A TPRM policy is the board-approved statement of how an organisation identifies, assesses, contracts, monitors and exits its third-party relationships, and who is accountable at each step. It is the first document a regulator, an auditor or a prospective customer asks for, and the one every procedure, register and questionnaire in the programme hangs from. This guide sets out what a TPRM policy must contain, which regimes require it, what separates a policy that is evidence from one that is intent, and the mistakes that make a well-written policy fail an examination.
What this guide covers
- Which regimes require a TPRM policy
- What a TPRM policy must contain
- The policy statements in a TPRM policy
- What makes a TPRM policy evidence rather than intent
- Writing the roles section
- Scope decisions the policy has to make
- The TPRM policy and the risk appetite statement
- Common mistakes that fail an examination
- Where to get a TPRM policy that operates
- Frequently asked questions about a TPRM policy

Which regimes require a TPRM policy
Almost all of them, under different names. NIST CSF 2.0 subcategory GV.SC-01 asks for a cybersecurity supply chain risk management programme, strategy, objectives, policies and processes established and agreed by stakeholders. NIST SP 800-53 control SR-1 is the supply chain risk management policy and procedures. ISO/IEC 27001:2022 Annex A control 5.19 addresses information security in supplier relationships, which certification auditors expect to see stated in policy. EBA/GL/2019/02 section 7 requires a written outsourcing policy from financial institutions. The 2023 Interagency Guidance expects the board to approve appropriate policies and management to develop and implement them. 23 NYCRR 500.11 requires written policies and procedures for third-party service providers.
The practical reading is that one TPRM policy, approved once, can cite all six. Writing a separate policy for each regime produces six documents that drift apart and a board that has approved things it cannot compare.
What a TPRM policy must contain
The CSF 2.0 implementation examples for GV.SC-01 describe a strategy, a programme with a plan, policies and procedures shared with stakeholders. Read alongside the Interagency Guidance’s governance section, that produces a stable table of contents for a TPRM policy:
| Section | What it states | Why an examiner looks for it |
|---|---|---|
| Purpose and scope | Every relationship, by contract or otherwise, including affiliates and subcontractors | Scope that stops at paid vendors misses what the Guidance explicitly includes |
| Policy statements | The commitments: responsibility retained, everything inventoried, effort by tier, nothing signed without due diligence, contracts checked, monitoring continues, exit planned, subcontractors inside, programme reviewed | Each statement is a control the examiner can test |
| Lifecycle | The five stages with entry criteria, exit criteria and governing documents | Shows the policy is operated, not aspirational |
| Roles and responsibilities | Board, management, relationship owners, procurement, legal, security, audit | Accountability for each relationship must sit with a named role |
| Proportionality | The tiering method and who may raise or lower a tier | Every regime demands proportionality; this is how it is decided |
| Prohibited arrangements | What the organisation will not contract: unsupervisable, un-auditable, sanctioned | Limits the board has actually set |
| Exceptions | How a deviation is approved, time-limited and revisited | Proves deviations are decisions, not omissions |
| Review | Annual, and on change of regime, structure or portfolio | A policy dated three years ago is stale evidence |
The policy statements in a TPRM policy
The statements are the heart of the document, and they should be written as commitments the organisation can be measured against. Nine cover the ground. Responsibility stays with the organisation whatever it contracts out. Every relationship is inventoried before it receives data, access or payment. Effort is proportionate to risk, decided by tiering. Nothing is signed without completed due diligence. Every contract is checked against a requirements list, with gaps recorded as exceptions. Monitoring continues for the life of the relationship at the cadence the tier sets. Every critical arrangement has a tested exit plan. Material subcontracting is disclosed, assessed and monitored. The programme is reviewed independently and the results reach the board.
Notice what those statements are not. They are not descriptions of good practice in general. Each names a mechanism, a tier, a checklist, a cadence, a plan, that a reader can go and find. A TPRM policy whose statements cannot be tested is a mission statement.
What makes a TPRM policy evidence rather than intent
An examiner reads a policy for four things beyond its content. Approval: the minute of the board or committee that approved it, with the date. Version control: what changed at each revision and who approved the change. Ownership: a named role that maintains it. And operation: the documents the policy refers to actually exist and are in use. The last one is the test a policy fails when the procedures it names do not exist. A TPRM policy that promises tiered due diligence is only evidence if the tiering methodology and the questionnaires exist and the inventory shows tiers assigned.
The third-party risk management framework is the structure that makes that operation visible: the policy at the top, the procedures and registers beneath it, and a crosswalk showing which regime each answers. The policy should name that structure so that a reader can move from a statement to its evidence in one step.
Writing the roles section
The roles section is where accountability either lands on a named function or evaporates. The board approves the policy and the appetite, receives periodic reporting and holds management to remediation. Management owns the programme, its procedures and its registers, and runs the second-line challenge. Each relationship has one relationship owner in the business line, accountable through the lifecycle. Procurement refuses to raise a purchase order for a provider that has not passed intake. Legal owns contract wording and confirms every required provision is present. Information security performs and reviews security due diligence and assurance. Internal audit reviews the programme independently.
Write those as sentences with a subject and a verb, not as a list of departments. A RACI matrix beneath the policy then fixes who is responsible, accountable, consulted and informed for every lifecycle activity, and the inventory records the relationship owner’s name against every provider. A relationship with no named owner is a finding in its own right.
Scope decisions the policy has to make
Three boundary questions come up in every review and the policy should answer them in advance. Intra-group providers: a parent or affiliate providing a service is inside the programme on the same terms, with reliance on group assurance permitted and recorded. Existing providers: relationships that pre-date the policy enter the inventory, are tiered, and are brought up to their tier’s standard on a stated timetable rather than grandfathered. Low-value arrangements: nothing is exempt from the inventory, but the lite tier exists so that a provider with no data and no access takes a short questionnaire and standard terms rather than the full process.
The TPRM policy and the risk appetite statement
The Interagency Guidance names alignment with risk appetite as the first planning consideration and the first thing the board checks. The appetite belongs in a companion document rather than in the policy itself, because it changes more often: which critical functions may be outsourced and on what conditions; the concentration tolerance, such as how many critical functions one provider may support without committee approval; the data and location positions; the subcontracting position; the findings and assurance tolerances. The policy commits the organisation to operate within the appetite; the appetite states the numbers.
Common mistakes that fail an examination
| Mistake | Consequence | Fix |
|---|---|---|
| Scope limited to “vendors” | Affiliates, partners, referral sources and consultants sit outside the programme | Use the Guidance’s language: any business arrangement, by contract or otherwise |
| No tiering rule | Every provider gets the same treatment, so critical ones get too little | State the method and who decides |
| Procedures embedded in the policy | Every operational change needs board approval | Policy states what; procedures state how |
| No exception route | Deviations happen silently | A time-limited exception process with named approvers |
| Copied from another regime’s template | Terms and thresholds that do not match the organisation | Write for the regimes you answer to; cite them |
| Approved once, never reviewed | Stale evidence; missed regime changes | Annual review recorded in document control |
Where to get a TPRM policy that operates
The TPRM Toolkit ships the policy alongside everything it refers to: the charter, the appetite statement, the RACI, the committee terms of reference, the exception procedure, the tiering methodology and the 78 procedures, templates and registers beneath them, so that every statement in the policy points at a document that exists. Each carries a requirements table naming the identifiers it answers across twelve regimes. For the surrounding concepts, read what TPRM is and the TPRM lifecycle; the third-party risk assessment and vendor due diligence checklist guides cover the two procedures the policy’s fourth statement depends on.
Frequently asked questions about a TPRM policy
How long should a TPRM policy be?
Long enough to state scope, commitments, lifecycle, roles, proportionality, prohibitions, exceptions and review, and no longer. The policy in the TPRM Toolkit runs to eight pages, and that is enough. Procedures, questionnaires and registers belong in separate documents the policy names.
Who approves a TPRM policy?
The board or a designated board committee. The Interagency Guidance places approval of policies with the board explicitly, and the EBA guidelines require the management body to approve the outsourcing policy.
Does a TPRM policy replace a vendor management policy?
Yes, and it should. A vendor management policy covers suppliers you pay; a TPRM policy covers every business arrangement. Running both creates two scopes and two owners for the same relationships.
How often must it be reviewed?
At least annually, and on any material change: a new regime, an acquisition, a change in the portfolio’s shape. The review is recorded in the document control table and reported to the board even where nothing changed.