Third-party risk is one discipline answering to several regulators. The lifecycle is the same whoever is asking: identify what the vendor touches, assess before you sign, evidence the assessment, and keep watching while the contract runs. DORA and NIS2 then add specific register and oversight duties on top of that common spine, which is why it pays to build the spine once.
7 pages on Third-party risk, in the order the work happens. Jump to the stage you are at, or read straight through.
Establish the lifecycle and the criteria that decide how hard you look at a given vendor.
Ask questions that produce evidence, and record the answers so they are reusable next year.
Decide whether to run the programme in-house or buy it, and judge platforms on oversight rather than questionnaire count.
These sit under another subject but bear directly on Third-party risk.
The free compliance check runs the Third-party risk gap assessment in about five minutes and gives you a scored report you can take to a board meeting.
14-day free trial · no credit card · unlimited users