TPRM Lifecycle Phases Flashcards

1
Q

TPRM Info

A

Third Party Risk Management (TPRM) is the framework that consists of policies and procedures, controls, and oversight; established to identify and address risks imposed upon an organization by their third parties. To ensure third parties are operating securely and effectively, by adequately monitoring and mitigating risks related to the data and/or
processes that have been outsourced, an organization must have in place an effective TPRM program. Customers, board members, customers, and regulators often expect that organizations have mature TPRM programs in place.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

TPRM Lifecycle
P.P.C.C.D.C

A

Six Phases:
1. Planning & Oversight
2. Pre-Contract Due Diligence
3. Contract Review
4. Continuous Monitoring
5. Disengagement
6. Continuous Improvement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Planning & Oversight

A

Provides an organization with the foundation to build upon and properly support their overall program.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Pre-Contract Due Diligence

A

Ensures the organization performs due diligence, commensurate with the level of inherent risk, to determine if the organization should proceed with a specific third party relationship and prior to signing a contract to ensure business needs will be met.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Contract Review

A

Ensures the organization documents relationship expectations in an agreement that can be upheld in a court of law. It also ensures risks noted within the due diligence process can be addressed within contractual clauses.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Continuous Monitoring

A

Requires the organization to assess third party risk on a continual basis to ensure contract terms, business obligations, legal and regulatory requirements, and performance expectations are met.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Disengagement

A

Ensures the organization is able to transition away from a third party with minimal impact should the relationship end due to contract expiration or when adverse/unplanned conditions are met.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Continuous Improvement

A

An ongoing activity which seeks to enhance the organization’s TPRM program as third party risk management guidance, trends, and techniques are realized.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly