducting appropriate due diligence, and making risk-informed selection decisions based on defined criteria.

4
Contract Management

Assesses the organization's approach to negotiating, documenting, and managing contractual arrangements with third parties, including required provisions, service level agreements, and audit rights.

5
Ongoing Monitoring & Performance

Evaluates the organization's capabilities for continuously monitoring third-party performance, risk indicators, and compliance throughout the relationship lifecycle.

6
Info Sec & Data Protection

Assesses the organization's approach to managing information security and data protection risks in third-party relationships, including security requirements, access management, and data handling.

7
BCM Exit Management

Evaluates the organization's approach to ensuring third-party resilience, developing exit strategies, and maintaining contingency arrangements for critical relationships.

8
Subcontracting Risk

Assesses the organization's approach to managing risks arising from third-party subcontracting arrangements and extended supply chain dependencies.

9
Reporting, Assurance & Continuous Improvement

Evaluates the organization's approach to TPRM reporting, independent assurance, regulatory compliance, and continuous improvement of third-party risk management capabilities.

Assessment Details

90

Questions

32

Minutes (estimated)

9

Domains

Start AssessmentView All Assessments
ISO-aligned methodology
Instant results & recommendations
Free to complete