The TPRM lifecycle is the sequence every third-party relationship moves through, from the first conversation about engaging a provider to the day its last copy of your data is certified destroyed. Regulators describe it in five stages, and the reason the stages matter is not tidiness: each one has an entry criterion, an exit criterion and a record it must leave behind, and the failures that examiners write up are stages that were skipped and records that were never produced. This guide walks the TPRM lifecycle stage by stage, with the question each stage answers, the evidence an examiner expects, and where programmes stall.
What this guide covers
- The five stages of the TPRM lifecycle
- Stage 1 of the TPRM lifecycle: planning
- Stage 2: due diligence and selection
- Stage 3: contracting in the TPRM lifecycle
- Stage 4: ongoing monitoring
- Stage 5: termination and exit
- Governance across the TPRM lifecycle
- Frequently asked questions about the TPRM lifecycle

The five stages of the TPRM lifecycle
The Financial Stability Board’s December 2023 toolkit describes tools “throughout the lifecycle” of third-party service relationships; the 2023 Interagency Guidance names the stages as planning, due diligence and third-party selection, contract negotiation, ongoing monitoring and termination; DORA’s Chapter V and the EBA outsourcing guidelines cover the same ground as pre-contractual analysis, the contractual phase, oversight and exit. The vocabulary differs. The TPRM lifecycle underneath does not, and governance runs across all five stages rather than being a sixth.
| Stage | Entry criterion | Exit criterion | Records left |
|---|---|---|---|
| 1. Planning | A business need to engage a third party | Sourcing risk assessment approved; tier assigned | Intake form, inherent-risk score, planning assessment |
| 2. Due diligence and selection | Tier assigned | Due diligence report signed; selection recorded | Scored questionnaire, assurance review, screening, decision record |
| 3. Contracting | Selection approved | Contract executed and checked; register updated | Requirements checklist, exceptions, executed contract |
| 4. Ongoing monitoring | Contract in force | Relationship terminated | Service reports, reassessments, findings, incident and change logs |
| 5. Termination | Decision or trigger to end | Data returned, access removed, record closed | Exit plan, transition record, destruction certificate |
Stage 1 of the TPRM lifecycle: planning
Planning, the first stage of the TPRM lifecycle, answers a question that is easy to skip: should we engage a third party for this at all, and can we oversee it if we do? The Interagency Guidance lists eleven planning considerations, and three of them are routinely absent from real programmes.
The first is the full cost, meaning not the contract price but the price plus integration, oversight and the cost of eventually leaving. The second is the organisation’s own capacity to oversee the provider for the life of the contract: staff, expertise and systems. The third is the contingency, an outline of what would happen if the provider failed or the relationship had to end, written before anyone has a reason to be optimistic.
The stage ends with a tier. Tiering is the mechanism by which proportionality, which every regime demands and none defines, becomes a rule: the inherent-risk questions place the relationship in a band, and the band sets the depth of everything that follows. A programme that assigns the tier after due diligence has done the assessment at the wrong depth.
Stage 2: due diligence and selection
Due diligence is where the TPRM lifecycle earns its evidence, and it is the stage a TPRM lifecycle template is expected to carry already written. The Guidance sets out fourteen factors, from the provider’s strategy and financial condition through information security, operational resilience, incident management, physical security, reliance on subcontractors and insurance. The depth applied to each is the tier’s decision: a low-tier provider with limited data and no privileged access takes a short questionnaire; a provider supporting a critical function takes the enhanced questionnaire, a financial viability check, an assurance report review, a business continuity assessment and, where the risk warrants it, an on-site or remote assessment.
Two rules separate due diligence from a formality. A provider’s statement is an answer, not evidence; the reviewer records the document, report or observation that supports each score. And the stage closes with a written report and a selection decision record that names the conditions of approval, the conflicts of interest considered and the authority that approved. Under DORA Article 28(4) that record is not optional for a financial entity.
Stage 3: contracting in the TPRM lifecycle
The contract is where the previous two stages become enforceable. The Interagency Guidance lists seventeen contract considerations; DORA Article 30 sets nine elements every ICT arrangement must carry and six more for critical or important functions, including unrestricted audit rights and a mandatory transition period on exit. The practical instrument is a requirements checklist completed before execution, with a clause reference against every provision and a recorded exception for every gap. A contract executed without the checklist is unchecked, whatever it says.
The provisions that get negotiated away are the ones the later stages depend on: audit and information rights, incident notification with a clock the organisation can meet its own deadlines inside, subcontracting notice and objection rights, and transition assistance. Losing them in stage 3 is what makes stages 4 and 5 impossible.
Stage 4: ongoing monitoring
Monitoring, the longest stage of the TPRM lifecycle, is what turns a due diligence result that was true at signing into a position the organisation can still defend a year later. It has two halves. Periodic monitoring runs at the cadence the tier sets: service reports against service levels, relationship reviews, assurance renewal, questionnaire reassessment, financial and screening refreshes, subcontractor confirmation and access reviews. Continuous monitoring watches between reviews for the signals that do not wait for a quarter: breach news, financial deterioration, a change of control, a sanctions hit, a regulatory action.
The Guidance names fourteen monitoring considerations and, separately, the escalation of significant issues. In practice the escalation path is the test of a monitoring stage: a service level missed twice, an assurance report expired without a bridge letter, a subcontractor discovered rather than disclosed, or a critical finding past due each need a named forum and a defined consequence. Monitoring that files whatever the provider sends is an inbox, not a stage of the TPRM lifecycle.
Stage 5: termination and exit
Every relationship in the TPRM lifecycle ends. The question is whether it ends on the organisation’s timetable or the provider’s. The Guidance names six termination considerations; DORA Article 28(8) requires exit strategies for critical services that are documented, tested and reviewed, with alternatives, transition plans and contingency measures for the gap between a provider’s failure and the completion of transition. Our separate guide to a DORA exit strategy covers the financial-entity specifics.
The records this stage must leave are concrete: the notice served and its ground, the transition plan executed, the data returned and validated, every provider account and connection removed, and a certificate from the provider of what was destroyed and what, if anything, it retains under a legal obligation. Expiry is a termination too; a contract that quietly lapsed while the provider’s access and the organisation’s data remained is a finding against the programme.
Governance across the TPRM lifecycle
Governance is not stage six. The board approves the policy and the appetite and receives periodic reporting; management directs each stage, escalates and remediates; independent review tests whether the process is designed and operating; and documentation ties the stages together. The Guidance’s ten classes of expected documentation map cleanly onto the records in the table above, which is the simplest way to audit a TPRM lifecycle programme: for each relationship in the inventory, can the organisation produce the record each stage should have left?
Where the whole lifecycle needs building rather than describing, the TPRM Toolkit ships 86 templates organised on exactly these stages, from the intake form and tiering workbook through three populated questionnaires, the contract requirements checklist, the monitoring schedule and the exit plan, each mapped to the regime that requires it. For the definitional starting point, read what TPRM is first; for how the lifecycle is shared by four regimes at once, our guide to third-party risk management across DORA, NIS2 and ISO 27001 is the companion piece.
For the text the stages come from, read the Interagency Guidance guide; for how the same lifecycle carries twelve regimes, the third-party risk management framework; and for stage two in depth, the third-party risk assessment.
Frequently asked questions about the TPRM lifecycle
How long does each stage of the TPRM lifecycle take?
Planning and due diligence for a critical provider are measured in weeks, mostly waiting on the provider’s questionnaire and evidence. Contracting depends on the negotiation. Monitoring lasts for the life of the relationship. Exit for a critical service is the one stage with a regulatory floor: DORA expects a mandatory transition period in the contract, and the exit plan states the realistic time against the tolerable outage.
Can an existing provider skip the early stages?
No. A provider that pre-dates the programme enters the inventory, is tiered, and is brought up to its tier’s due diligence and contract standard on a stated timetable. The stages are the same; only the sequence starts mid-way.
Which stage do examiners test hardest?
Monitoring, because a record of it exists only if the cadence was set and kept. Due diligence and contracts generate paper at signing without anyone trying; monitoring only leaves a record if the cadence was set and kept.
Does the TPRM lifecycle apply to intra-group providers?
Yes. A parent or affiliate providing a service is a third party for the purposes of the programme. The reliance on group assurance may be recorded, but a written agreement, an exit plan for a critical function and the supervisory conditions all still apply.