Table of Contents
If you ask five individuals to define third-party management, you will probably receive five distinct interpretations. This variation is not due to a lack of clarity in the profession, but rather because the field is rapidly evolving and advancing.
The realm of third-party management is expanding beyond its conventional focus on risk, as organizations are beginning to understand that effective vendor management encompasses procurement, contracting, performance, and the entire lifecycle of the relationship. Within this broader framework, specialized areas are emerging to address the most intricate and significant risk domains with the necessary depth.
This organic development is leading to a new structure for third-party management and the execution of related tasks. It is also creating opportunities for leaders who grasp the direction of this evolution, as they will be the ones to establish programs that are taken seriously by customers, regulators, and executives.
Here’s what is beginning to take form.
The Three-Level Hierarchy
Level 1: Third-Party Management (TPM), the Enterprise Umbrella
At the pinnacle of the hierarchy is Third-Party Management (TPM), also known as Vendor Management. This level sets the organization-wide strategy concerning three key aspects: the program’s scope, the operational structure, and the regulations, frameworks, and standards that the program must adhere to.
TPM acts as the central coordinator for managing third parties throughout the organization. It addresses questions that no single team can answer: which vendors are included, who has the authority to approve a new vendor, and which frameworks the program must comply with. Additionally, it establishes the infrastructure, support, and governance necessary for procurement, risk, legal, information security, and business owners to operate from a unified playbook throughout the entire relationship lifecycle.
Level 2: Third-Party Risk Management (TPRM), the Risk Function
Below that is Third-Party Risk Management (TPRM), a risk-oriented discipline that functions as a sub-component within the larger TPM framework. TPRM is tasked with overseeing the management of third-party risk across all relevant risk domains specific to an organization’s operational context. The practical implementation of this can differ based on industry and operational scope.
The new IIA Third-Party Topical Requirement, created by the Institute of Internal Auditors, effectively outlines the primary risk domains that organizations should consider integrating into their TPRM program. These topical requirements are global standards rather than industry-specific regulations, making them applicable across various sectors and providing a useful baseline regardless of the program’s position. They encompass eleven domains: strategic, reputational, ethical, operational, financial, compliance, cybersecurity and data protection, information technology, legal, sustainability, and geopolitical.
This comprehensive approach is intentional, as it reflects the full range of risks that third parties can introduce to an organization. In practice, however, most TPRM programs only address a few of these domains, indicating that the gaps are not coincidental but structural. The complete scope should serve as the foundation for every organization, customized to fit the operational environment and risk tolerance, rather than being developed incrementally in response to regulatory demands or immediate risks.
Level 3: Domain Specialties Like TPCRM
Certain risk domains are so vital to an organization’s operations that they evolve into their own subspecialties, complete with dedicated teams, tools, and a level of focus that a generalist TPRM program cannot consistently provide. These teams may be part of the TPRM function or located in other areas of the business, such as information security, operations, or compliance, depending on the organization’s structure. Regardless, they function as a distinct discipline within the broader TPRM framework.
The most prominent example currently emerging is Third-Party…
Source: Original article