{
  "name": "Procurement Proof Guides",
  "as_of": "2026-07-14",
  "count": 6,
  "guides": [
    {
      "slug": "third-party-risk-management",
      "name": "Third-Party Risk Management",
      "category": "framework-methodology",
      "url": "https://procurementproof.com/guides/third-party-risk-management",
      "primary_keyword": "third party risk management",
      "search_volume": 3100,
      "aka": [
        "TPRM",
        "vendor risk management",
        "third-party risk"
      ],
      "methods": [
        "Vendor inventory and risk tiering (inherent risk scoring before any assessment work begins)",
        "Standardized due-diligence questionnaires, most commonly the Shared Assessments SIG (Standardized Information Gathering) questionnaire",
        "Evidence verification against self-reported answers (SOC 2 Type II reports, ISO 27001 certificates, financial statements, insurance certificates)",
        "Fourth-party mapping to understand a vendor's own critical subcontractors and concentration risk",
        "Contractual risk controls: right-to-audit clauses, breach-notification timelines, data-handling and subcontracting terms",
        "Ongoing monitoring: adverse-media screening, financial-health signals, security-posture rescoring, and periodic reassessment tied to risk tier"
      ],
      "standards_bodies": [
        {
          "name": "Shared Assessments Program",
          "abbr": "SIG",
          "note": "Publishes the Standardized Information Gathering (SIG) questionnaire, the de facto industry-standard TPRM due-diligence instrument, and the Vendor Risk Management Maturity Model (VRMMM)."
        },
        {
          "name": "National Institute of Standards and Technology",
          "abbr": "NIST",
          "note": "NIST SP 800-161 (Cybersecurity Supply Chain Risk Management Practices) is the primary US federal reference framework for third-party and supply-chain risk."
        },
        {
          "name": "International Organization for Standardization",
          "abbr": "ISO",
          "note": "ISO/IEC 27036 addresses information security for supplier relationships; ISO 31000 provides the general risk-management framework many TPRM programs are built on."
        },
        {
          "name": "Office of the Comptroller of the Currency",
          "abbr": "OCC",
          "note": "OCC Bulletin 2013-29 (updated by 2020-10 interagency guidance) sets third-party risk management expectations for national banks and federal savings associations."
        }
      ]
    },
    {
      "slug": "third-party-risk-management-framework",
      "name": "Third-Party Risk Management Framework",
      "category": "framework-methodology",
      "url": "https://procurementproof.com/guides/third-party-risk-management-framework",
      "primary_keyword": "third party risk management framework",
      "search_volume": 350,
      "aka": [
        "TPRM framework",
        "vendor risk framework"
      ],
      "methods": [
        "Regulatory-mapping exercise: which frameworks are explicitly referenced by your regulator, industry body, or key customer contracts",
        "Gap analysis against the chosen framework's control language, not just a checkbox adoption statement",
        "Maturity benchmarking using the Shared Assessments VRMMM or an equivalent internal rubric",
        "Framework-to-process mapping: translating abstract control language into your actual tiering thresholds, questionnaire sections, and escalation triggers",
        "Periodic framework review as the standard itself is revised (NIST and ISO both update on multi-year cycles)"
      ],
      "standards_bodies": [
        {
          "name": "National Institute of Standards and Technology",
          "abbr": "NIST",
          "note": "NIST SP 800-161 Rev. 1 (Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations) is the primary US reference framework, especially for federal and defense-adjacent supply chains."
        },
        {
          "name": "International Organization for Standardization",
          "abbr": "ISO/IEC 27036",
          "note": "A four-part standard covering information security in supplier relationships, from overview and concepts through ICT supply-chain security guidance."
        },
        {
          "name": "Shared Assessments Program",
          "abbr": "VRMMM",
          "note": "The Vendor Risk Management Maturity Model is a benchmarking rubric (not a control framework) used to assess how mature a TPRM program is against industry peers."
        },
        {
          "name": "European Union",
          "abbr": "DORA",
          "note": "The Digital Operational Resilience Act sets binding ICT third-party risk management requirements for EU financial entities, including named contractual and oversight provisions."
        }
      ]
    },
    {
      "slug": "third-party-risk-assessment",
      "name": "Third-Party Risk Assessment",
      "category": "framework-methodology",
      "url": "https://procurementproof.com/guides/third-party-risk-assessment",
      "primary_keyword": "third party risk assessment",
      "search_volume": 600,
      "aka": [
        "vendor risk assessment",
        "TPRM assessment",
        "third-party security assessment"
      ],
      "methods": [
        "Inherent-risk scoring before vendor contact (data sensitivity, financial exposure, operational criticality, regulatory scope)",
        "Standardized questionnaire scaled to risk tier - full SIG for high-risk vendors, a lite/core version for lower-tier ones",
        "Evidence verification: SOC 2 Type II reports, ISO 27001 certificates, penetration-test summaries, insurance certificates, financial statements",
        "Residual-risk scoring after evidence review, documented against a consistent, repeatable rubric",
        "Gap and remediation tracking for findings that don't clear the acceptable-risk threshold",
        "Reassessment scheduling tied to the resulting risk tier, not a fixed calendar date for every vendor"
      ],
      "standards_bodies": [
        {
          "name": "Shared Assessments Program",
          "abbr": "SIG",
          "note": "The Standardized Information Gathering questionnaire is the most widely used due-diligence instrument underlying third-party risk assessments, available in Core and Lite depth tiers."
        },
        {
          "name": "American Institute of CPAs",
          "abbr": "SOC 2",
          "note": "SOC 2 Type II reports (issued under AICPA's Trust Services Criteria) are the most commonly requested piece of verification evidence in a security-focused third-party assessment."
        },
        {
          "name": "International Organization for Standardization",
          "abbr": "ISO 27001",
          "note": "ISO/IEC 27001 certification is a frequently requested evidence artifact for information-security-management-system maturity in a vendor assessment."
        }
      ]
    },
    {
      "slug": "due-diligence-framework",
      "name": "Due-Diligence Framework",
      "category": "framework-methodology",
      "url": "https://procurementproof.com/guides/due-diligence-framework",
      "primary_keyword": "due diligence framework",
      "search_volume": 80,
      "aka": [
        "due diligence framework",
        "vendor due diligence framework"
      ],
      "methods": [
        "Scope definition: which risk categories are in scope for every vendor (financial, security, compliance, operational, reputational)",
        "Tiered depth rules: what level of check applies at each inherent-risk tier",
        "Evidence-sufficiency standards: what documentation is required and what counts as acceptable versus insufficient",
        "Decision thresholds: defined score or finding levels that trigger approval, conditional approval, or rejection",
        "Sign-off authority mapping: who can approve at each risk tier, and when it escalates above procurement to legal, security, or executive review",
        "Documentation and audit-trail requirements: what gets recorded so a decision can be reconstructed and defended later"
      ],
      "standards_bodies": [
        {
          "name": "International Organization for Standardization",
          "abbr": "ISO 31000",
          "note": "The general risk-management standard many due-diligence frameworks borrow their scoring and escalation structure from."
        },
        {
          "name": "Shared Assessments Program",
          "abbr": "SIG",
          "note": "Provides a standardized evidence-collection instrument that a due-diligence framework can specify as its baseline documentation requirement."
        }
      ]
    },
    {
      "slug": "vendor-due-diligence",
      "name": "Vendor Due Diligence",
      "category": "process-execution",
      "url": "https://procurementproof.com/guides/vendor-due-diligence",
      "primary_keyword": "vendor due diligence",
      "search_volume": 700,
      "aka": [
        "supplier due diligence",
        "vendor due diligence process"
      ],
      "methods": [
        "Pre-screening: sanctions/watchlist checks, business-registration verification, litigation and adverse-media screening",
        "Financial due diligence: financial statement review, credit and payment-history checks, insurance-coverage verification",
        "Security and operational due diligence: SOC 2/ISO 27001 evidence review, data-handling practices, subcontractor disclosure",
        "Business-continuity due diligence: disaster-recovery and continuity plans, historical uptime/incident record where available",
        "Reference and track-record checks where the relationship criticality warrants them",
        "Formal sign-off against documented thresholds, with the decision and supporting evidence retained on record"
      ],
      "standards_bodies": [
        {
          "name": "Shared Assessments Program",
          "abbr": "SIG",
          "note": "The SIG questionnaire is commonly used as the evidence-gathering instrument within a vendor due-diligence process."
        },
        {
          "name": "Financial Action Task Force",
          "abbr": "FATF",
          "note": "FATF sanctions and anti-money-laundering guidance informs the pre-screening/watchlist-check step common to rigorous due-diligence processes."
        }
      ]
    },
    {
      "slug": "procurement-due-diligence-checklist",
      "name": "Procurement Due-Diligence Checklist",
      "category": "process-execution",
      "url": "https://procurementproof.com/guides/procurement-due-diligence-checklist",
      "primary_keyword": "procurement due diligence checklist",
      "search_volume": 40,
      "aka": [
        "procurement checklist",
        "vendor onboarding checklist"
      ],
      "methods": [
        "Financial checks: business registration verification, financial statement or credit-report review, payment-history and litigation screening",
        "Security checks: SOC 2/ISO 27001 evidence, data-handling and encryption practices, incident-history disclosure",
        "Compliance checks: relevant regulatory registrations, sanctions/watchlist screening, industry-specific certifications where applicable",
        "Continuity checks: business-continuity and disaster-recovery plan review, insurance coverage verification, subcontractor/fourth-party disclosure",
        "Contractual checks: right-to-audit clause, breach-notification timeline, data-ownership and termination terms",
        "Tiering logic: which of the above apply in full, in a lighter form, or not at all, based on the vendor's inherent-risk score"
      ],
      "standards_bodies": [
        {
          "name": "Shared Assessments Program",
          "abbr": "SIG Lite",
          "note": "The SIG Lite questionnaire is a commonly used lighter-tier instrument for lower-risk vendor checklists, distinct from the full SIG Core used for high-risk vendors."
        }
      ]
    }
  ]
}