TPRM glossary

Risk register, a live record, not a filing cabinet

A risk register is the record of identified risks with their owner, assessed severity, treatment decision and review date. In third-party risk it is the authoritative list of what each vendor exposes you to and what is being done about it — distinct from a vendor register, which lists relationships rather than risks.

Two registers, often confused

A vendor register lists relationships: who the supplier is, what they provide, which business owner is accountable, what tier they sit in, when they were last assessed. A risk register lists exposures: this vendor holds this data with this weakness, rated this severity, owned by this person, treated this way, reviewed on this date.

Programmes that keep only the first can tell you everything about their suppliers except what is wrong with them. Programmes that keep only the second lose the population view — coverage, tiering, concentration — that only the vendor register can produce. Both are needed, and the link between them is the vendor record.

What a good entry holds

A description specific enough to act on — "no MFA on the administrative console used by their support staff", not "access control weaknesses". An inherent and a residual rating, so the effect of the controls is visible. A named owner who is a person, not a department. A treatment decision with a due date. And a review date that has been met.

The failure mode is age. Registers accumulate: entries are added, treated in principle, never closed, and after two years the document describes a programme that no longer exists. A register nobody trusts gets worked around, and the working-around is invisible — which is worse than the stale entries, because at least those are countable.

Common questions

What is the difference between a risk register and a vendor register?
A vendor register lists relationships — supplier, service, owner, tier, assessment date. A risk register lists exposures, each with a severity, an owner, a treatment decision and a review date. Most programmes need both, linked through the vendor record.
What should a third-party risk register entry contain?
A specific description of the exposure, the vendor and service it relates to, inherent and residual ratings, a named individual owner, the treatment decision with a due date, the evidence supporting it, and a review date. Anything vaguer than that cannot be actioned or closed.
How often should a risk register be reviewed?
Individual entries on the review date set for them — driven by severity, so critical exposures are revisited far more often than low ones. The register as a whole benefits from a periodic sweep for entries that have passed their review date, since those are the ones that quietly go stale.

Definitions are the easy part. Evidence is not.

See what your vendors actually expose — scored, monitored and evidenced in one place.