TPRM glossary

Risk treatment, four options, and only one of them is a plan

Risk treatment is the decision about what to do with an identified risk. ISO 31000 sets out the options: avoid the activity, reduce the risk with controls, share or transfer it through contract or insurance, or accept it knowingly. Doing nothing without deciding is not acceptance — it is an unrecorded decision. Also called Risk response.

The four options, applied to a vendor

Avoid — do not use the vendor, or do not use it for this purpose. The option most often ruled out for commercial reasons and most often correct when the exposure is a critical process with a weak supplier and no alternative.

Reduce — require remediation, or add controls on your side: restrict the data shared, tighten the integration, monitor more closely. Share — move part of the exposure through contractual liability, indemnities or insurance, remembering that transferring financial consequence does not transfer regulatory accountability or the operational outage. Accept — decide the residual risk sits within appetite, and record who accepted it, when, and until when.

Making treatment stick

Treatment is where third-party risk programmes leak. The finding is raised, the vendor agrees to fix it, and then the trail ends: no owner on your side, no deadline, no evidence requirement, no consequence for missing it. Six months later the same finding reappears in the next assessment and is raised again as though it were new.

What closes the loop is unglamorous: a named owner on both sides, a due date derived from severity rather than negotiated per case, a defined piece of evidence that constitutes proof, and escalation that actually fires when the date passes. That mechanism — actions, deadlines, evidence, SLA tracking — is what TARA's treatment and SLA work automates, because the reason it fails by hand is volume rather than intent.

Common questions

What are the four risk treatment options?
Avoid the activity creating the risk, reduce it through controls or remediation, share or transfer it through contract or insurance, or accept it knowingly and record the acceptance. ISO 31000 also recognises deliberately taking on risk to pursue an opportunity, which in vendor terms is proceeding with a supplier because the commercial upside justifies the exposure.
Does transferring risk to a vendor remove it?
No. Contractual liability and insurance move financial consequence; they do not move regulatory accountability, and they do nothing about the outage. Regulators are consistent that a firm remains responsible for an outsourced function regardless of what the contract says about liability.
What is the difference between risk treatment and remediation?
Treatment is the decision — avoid, reduce, share or accept. Remediation is one way of executing the "reduce" option: the specific work done to fix a finding. Every remediation is a treatment; not every treatment is a remediation.

Definitions are the easy part. Evidence is not.

See what your vendors actually expose — scored, monitored and evidenced in one place.