Reference · 23 terms


Third-party risk management & procurement due-diligence glossary

Plain-English definitions covering TPRM methodology, evidence standards, and the procurement vocabulary that governs due-diligence advisor sourcing. Written for procurement, risk, and compliance teams who need the vocabulary before a first call.

Business Associate Agreement (BAA)

Also: BAA

A contract required under HIPAA between a healthcare organization (covered entity) and any vendor (business associate) that creates, receives, maintains, or transmits protected health information on its behalf. A BAA defines the vendor's obligations to safeguard that data and is a standard due-diligence prerequisite for healthcare-sector vendor relationships involving patient data.

Related: Right-to-Audit Clause, SOC 2 Report

See: vendor due diligence, third party risk management framework

Right-to-Audit Clause

Also: audit rights clause

A contract provision giving the customer (or its designated auditor) the right to inspect a vendor's records, systems, or facilities to verify compliance with security, financial, or operational commitments made in the agreement. A common, heavily negotiated term in vendor contracts involving sensitive data or regulated processes.

Related: Business Continuity Attestation, SOC 2 Report

See: vendor due diligence, due diligence framework

Subprocessor Disclosure

Also: subcontractor disclosure

A vendor's formal disclosure of the third parties (subprocessors or subcontractors) it relies on to deliver its service, including what data or access each one has. Subprocessor disclosure is the practical mechanism that makes fourth-party risk mapping possible - without it, an organization has no visibility into who else is actually touching its data or processes through the vendor relationship.

Related: Fourth-Party Risk, Right-to-Audit Clause

See: third party risk management, vendor due diligence

Evidence & Standards 9

Business Continuity Attestation

Also: BCP attestation

A vendor's formal statement or supporting evidence confirming it has a tested business continuity and disaster recovery plan in place, typically requested during due diligence for vendors supporting a critical process. An attestation alone (a vendor saying it has a plan) is weaker evidence than a summary of actual test results or a third-party audit of that plan.

Related: Business Continuity Plan (BCP), Right-to-Audit Clause

See: vendor due diligence, procurement due diligence checklist

Business Continuity Plan (BCP)

Also: BCP, disaster recovery plan, DRP

A vendor's documented plan for maintaining or quickly restoring critical operations after a disruption - a natural disaster, a cyber incident, a key-personnel loss. A closely related document, the disaster recovery plan (DRP), typically focuses specifically on restoring IT systems and data. Requesting and reviewing the actual plan (not just an attestation that one exists) is standard practice for vendors supporting operationally critical functions.

Related: Business Continuity Attestation

See: vendor due diligence

Digital Operational Resilience Act (DORA)

Also: DORA

An EU regulation, in force since January 2025, setting binding ICT third-party risk management requirements for banks, insurers, and other financial entities operating in the EU, including mandatory contractual provisions, a register of information on ICT third-party providers, and oversight of "critical" ICT third-party providers by EU regulators.

Related: NIST SP 800-161, Right-to-Audit Clause

See: third party risk management framework

Due-Diligence Questionnaire (DDQ)

Also: DDQ, vendor questionnaire

A structured set of questions sent to a prospective or existing vendor to collect information on its financial stability, security practices, compliance posture, and operational resilience. The SIG questionnaire is the most widely used standardized DDQ in TPRM; many organizations also maintain a shorter custom DDQ for lower-risk vendors.

Related: SIG Questionnaire

See: vendor due diligence, procurement due diligence checklist

ISO 27001 Certification

Also: ISO/IEC 27001

A certification, issued by an accredited certification body, confirming a vendor's information security management system (ISMS) meets the ISO/IEC 27001 international standard. Commonly requested as evidence during vendor security due diligence. Certification confirms the ISMS was audited against the standard; it does not by itself confirm every specific control a customer might care about, which is why due-diligence reviewers still check the certificate's scope statement.

Related: SOC 2 Report

See: third party risk management framework, third party risk assessment

NIST SP 800-161

Also: Cybersecurity Supply Chain Risk Management Practices, C-SCRM

A publication from the National Institute of Standards and Technology providing cybersecurity supply-chain risk management practices for federal agencies and contractors, widely referenced beyond government as a benchmark framework for third-party and supply-chain risk programs. Revision 1 expanded guidance on supplier risk assessment and response.

Related: ISO 27001 Certification

See: third party risk management framework

SIG Questionnaire

Also: Standardized Information Gathering questionnaire, SIG Core, SIG Lite

The Standardized Information Gathering questionnaire, published and maintained by the Shared Assessments Program, is the most widely used due-diligence instrument in third-party risk management. It comes in a full "Core" version for high-risk vendors and a lighter "Lite" version for lower-risk ones, covering security, privacy, and operational-risk domains in a standardized format vendors can reuse across multiple customers.

Related: Due-Diligence Questionnaire (DDQ), Vendor Risk Management Maturity Model (VRMMM)

See: third party risk assessment, vendor due diligence

SOC 2 Report

Also: SOC 2 Type I, SOC 2 Type II, Trust Services Criteria report

An independent auditor's report, issued under the AICPA's System and Organization Controls (SOC) framework, evaluating a vendor's controls against the Trust Services Criteria (security, availability, processing integrity, confidentiality, privacy). A Type I report evaluates controls at a point in time; a Type II report evaluates whether those controls operated effectively over a period, typically 6-12 months, and is the stronger evidence of the two for TPRM purposes.

Related: ISO 27001 Certification, Right-to-Audit Clause

See: third party risk assessment, vendor due diligence

Vendor Risk Management Maturity Model (VRMMM)

Also: VRMMM

A benchmarking rubric published by the Shared Assessments Program that assesses how mature an organization's third-party risk management program is against defined maturity levels and industry peers. The VRMMM is a maturity-assessment tool, not a control framework - it's commonly used alongside a framework like NIST SP 800-161 or ISO/IEC 27036, not as a replacement for one.

Related: SIG Questionnaire

See: third party risk management framework

Program & Methodology 4

Continuous Monitoring

Also: ongoing vendor monitoring, continuous vendor monitoring

The practice of tracking vendor risk signals - adverse media, financial-health indicators, security-posture changes, breach disclosures - on an ongoing basis after onboarding, rather than only reassessing at a fixed calendar interval. Continuous monitoring is what turns a one-time due-diligence check into an actual risk-management program.

Related: Third-Party Risk Management, Adverse Media Screening

See: third party risk management

Third-Party Risk Management

Also: TPRM, vendor risk management

The discipline of identifying, assessing, and monitoring risk introduced by external vendors and suppliers, spanning the full relationship lifecycle from pre-contract due diligence through ongoing monitoring and eventual offboarding.

Related: Vendor Risk Tiering, Due-Diligence Questionnaire (DDQ), Continuous Monitoring

See: third party risk management

Vendor Offboarding

Also: vendor termination, vendor exit management

The formal process of ending a vendor relationship: revoking access and credentials, confirming data return or destruction, closing out contractual obligations, and documenting the relationship's history for future reference. Offboarding is frequently the weakest link in a TPRM program - risk from a terminated vendor that still holds data or system access rarely gets tracked with the same rigor as onboarding.

Related: Third-Party Risk Management, Subprocessor Disclosure

See: third party risk management

Vendor Risk Tiering

Also: risk tiering, vendor segmentation

The practice of sorting vendors into risk categories (typically high, medium, low) based on inherent risk factors - data sensitivity, financial exposure, operational criticality, regulatory scope - before any assessment work begins. Tiering determines how deep a due-diligence assessment needs to go and how often the vendor gets reassessed.

Related: Inherent Risk vs. Residual Risk, Third-Party Risk Management

See: third party risk management, third party risk assessment

Risk Concepts 4

Concentration Risk

Also: vendor concentration risk

The risk created when an organization depends heavily on a single vendor, or on multiple vendors that in turn share the same critical subcontractor, cloud provider, or region. Concentration risk means a single point of failure can disrupt multiple parts of the business simultaneously, and it's frequently invisible without fourth-party mapping.

Related: Fourth-Party Risk, Vendor Risk Tiering

See: third party risk management

Fourth-Party Risk

Also: subcontractor risk, n-th party risk

Risk introduced by a vendor's own critical subcontractors and subprocessors - the vendors your vendors rely on. A vendor with strong controls can still expose you to concentration risk if it (and several of your other vendors) all depend on the same undisclosed subprocessor or cloud region. Mapping fourth-party relationships requires the vendor to disclose its own critical suppliers.

Related: Vendor Risk Tiering, Third-Party Risk Management

See: third party risk management, third party risk assessment

Inherent Risk vs. Residual Risk

Also: inherent risk, residual risk

Inherent risk is how risky a vendor relationship is before any of the vendor's actual controls are evaluated - based purely on what data, systems, or processes the vendor would touch. Residual risk is what remains after the vendor's real controls (security, financial stability, continuity planning) are verified. A vendor can have high inherent risk but low residual risk if its controls are genuinely strong.

Related: Vendor Risk Tiering, Residual Risk Acceptance

See: third party risk assessment

Residual Risk Acceptance

Also: risk acceptance

A formal, documented decision by someone with the authority to do so, accepting a vendor's remaining residual risk after due diligence rather than requiring further remediation or rejecting the relationship. A defined due-diligence framework specifies who can sign a risk acceptance at each risk tier, so high-residual-risk vendors don't get approved by someone without the standing to accept that exposure.

Related: Inherent Risk vs. Residual Risk

See: due diligence framework, third party risk assessment

Screening & Monitoring 3

Adverse Media Screening

Also: negative news screening

The practice of checking a vendor's name (and often its key executives) against news sources, litigation databases, and public records for negative coverage - fraud allegations, regulatory action, financial distress, litigation - as part of due diligence and ongoing monitoring. Typically run at onboarding and repeated periodically as part of continuous monitoring.

Related: Sanctions Screening, Continuous Monitoring

See: vendor due diligence

Know Your Vendor (KYV)

Also: KYV

The practice of verifying a vendor's identity, ownership structure, and legitimacy before onboarding - business registration checks, beneficial-ownership verification, sanctions screening. KYV is an early, foundational step in a due-diligence process, adapted from "know your customer" (KYC) practices in financial services and applied to the vendor side of the relationship.

Related: Sanctions Screening

See: vendor due diligence

Sanctions Screening

Also: watchlist screening, OFAC screening

Checking a vendor and its beneficial owners against government sanctions and watchlists (such as OFAC's Specially Designated Nationals list) to confirm the organization is legally permitted to do business with them. A standard, usually automated, pre-screening step early in vendor due diligence, before deeper financial or security review begins.

Related: Adverse Media Screening

See: vendor due diligence

TPRM sourcing brief

Occasional emails when we publish a new guide, glossary update, or vendor addition. No spam, unsubscribe anytime.

Single opt-in. We store only your email to send these updates. See ourprivacy notice. This is procurement information, not a compliance guarantee or legal advice.