Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

TPRM metrics dashboard showing coverage, assessment timeliness, open findings, incidents and concentration

TPRM Metrics and KPIs: A Practical 2026 Guide

TPRM metrics tell you whether your third-party risk programme is actually controlling risk or only generating paperwork. Counting assessments completed says little; measuring how many critical suppliers were assessed on time, how long serious findings stay open and how exposed you are to a single provider says much more. Good metrics let leaders steer the programme and let the team show what it has achieved.

This guide explains which TPRM metrics are worth tracking, how to define them, how to set thresholds, how to report them and which numbers to avoid. It is general guidance that you should adapt to the size and maturity of your programme.

Free gap assessment

Where do you actually stand against ISO 27001?

Score every management system clause and all 93 Annex A controls, free, and get a prioritised gap list back.

Run the free ISO 27001 gap assessment →  or  View premium report sample

Why TPRM metrics matter

A third-party risk programme spends time and money on onboarding, assessments, monitoring and offboarding. Without metrics, leaders cannot tell whether that effort is reducing risk, where it is falling behind or where to invest. Metrics also help the team defend its budget with facts.

Good TPRM metrics answer real questions: Do we know who our suppliers are? Have the risky ones been reviewed? Are problems getting fixed? Are we exposed to a single point of failure? Framing metrics as questions keeps them useful. The approach fits the principle in ISO 31000 on risk management that risk management should be integrated, dynamic and based on the best available information.

Types of TPRM metrics

Distinguish three kinds. Activity metrics count what the team does, such as assessments completed. Performance metrics show how well the programme runs, such as timeliness and coverage. Risk metrics show the exposure itself, such as open findings, incidents and concentration.

Activity numbers are easy to collect but easy to game. Focus on performance and risk metrics, and use activity data only as context. A dashboard with a handful of each type is better than fifty measures that nobody reads.

Coverage and inventory TPRM metrics

You cannot manage what you cannot see. Track the share of suppliers that are in your register, have an owner and have a risk tier. Measure how quickly new suppliers are added after purchase, and how many were found later through payments or contracts rather than through procurement.

A growing gap between the register and the payments ledger signals that suppliers are being onboarded outside the process. Fixing that is often the single biggest improvement to the programme. See the TPRM lifecycle for how onboarding should work.

MetricWhat it showsExample threshold
Inventory coverageShare of suppliers in the register with a risk tier100 percent of active suppliers
Assessment timelinessShare of critical suppliers assessed within the cycleAt least 95 percent
Open high findingsNumber and age of unresolved serious findingsNone older than 90 days
Contract coverageShare of critical suppliers with required clauses100 percent
Incident rateSupplier-related incidents by severityTrending down
ConcentrationShare of critical services with a single providerReviewed each quarter

Assessment and monitoring metrics

Measure whether critical and high-risk suppliers are assessed within the cycle you set, for example annually for critical suppliers. Track the average time to complete onboarding assessments, since long delays push business teams to bypass the process. Track the share of suppliers under continuous monitoring, as described in third-party continuous monitoring.

Look at quality as well as quantity: how many assessments were reviewed by a second person, and how many needed rework. A sample-based quality check catches superficial reviews.

  • Percentage of critical suppliers assessed on time
  • Average onboarding assessment duration
  • Share of suppliers under continuous monitoring
  • Assessment quality review results

Findings and remediation metrics

Findings drive risk reduction only if they are fixed. Track the number of open findings by severity, their average age and the share closed within target. Highlight overdue high-severity findings on the dashboard. Also track repeat findings: the same issue recurring at the same supplier indicates weak remediation or weak follow-up.

Group findings by theme. If many suppliers fail on incident response or access control, you may need clearer requirements or better contract clauses. See third-party risk assessment findings for how to classify and track them.

Free third-party risk assessment

How much risk does this vendor bring?

Tier the vendor, check the evidence, rate the risks from 30 third-party scenarios and choose controls referenced to ISO 27001, NIST CSF 2.0 and DORA. You get a tier, a heat map and the findings an auditor would raise, free.

Start the free vendor risk assessment →  or  View premium report sample

Contract and governance metrics

Measure the share of critical suppliers with the clauses your policy requires, such as audit rights, incident notification and exit terms. Track exceptions and their age. See third-party contract clauses for what to require.

Governance metrics include the share of policy exceptions with approvals, the number of overdue reviews of the policy itself and attendance at governance meetings. They are less exciting but show whether the programme has the authority it needs. Our page on the TPRM policy explains what to include.

Incident and concentration metrics

Count supplier-related incidents by severity, root cause and supplier, and track time to notify and to resolve. Watch trends rather than single numbers: a rise in minor incidents at one supplier may precede a major one.

Measure concentration: how many critical services rely on one provider, one region or one fourth party. Report the top dependencies. See vendor concentration risk and fourth-party risk. These metrics support decisions about diversification and exit planning.

Set thresholds and owners for TPRM metrics

A metric without a threshold is only a number. Agree what is acceptable, what needs attention and what needs escalation, and mark the levels with colours or labels. Tie thresholds to your risk appetite where possible.

Assign an owner to each metric, responsible for explaining changes and proposing action. Review the metric set once a year and retire measures that no longer drive decisions. Keep definitions and data sources documented so results are consistent from one report to the next.

Reporting TPRM metrics to leaders

Present a one-page dashboard with the most important metrics, trends over time and a short commentary on what is changing and what action is needed. Emphasise decisions: where extra resources, policy changes or supplier exits are needed. See third-party risk reporting for a full reporting approach.

Avoid overloading readers. Show the top five to ten TPRM metrics, and put the detail in an appendix. Use plain language and explain any technical terms.

Common mistakes with TPRM metrics

Frequent errors include counting activity rather than outcomes, using metrics without thresholds, mixing definitions across reports, measuring what is easy rather than what matters, hiding bad news and never retiring stale measures. Another is presenting a perfect score every quarter, which usually means the measure is too easy.

Avoid these by tying each metric to a decision, testing data quality and being open about weak spots. Metrics should provoke useful conversations, not comfort.

Data quality and automation

Metrics are only as reliable as their data. Pull supplier lists from procurement or finance systems, not from spreadsheets kept by individuals, and reconcile them regularly with the register. Where you can, automate data collection from your TPRM platform, contract system and incident log, and document any manual adjustments. Sample a few records each quarter to check that reported numbers match the source.

Be careful with automation that produces numbers no one understands. Keep a plain-language definition beside each metric and the formula used. When a figure changes sharply, the first question should be whether the data changed, not the risk.

Compare results over time and, where possible, with peers or industry surveys. A single quarter tells you little, while a steady rise in overdue findings or a steady fall in onboarding time tells you a great deal. Record the reason for any change in method so that trends stay meaningful, and annotate charts with events such as a new policy or a major incident.

A short worked example

A financial services firm reviews its dashboard and finds that assessment timeliness for critical suppliers is 97 percent, but open high findings older than ninety days have risen from three to eleven. It investigates and finds that remediation follow-up is being done by email with no owner. It introduces a tracker with named owners and weekly reviews.

Within a quarter, overdue high findings fall to two. The dashboard also reveals that four critical services depend on the same cloud region, prompting a diversification review. The metrics changed decisions, which is the point.

Structuring the assessment data

If you want consistent assessments that feed reliable metrics, the Third-Party Risk Assessment Report and Workbook provides a structured report and workbook for capturing risk ratings, findings and actions in a form that can be summarised. Whatever the tool, meaningful TPRM metrics rest on clean data, clear definitions and thresholds that trigger action.

TPRM metrics FAQ

What are the most important TPRM metrics?

Inventory coverage, timeliness of assessments for critical suppliers, open and aged high findings, contract coverage, incident trends and concentration of critical services.

How many metrics should we report?

A handful, typically five to ten, with clear thresholds and commentary. Keep detail in an appendix for those who want it.

What is the difference between KPIs and KRIs?

KPIs show how well the programme performs, such as timeliness. KRIs show the level of risk exposure, such as open high findings or concentration.

How often should we report?

Monthly for operational teams and quarterly for senior leaders and the board, with urgent issues escalated immediately.

Which metrics should we avoid?

Pure activity counts such as number of questionnaires sent, unless they are paired with outcomes. They are easy to inflate and rarely drive decisions.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.