TPRM glossary

Third-party risk management, term by term.

The vocabulary of third-party risk, vendor risk and supply chain risk, defined plainly. Each entry gives the definition first, then what the term means in practice for a programme that has to act on it — and links to the pillar page that covers the discipline in full.

How the entries are written

Every entry opens with a definition of one or two sentences, written so it can be quoted on its own. Below that sit two short sections — what the term means inside a third-party risk programme, and the part practitioners get wrong — followed by the questions people actually ask about it.

Where a term has a page of its own on this site, the entry links to it rather than repeating it. The glossary is for definitions; the pillars are for the work.

Browse all terms

Compensating control
when the required control will not fit
Concentration risk
when the register hides a single point of failure
Continuous monitoring
because an annual assessment is a photograph
Critical third party
a designation, not a description
Data processing agreement
the contract UK and EU GDPR make compulsory
Due diligence questionnaire
the wider set of questions, not just the security ones
Fourth-party risk
the suppliers your suppliers depend on
Information security policy
the document every assessment asks for first
Inherent risk
the exposure before anything is done about it
Key risk indicator
a measure that moves before the loss does
Material outsourcing
the arrangements a regulator wants to hear about
Nth-party risk
the chain past the point you can enumerate it
Residual risk
what is left once the controls are counted
Right to audit
a clause worth having and rarely worth using
Risk appetite
the line that makes a decision automatic
Risk register
a live record, not a filing cabinet
Risk treatment
four options, and only one of them is a plan
Security questionnaire
evidence, or a spreadsheet of assertions
Shadow IT
the vendors nobody told you about
Sub-processor
the processor your processor hired
Supply chain attack
one compromise, many victims
Third-party vendor
every vendor is a third party; not every third party is a vendor
Vendor consolidation
fewer suppliers, and a different risk profile
Vendor lifecycle management
from first contact to verified deletion
Vendor risk scoring
a number is a summary, not an argument
Vendor tiering
deciding what deserves the effort

Knowing the terms is one thing. Evidencing them is another.

RiskXchange scores, monitors and evidences your third parties continuously — not once a year.