NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new
Third-Party Risk Management Process Flow
Learn

Third-Party Risk Management Process Flow

·Alexander Sverdlov
The short answer
A third-party risk management process runs: request, tier, assess, decide, contract, onboard, monitor, re-assess, exit. Every programme stalls at the same stage, which is waiting for the supplier to return evidence. That step is the only one whose duration is outside your control, so the flow should be designed to start it early and to keep working while it is outstanding, rather than treating it as a gate that blocks everything behind it.
On this page
  1. The nine stages
  2. Where it actually stalls
  3. Who owns each stage
  4. Designing the flow so it does not block
  5. The triggers that restart the flow
  6. Turning the flow into a procedure document
  7. Do this in Venvera
  8. Frequently asked questions

The nine stages

StageWhat happensOutput
1. RequestThe business asks to use a supplier, ideally before signing anythingA registered request with a business owner
2. TierClassify by what breaks if the supplier stopsA tier that sets everything downstream
3. AssessGather evidence proportionate to the tierA scored assessment with recorded reasoning
4. DecideApprove, approve with conditions, or refuseA decision with an owner and a date
5. ContractEnsure the required security and regulatory clauses are presentA contract with clause coverage recorded
6. OnboardProvision access, register the supplier, set the review dateA register entry, not a closed ticket
7. MonitorWatch for incidents, certification expiry, and changeAlerts that reach a person
8. Re-assessOn the cycle, and on triggersAn updated score and decision
9. ExitOffboard, revoke access, retrieve or delete dataEvidence that access actually ended

Stage nine is the one most often missing entirely. Access that outlives the relationship is a finding waiting to happen, and it is the same failure the access review is designed to catch after the fact.

Where it actually stalls

Where a third-party risk management process stalls: chasing the supplier for evidence
One stage in the flow depends on somebody else's priorities. Design around it.

Stage three is the bottleneck, and specifically the part of stage three where you are waiting for a supplier to return a questionnaire or a certificate. Everything before it moves at your pace. Everything after it is fast. The waiting is what turns a two-week process into a two-month one, and it is what makes the business start signing contracts without telling you.

Three design responses work better than chasing harder:

  • Start the request early. Send the evidence request at the moment the business raises the request, before tiering is finalised. The worst case is that you asked for slightly more than you needed.
  • Do not block the whole flow on it. Contract review and clause checking can proceed in parallel.
  • Make the ask proportionate. A shorter questionnaire comes back faster, and a Tier 3 supplier does not need the Tier 1 form.
The assessment stage broken into its own seven steps within the wider flow
Stage three expands into its own process, which is why it dominates the timeline.

Who owns each stage

StageTypically owned byCommon failure
Request and tierBusiness owner with securityRequests arrive after the contract is signed
AssessSecurity or complianceBecomes a queue with no service-level expectation
DecideRisk owner with authority to refuseNobody is empowered to say no
ContractLegalSecurity clauses treated as optional boilerplate
Onboard and monitorBusiness ownerHanded off and never looked at again
Re-assessSecurity or complianceNo trigger exists, so it never happens
ExitBusiness owner with ITAccess is never actually revoked

Designing the flow so it does not block

  1. One front door. Every supplier request enters the same way. Two routes means one of them is unmonitored.
  2. Tier before you assess. Tiering takes minutes and determines hours.
  3. Publish the service level per tier. If the business knows Tier 3 clears in two days, it stops routing around you.
  4. Parallelise legal and security. They do not need each other's output to start.
  5. Automate the chase. Reminders that fire on their own outperform a person remembering to follow up.
  6. Make the register the output. If the process ends in a closed ticket rather than a register entry with a review date, stage eight will never happen.
Vendor questionnaire campaign with response status per supplier
Automated chasing turns the bottleneck stage from a personal chore into a background process.
Supplier register with scores, tiers and review dates
If the flow ends in a register entry with a review date, the later stages happen by default.

The triggers that restart the flow

A calendar cycle alone is not enough, because risk changes between reviews. Five events should push a supplier back into assessment regardless of when it was last looked at.

  • The supplier is acquired or changes ownership
  • The supplier suffers a security incident, disclosed or reported
  • The supplier changes sub-processors or hosting location
  • What they do for you materially changes, particularly if it starts supporting a critical function
  • A certification lapses or its scope changes
Concentration analysis across providers and sub-processors
Monitoring is where concentration shows up, and it only appears when you look across suppliers.

Turning the flow into a procedure document

If you need a written third-party risk management procedure, the flow above is its spine. A usable document names, for each of the nine stages, the owner, the input, the output, the service level and the escalation path when the service level is missed. Anything beyond that is usually written to satisfy an auditor rather than to be followed, and it shows.

Keep the tier definitions in the same document. They are the part people actually need to look up.

Do this in Venvera

Venvera runs the flow as one system: the register, five-signal scoring, questionnaire campaigns with automated chasing, contract clause tracking, concentration analysis and review dates that fire on their own. Because the output is a register entry rather than a closed ticket, stages seven to nine happen by default. See third-party risk management, and how to perform a third-party risk assessment for the assessment stage in detail.

Map your flow with us

Book 30 minutes. We will walk your current process stage by stage, find where it stalls, and show you what the automated version looks like on your own supplier list.

Book a walkthrough

Frequently asked questions

What are the stages of a third-party risk management process?

Request, tier, assess, decide, contract, onboard, monitor, re-assess and exit. The first two are quick and determine everything after them; the last one is the stage most often missing.

Where do third-party risk processes usually fail?

At the assessment stage, waiting for the supplier to return evidence. It is the only stage whose duration depends on someone outside your organisation, so the flow should start it early and continue other work in parallel rather than treating it as a blocking gate.

Who should own third-party risk management?

Ownership is split: the business owner raises and owns the relationship, security or compliance runs the assessment, legal handles clauses, and a risk owner with authority to refuse makes the decision. The common failure is that nobody is empowered to say no.

How do you write a third-party risk management procedure?

Name, for each of the nine stages, the owner, input, output, service level and escalation path, and include the tier definitions. That is a document people will actually use.

What triggers a re-assessment?

Acquisition or change of ownership, a security incident, a change of sub-processor or hosting, a material change to the service, and certification lapse or scope change. These sit alongside the calendar cycle rather than replacing it.

How long should the process take?

Publish a service level per tier rather than one for everything. When the business knows a low-risk supplier clears quickly, it stops bypassing the process, which is the behaviour that causes most unregistered suppliers.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

CONTINUE READING