Third-Party Risk Management And Vendor Assessment

Build practical third-party vendor due diligence and risk-management skills.

81
August 2026
  • Trust badge
  • Trust badge

Get this this CPD‑Accredited programme now. Be secure with a SSL-secured payment backed up by a 14‑day money‑back guarantee.

Overview

Did you know third-party vendors expose your biggest vulnerabilities? Software breaches recently sparked 31% of security incidents.

Unchecked vendors weaken cybersecurity, compliance, and financial stability. Consequently, this practical course unleashes ultimate vendor risk mastery. 

Safeguard every lifecycle stage from onboarding to offboarding. Neutralize fourth-party, AI, and software threats effortlessly. Make sharper, bulletproof decisions that protect your bottom line.

Learning Outcomes

By completing this course, learners will be able to:

  • Define third-party risk concepts and common vendor risk categories.
  • Classify vendors using inventory, due diligence, and risk tiers.
  • Assess inherent and residual risk across vendor relationships.
  • Analyse cybersecurity evidence, including SOC 2 and ISO documentation.
  • Evaluate operational, financial, ethical, and fourth-party vendor risks.
  • Develop risk-informed monitoring, remediation, and offboarding decisions.

Certification Information

Certification Information

Successful learners receive this certificate:

Certificate of Completion from Spanish Compliance Institute

It demonstrates completed learning across vendor-risk management topics. It does not provide regulatory accreditation or professional licensing.

Curriculum

1

Module 1: Foundations of Third-Party Risk

1 Hour

  • Third-Party Risk Defined
  • Vendor Types and Categories
  • Inherent and Residual Risk
  • Governance and Accountability
2

Module 2: Vendor Lifecycle Risk Governance

1 Hour

  • Vendor Inventory and Classification
  • Due Diligence and Tiering
  • Contract Controls and SLAs
  • Monitoring and Offboarding
3

Module 3: U.S. Vendor Compliance Requirements

1 Hour

  • Banking and GLBA Rules
  • HIPAA Business Associate Rules
  • SEC and NYDFS Oversight
  • Privacy and Breach Laws
4

Module 4: Cybersecurity and Data Protection

1 Hour

  • NIST Supply Chain Risk
  • Access and Data Controls
  • Cloud and SaaS Risk
  • SOC 2 and ISO Evidence
5

Module 5: Operational Vendor Risk Domains

1 Hour

  • Business Continuity Risk
  • Financial and Insurance Risk
  • Ethics and Compliance Risk
  • Fourth-Party Risk
6

Module 6: Advanced Vendor Assessment Methods

1 Hour

  • Risk Scoring Models
  • Audit and Corrective Actions
  • AI Vendor Risk
  • Software Supply Chain Risk
7

Mock Exam

30 Minutes

8

Final Exam

30 Minutes

Requirements

  • No prior TPRM experience is required.
  • A computer, tablet, or compatible mobile device.
  • Reliable internet access for online course materials.

This Course Includes

  • Approximately Seven hours of self-paced online learning.
  • Practical vendor risk guidance and applied scenarios.
  • Regulatory and professional framework awareness.
  • Vendor assessment and lifecycle governance coverage.
  • Mock Exam and Final Exam.

Why Choose Us

Spanish Compliance Institute delivers structured, practical compliance-focused professional learning. Training connects risk concepts with realistic workplace responsibilities.

Learners choose Spanish Compliance Institute because training is:

  • Clear and structured for busy professionals.
  • Practical across real vendor lifecycle decisions.
  • Focused on cybersecurity, compliance, and operational vendor risk.
  • Flexible through convenient self-paced online access.
  • Relevant across international vendor-risk environments.

Career Opportunities

This course can support professionals entering vendor-risk roles.

  • Third-Party Risk Analyst
  • Vendor Risk Analyst
  • Compliance Analyst
  • Cybersecurity Risk Analyst
  • Operational Risk Analyst
  • Third-Party Governance Coordinator

These roles commonly involve vendor oversight, assessment, and risk reporting. The course supports development without guaranteeing employment or promotion.

More About This Course

What is Third-Party Risk Management?

Third-Party Risk Management governs risks created by external business relationships. It covers assessment, contracts, monitoring, remediation, and exit decisions.

Vendor Risk Management focuses more specifically on vendor relationships. TPRM can also include contractors, partners, and fourth parties.

Who should take this course?

This training supports professionals responsible for third-party relationships.

  • Compliance teams overseeing vendor obligations and control evidence.
  • Procurement professionals managing due diligence and contract requirements.
  • Risk analysts assessing inherent and residual vendor risk.
  • Cybersecurity teams reviewing third-party security controls and evidence.
  • Legal teams supporting vendor contracts and data obligations.
  • Managers accountable for critical vendor relationships and resilience.

What does the course cover?

Coverage spans six modules and 24 structured sections. Topics include due diligence, tiering, SLAs, and monitoring.

Cybersecurity includes NIST, cloud, SOC 2, and ISO evidence. Advanced topics include AI vendors and software supply chains. The detailed curriculum appears below.

Why is third-party vendor assessment important?

Vendor assessment reveals exposure before risks become costly incidents. It compares inherent risks against controls and residual exposure.

Regular reassessment supports changing risks throughout vendor relationships. Risk-based oversight helps focus resources on critical vendors.

Frequently Asked Questions

Yes, you will master the end-to-end TPRM lifecycle, from setting up governance and defining risk appetite to establishing vendor offboarding workflows.

Yes, you will gain actionable skills in evaluating inherent vs. residual risk, categorizing vendors into risk tiers, and auditing self-reported security questionnaires.

Yes, the course provides step-by-step guidance on analyzing third-party security certifications, audit reports, and Data Processing Agreements to ensure compliance.

Yes, you will learn practical techniques to map subcontractor concentration risks, review Business Continuity and Disaster Recovery plans, and safeguard against supply chain disruption.

Yes, you will learn how to measure TPRM effectiveness using Key Performance Indicators (KPIs) and build a cost-efficient vendor management program for your organization.

Share This Course