Third-party risk management, term by term.
The vocabulary of third-party risk, vendor risk and supply chain risk, defined plainly. Each entry gives the definition first, then what the term means in practice for a programme that has to act on it — and links to the pillar page that covers the discipline in full.
How the entries are written
Every entry opens with a definition of one or two sentences, written so it can be quoted on its own. Below that sit two short sections — what the term means inside a third-party risk programme, and the part practitioners get wrong — followed by the questions people actually ask about it.
Where a term has a page of its own on this site, the entry links to it rather than repeating it. The glossary is for definitions; the pillars are for the work.
Browse all terms
Knowing the terms is one thing. Evidencing them is another.
RiskXchange scores, monitors and evidences your third parties continuously — not once a year.