Practitioner guides written at the depth of a senior TPRM lead and an IT auditor: control objectives, evidence, testing approaches, what examiners ask for, and templates you can use. Vendor-neutral, global in scope and free to read and download.
Whitepapers
In-depth guides
Each paper is available to read online or as a PDF, with no form to fill in.
How to design board and executive reporting on third-party risk: appetite statements, KRIs and KPIs, reporting cadence, escalation triggers, board pack anatomy, supervisory expectations across regimes, and how internal audit tests it.
How to discover fourth and nth parties, build a dependency graph, measure concentration, run blast radius and severe-but-plausible scenarios, track CUECs from SOC reports and meet DORA, PRA, CPS 230, RBI, OSFI and US expectations.
Heads of TPRM, CROs, CISOs, operational resilience leads, internal audit and compliance officers
A practitioner guide to risk-tiered vendor due diligence: intake scoping, inherent risk versus criticality, tier criteria, evidence by tier, SOC report review, residual risk, sign-off, reassessment cadence and how internal audit tests the program.
Heads of TPRM, CROs, CISOs, compliance officers, internal auditors
A practitioner map of third-party risk rules across the US, Canada, EU, UK, India, Singapore, the Philippines, the Middle East and Australia/NZ, with terminology and lifecycle crosswalks and one control set.
Heads of TPRM, CROs, CISOs, compliance officers, internal audit and group risk functions
A practitioner guide to governing AI inside a TPRM program and assessing vendor AI: controls, failure modes, NIST AI RMF, ISO/IEC 42001, model risk expectations, EU AI Act roles and the evidence auditors will ask for.
Heads of TPRM, CROs, CISOs, model risk managers, compliance officers, internal audit
A focused due-diligence playbook for AI suppliers and AI-enabled vendors: an evidence-based question set, how to uncover foundation model providers as fourth parties, what ISO/IEC 42001 and NIST AI RMF do and do not prove, EU AI Act deployer duties, shadow AI, and the contract clauses that matter.
Heads of TPRM, CISOs, procurement, model risk and compliance officers, internal audit
How SaaS-to-SaaS integrations and non-human identities became a leading breach path, what recent incidents teach, and how to bring OAuth connections, integration tokens and their scopes into vendor due diligence, contracts and continuous monitoring.
Heads of TPRM, CISOs, identity and SaaS security leads, procurement, internal audit
A practitioner guide to continuous vendor monitoring that reduces noise: how security ratings mislead, how to confirm and attribute signals, how to set thresholds that trigger reassessment, and how to make monitoring examiner-ready rather than a second inbox.
Heads of TPRM, CISOs, SOC and vendor risk analysts, operational resilience leads, internal audit