Third-Party Risk

Vendor Risk Management Kit: Full Lifecycle, 7 Documents.

End-to-end TPRM documentation for regulated industries. Vendor tiering framework, due diligence questionnaire, weighted risk scoring, contract requirements checklist, monitoring tracker, and exit playbook. CPS 230 and ISO 27001 A.5.19 aligned.

APRA CPS 230APRA CPS 234Privacy Act 1988 (APP 8)ISO 27001:2022 A.5.19-5.22SOCI Act 2018
Buy Now: $899 AUD →

7 documents: ready to implement.

AIR-TPRM-GDE-001

TPRM Framework Guide

Risk landscape, regulatory drivers (CPS 230, CPS 234, APP 8, ISO 27001), lifecycle, fourth-party risk

AIR-TPRM-VIR-001

Vendor Inventory and Tiering Register

Master supplier catalogue, Tier 1–4 classification, sub-provider register, concentration risk

AIR-TPRM-DDQ-001

Due Diligence Questionnaire

Financial, security (15 questions), privacy (12 questions), resilience, sub-provider disclosure: vendor-facing

AIR-TPRM-RAS-001

Risk Assessment and Scoring Workbook

Weighted model: Security 35%, Privacy 20%, Resilience 20%, Financial 15%, Supply Chain 10%

AIR-TPRM-CCL-001

Contract Requirements Checklist

30+ clauses rated Mandatory/Required/Advisable by vendor tier across 4 domains

AIR-TPRM-MON-001

Monitoring Tracker

KPI dashboard, continuous intelligence sources, incident log, annual risk rating summary

AIR-TPRM-EXP-001

Vendor Exit and Offboarding Playbook

Planned and emergency exit procedures, data deletion, access revocation, post-exit review

What makes this different.

Weighted risk scoring model

Five-domain scoring model produces defensible, consistent vendor risk ratings: not checkbox compliance.

Fourth-party risk addressed

Sub-provider disclosure, concentration risk mapping, and fourth-party change notification clauses are explicitly covered.

Emergency exit procedure

The exit playbook includes a 12-step immediate response for unplanned vendor exits: insolvency, regulatory action, or security incident.

CPS 230 material service provider aligned

The vendor tiering and due diligence framework is designed to satisfy APRA CPS 230 material service provider requirements.

30+ contract clauses

The contract checklist covers every material security, privacy, resilience, and exit provision: tiered by vendor criticality.

Who this is for Risk and procurement teams in regulated industries, CISOs managing vendor portfolios, compliance teams subject to CPS 230, and risk consultants.

FAQ

The framework is aligned to CPS 230 requirements for material service provider identification, due diligence, contract terms, and ongoing oversight. APRA-regulated entities should also review the CPS 230 Supply Chain Pack.
Yes. Sections 2-6 of the DDQ are designed to be sent to vendors for completion. Section 1 is completed internally.
Yes. The vendor inventory includes a sub-provider register, concentration risk summary, and the contract checklist requires sub-provider change notification.

Ready to implement?

Download Vendor Risk Management Kit today: $899 AUD, instant delivery.

Buy Now: $899 AUD → Browse all products