Skip to content
Resources

Whitepapers for third-party risk and audit teams

Practitioner guides written at the depth of a senior TPRM lead and an IT auditor: control objectives, evidence, testing approaches, what examiners ask for, and templates you can use. Vendor-neutral, global in scope and free to read and download.

Whitepapers

In-depth guides

Each paper is available to read online or as a PDF, with no form to fill in.

Featured whitepaper

Board-Ready Third-Party Risk: What Directors and Executives Need to See

How to design board and executive reporting on third-party risk: appetite statements, KRIs and KPIs, reporting cadence, escalation triggers, board pack anatomy, supervisory expectations across regimes, and how internal audit tests it.

Board members, CROs, heads of TPRM, CISOs, compliance officers, internal audit
19 min read
Whitepaper

Your Vendor's AI Is Your Risk: Assessing AI Suppliers and AI-Enabled Vendors

A focused due-diligence playbook for AI suppliers and AI-enabled vendors: an evidence-based question set, how to uncover foundation model providers as fourth parties, what ISO/IEC 42001 and NIST AI RMF do and do not prove, EU AI Act deployer duties, shadow AI, and the contract clauses that matter.

Heads of TPRM, CISOs, procurement, model risk and compliance officers, internal audit
10 min read
Whitepaper

SaaS-to-SaaS Breaches: The Integration Tokens Nobody Is Watching

How SaaS-to-SaaS integrations and non-human identities became a leading breach path, what recent incidents teach, and how to bring OAuth connections, integration tokens and their scopes into vendor due diligence, contracts and continuous monitoring.

Heads of TPRM, CISOs, identity and SaaS security leads, procurement, internal audit
10 min read
Get started

See VendRisk360 on your own vendors

A tailored walkthrough with a third-party risk specialist, built around your program, your regulators and your vendors.