Third-Party Risk Management: How to Build the Program Without a TPRM Team
Third-party risk management (TPRM) is the ongoing work of listing every outside company that can reach your systems or data, ranking each by the damage a compromise would cause, and applying matching controls, contract terms, and reviews.
Table of Contents
A company with 20 to 1000 users can run this without hiring a dedicated team. The program comes down to one owner, a ranked vendor list, evidence someone actually reads, security terms in the contract, and an exit process that removes access when the work ends. It's the part of a managed cybersecurity program that depends least on tools and most on someone paying attention.
IBM's 2026 Cost of a Data Breach Report studied 602 breached organizations and dozens of factors that push breach costs up or down, and the factor at the top of the cost-increase list was a compromised business partner. When an attacker came in through a supplier, it added $227,250 to the average breach, more than security system complexity, shadow IT (software people use without IT knowing), or regulatory noncompliance.
That ranking makes sense once you picture how these breaches unfold. The entry point sits in someone else's environment, on systems you can't monitor, run by people you've never met. You tend to find out late. And secondhand.
It doesn't take an enterprise risk platform to fix. It takes structure, and a handful of decisions made on purpose instead of by default.
What Is Third-Party Risk Management, and How Is It Different From Vendor Risk Management?
Third-party risk management covers every outside party with access to your systems, data, or operations. Vendor risk management is the subset focused on companies you pay. At 150 people? Nearly the same list.
Edges are where the two split. A third party can be a contractor with a guest account in your Microsoft 365 tenant, a customer who uploads files to a shared portal, a franchise partner, or the open-source code a developer pulled into an app your team uses every day, which is its own branch of software supply chain risk. None of them sent you an invoice. All of them can reach something.
NIST treats the whole group as one problem. Its quick-start guide for cybersecurity supply chain risk management, published in October 2024, says its practices apply to business partners and to data and digital service providers, not only to the companies you buy technology from. NIST shortens the discipline to C-SCRM. It's the same work under a federal label.
If you run a plant, the manufacturing side of vendor risk gets into OT integrators, the firms that program and service production equipment, and their remote connections to machines on the floor. The program underneath works the same way whether you make parts, move freight, or bill hours.
Why Do Third-Party Breaches Cost More and Last Longer?
They start in systems you can't see. IBM's 2026 data shows supply chain compromise was the second most common way into breached organizations, took 258 days to identify and contain, and ran 11 days longer than the average breach.

Look at the cost rows first, because they confuse people. A breach that started through the supply chain averaged $4.96M, a hair under the $4.99M global average. Almost identical. So the entry point alone isn't what makes these expensive.
The $227,250 figure measures something different. It's what a compromised partner adds on top of everything else going wrong in a breach, and it came out as the single largest increase in the study. Put the two numbers together and the picture gets clearer. A supplier breach is a normal breach with a harder problem attached, which is that the people who could see it first don't work for you.
Time is where that compounds. In IBM's data, internal IT and security teams found 38% of breaches themselves, and those took 209 days to identify and contain. When a third party raised the alarm instead, whether a business partner, a consultant, or law enforcement, the timeline stretched to 280 days. That's more than 2 extra months of exposure, and it lands hardest on exactly the breaches that started outside your walls.
Underneath all of it is one structural fact. You don't own the logs. You can't scan your supplier's network, you usually can't see their alerts, and your contract may not require them to tell you quickly, and each of those was decided earlier, usually at signing, usually without anyone treating it as a security decision.
Nobody chose that outcome. It accumulated.
Who Owns Third-Party Risk at a Company With 20 to 1000 Users?
One named person, usually the CFO, the COO, or the IT lead, owns the program and signs off on accepted risk. Finance, IT, and legal each run one piece. Without a single owner, those pieces never connect.
Picture how a new vendor arrives at a company without that owner. A department head finds a tool they like and starts a free trial with a company email address, which quietly creates the first account before anyone else has heard of the vendor. Finance approves the spend because it's under the approval threshold, IT creates the accounts because someone asked, and legal, if it sees the contract at all, reviews the payment terms and little else. Every step is reasonable on its own. Nobody in that chain ever asked what the vendor could reach, and that question is the whole program.
Each approval made sense at the time. Over a few years they compound into a vendor list nobody can rank.
NIST makes roles a formal outcome under GV.SC, the supply chain category in version 2.0 of its Cybersecurity Framework, released in 2024. The quick-start guide names the functions that should coordinate, including cybersecurity, IT, legal, human resources, and engineering. At your size those functions might be 4 people. That's fine. What matters is that the table below gets filled in with names instead of department labels.

The last row is the one that breaks. The person who works with the vendor every week is the first to know when the relationship changes, and the last one anyone thinks to ask.
If nobody inside has the time or background to own it, a vCISO, a part-time outsourced security lead, can carry the process. We laid out what a vCISO costs for companies weighing that route. The risk decisions still belong to leadership, whoever runs the paperwork.
How Do You Build a Third-Party Risk Management Program?
Find the vendors you already have, rank them by what they can reach, collect evidence matched to each tier, write security terms into contracts, monitor on a schedule, and remove access completely when the relationship ends.
Those 6 steps map to the lifecycle NIST describes. The order matters less than doing each one, every time, for every vendor that lands in your top tier.
Find the Vendors You Already Have
Start with money and access, not memory. Ask department heads to list their vendors and you get the ones they remember. The records know better.
- The accounts payable ledger for the last 24 months. Every recurring payment is a candidate.
- Enterprise applications in Microsoft Entra ID, where every app someone signed into with a company account left a record, including the free ones finance never saw.
- Guest accounts in your Microsoft 365 tenant.
- Remote access tools such as ScreenConnect, TeamViewer, or AnyDesk, plus any vendor VPN account left open after a project wrapped up.
- Who has a badge or a door code? Physical access counts, from the copier technician to the after-hours cleaning crew.
Expect the Entra list to run longer than the accounts payable list. Free trials and app consents, the prompt where someone clicks Allow to let an app read their mailbox or calendar, never pass through accounting.
Rank Each Vendor With 3 Questions
Criticality, in NIST's quick-start guide, rests on 3 things. How important the supplier's products or services are to the business, how sensitive the data it processes or stores is, and how much access it has to your systems. Score each vendor on those 3 and the tiers mostly sort themselves.

Don't overthink the boundaries. A vendor that's hard to place usually belongs in Tier 1, because the uncertainty is the finding. If nobody can say what it reaches, nobody is watching what it reaches.
Tier 1 is shorter than people fear.
Size the Questionnaire to the Tier
Send a 300-question security questionnaire to every vendor and the program usually dies. Vendors answer slowly or not at all, the answers pile up unread, the team quietly stops sending them, and 6 months later there's a folder of PDFs on a shared drive and no program anyone could describe to an auditor.
CISA's approach is a better model. Its Information and Communications Technology (ICT) Supply Chain Risk Management Task Force publishes an enterprise vendor SCRM template organized around 7 categories, from supplier governance and secure design through personnel security and supply chain resilience. Then the task force published a version for small and medium-sized businesses, scoped to IT and communications firms with up to 500 employees, that keeps only the questions relevant to specific buying situations. The buyer-side questions fit any small company. Even the federal template expects you to trim it.
Tier 1 vendors get the full set. Tier 2 gets a dozen questions about what that vendor actually touches. Tier 3 gets nothing at all.
Read the SOC 2 Report Instead of Filing It
A SOC 2 report is an independent auditor's opinion on a service provider's security controls, built on criteria the AICPA maintains. It's the evidence a vendor is most likely to send you. It's also the one most likely to be filed without being read past the opinion letter.

These 4 sections matter more than that letter on page one.
- Complementary user entity controls. This is usually a short list near the end of the system description, the part of the report written to the AICPA's SOC 2 description criteria. These are controls the vendor's design assumes you're running on your side, like reviewing who has access to their platform or requiring multi-factor authentication (MFA) for your own users. If you aren't doing them, the clean report doesn't fully cover you.
- Subservice organizations. Your vendor runs on someone else's infrastructure, usually AWS, Azure, or Google Cloud. Under the carve-out method, those providers weren't tested at all. That's normal, and it also means you're trusting a second company you never assessed.
- The period covered. A Type 2 report covers a window of time, usually 3 to 12 months, and one whose window closed 14 months ago describes last year. Ask for a bridge letter, the vendor's written statement that nothing material changed since, or wait for the new report. The difference between Type I and Type II matters here too, since a Type 1 only checks design at a single point in time.
- Exceptions, found in the testing section (usually section 4). One exception isn't disqualifying. An exception in access reviews at the company that runs your payroll is worth a phone call.
Skip the user entity list and responsibility slides back to your team without anyone noticing, since it's the one section of the report that assigns work to you rather than to the vendor.
Write the Security Terms Into the Contract
Negotiating power peaks before signature and again at renewal. Every other time, you're asking nicely.
NIST's guide gets specific. It recommends putting cybersecurity requirements, and how you'll verify them, into default contract language. It also recommends information-sharing rules that reach your supplier's own suppliers, and security expectations written into service level agreements that hold for the life of the relationship. For a Tier 1 vendor, that turns into a short list your attorney can work from:
- Breach notification within a fixed number of hours, counted from when the vendor discovers the incident rather than when they finish investigating it. That clock should feed straight into your own incident response process.
- A right to assess, or at minimum a right to receive the current SOC 2 every year.
- Flow-down. Any subcontractor that touches your data meets the same terms.
- Data return and certified destruction when the contract ends, with a deadline attached.
Any vendor that won't agree to breach notification is telling you something useful before you've spent a dollar.
Monitor on a Schedule the Tier Sets
At this size, monitoring is mostly a calendar and a habit. Tier 1 vendors get reassessed every year and any time their name shows up in breach news, while Tier 2 gets a lighter review at renewal, which is also your second chance to add the contract terms you missed the first time.
Catching a vendor incident in progress is harder. Much harder. IBM's numbers show who tends to catch breaches sooner. Managed security service providers identified 31% of breaches in the 2026 study, and those took 230 days to identify and contain, against 280 when an outside party raised the alarm. Someone watching sign-ins from vendor accounts and odd remote sessions closes most of that gap, whether that's your own team or a SOC as a service, meaning an outside security operations center watching around the clock.
Offboard Like the Relationship Actually Ended
Offboarding is where good programs leak. The contract ends, the invoices stop, and the access stays.

GV.SC-10, a line item in NIST's framework, covers what happens after a partnership or service agreement concludes. In practice, accounts get disabled and shared passwords get rotated on a named date, API keys (the credentials one system uses to talk to another) and app consents get revoked, and a certificate of data destruction goes on file before the final invoice is paid.
Microsoft 365 makes the account piece harder than it looks, because guest accounts created for a vendor's staff don't expire on their own, and they keep whatever access they had to Teams channels and SharePoint sites until someone removes them. Microsoft's answer is Entra access reviews, which can scope a review to guest users only and then block sign-in for 30 days before removing the user from the tenant. It's a good control. There's a licensing catch.
According to Microsoft's Entra licensing page, access reviews need Entra ID P2 at minimum, and the inactive-guest report and inactive-user review scoping need Entra ID Governance. Microsoft 365 Business Premium includes P1. So a 120-person company on Business Premium doesn't have the automated version unless it added the Defender Suite for Business Premium, which brings P2, or bought Governance separately.
Without the license, the manual version still works. Once a quarter, pull the guest list from the Entra admin center, check each account's last sign-in, and delete anything tied to a vendor you no longer use. It takes an afternoon.
Is Your MSP a Third Party Too?
It's usually the highest-privilege vendor you have. A managed service provider typically holds admin rights to every laptop, server, and cloud tenant through its remote management tools, the software that lets its technicians reach any machine without being on site, which puts it at the top of Tier 1.
CISA's small business guidance treats this as a core scenario. The working group walked through a small company hiring an MSP and picked the template questions an owner should ask before awarding the contract. The stated outcome is that the business confirms the MSP shares its priority on supply chain security as a condition of the award.
So ask. How do they protect the remote management platform itself? Who on their team can reach your environment, and how is that access logged? What's their breach notification commitment to you? In hours? Do they hold their own SOC 2 or an equivalent, and will they share it? And what happens to your credentials and documentation if you leave?
Good ones answer fast. One that deflects them has answered a different question.
What Do the First 90 Days Look Like?
Roughly 13 weeks takes a company from nothing to a working program. Inventory first, tiering second, Tier 1 evidence third, then contracts and an offboarding sweep, ending with a one-page report to leadership.

Week 13 matters more than it looks. A risk the owner has accepted in writing is a business decision. One nobody wrote down is simply unmanaged.
Spreadsheet or TPRM Software?
For a company with a few dozen vendors worth reviewing, a spreadsheet can carry the first year. Software starts to earn its cost when reassessments, evidence requests, and renewals outgrow one person's calendar.
Nearly every comparison of the two you'll find is published by a company that sells the software, so the answer always comes out the same way. The real tradeoff is gentler. A tool can send questionnaires and chase replies automatically. It can't decide who owns the program, and it won't notice that your payroll vendor's SOC 2 assumes you run quarterly access reviews you've never scheduled.
Sequence matters here. Buy the tool after the owner, the tiers, and the contract terms exist. Before that, it automates a process nobody has defined.
And skip outside help entirely if you already have a security or risk lead with open time on their calendar. The NIST and CISA material here is free, and the work is mostly patience.