Description
The TPRM Toolkit is built on the lifecycle every regulator uses
Every supervisor that asks to see a third-party risk management programme asks for the same five things in the same order: how you plan an engagement, how you check a provider before you sign, what the contract has to say, how you watch the provider afterwards, and how you get out. The 2023 Interagency Guidance from the Federal Reserve, FDIC and OCC sets that lifecycle out in full; DORA Chapter V, the EBA outsourcing guidelines, PRA SS2/21 and the Financial Stability Board’s December 2023 toolkit all follow it.
The TPRM Toolkit is organised on that lifecycle: 86 editable templates, 66 Word documents and 20 Excel workbooks, across 10 sections. A programme built on it can be shown to a US bank examiner, a DORA supervisor, a SOC 2 auditor, a PCI DSS assessor or a data protection authority without being rewritten for each.
What the TPRM Toolkit maps to
The TPRM Toolkit claims 188 requirement identifiers across 12 regimes, and the crosswalk workbook lists every one of them against the document that answers it:
- the Interagency Guidance on Third-Party Relationships (88 FR 37920, June 2023): all 90 of its planning, due diligence, contract, monitoring, termination and governance considerations, item by item;
- NIST CSF 2.0 GV.SC-01 to GV.SC-10;
- NIST SP 800-53 Rev 5.2.0, the seven supply chain controls that concern service relationships, with the 5 component-integrity controls listed as out of scope rather than quietly omitted;
- ISO/IEC 27001:2022 Annex A 5.19 to 5.23;
- DORA Articles 28, 29 and 30, including every element of Article 30(2) and 30(3);
- NIS2 Article 21(2)(d) and 21(3);
- SOC 2 CC9.2; PCI DSS v4.0.1 12.8 and 12.9; GDPR Article 28; HIPAA business associate rules at 45 CFR 164.308(b), 164.314(a), 164.502(e) and 164.504(e); 23 NYCRR 500.11 as amended in November 2023; and EBA/GL/2019/02.
Every document in the TPRM Toolkit carries a Requirements-addressed table naming the identifiers it answers, in the full citation form a reader searching the source will look for.
Three vendor security questionnaires that arrive already written
Most third-party programmes stall at the questionnaire. The TPRM Toolkit ships three, generated from one question bank so they cannot drift from each other:
- Lite, 21 questions, for a low-tier provider with limited data or access;
- Standard, 84 questions, for the core of the portfolio;
- Enhanced, 136 questions across 20 control domains, for critical and high-risk providers, adding resilience, subcontracting, physical security, cloud, artificial intelligence and exit.
Each TPRM Toolkit questionnaire carries the evidence expected for every question, a mandatory flag on the ten questions where a zero is a finding whatever the total, reviewer scoring columns and a domain-score sheet. The scoring guide that goes with them makes two reviewers reading the same response reach the same score.
Contracting in the TPRM Toolkit: 32 provisions, mapped clause by clause
The TPRM Toolkit’s contract requirements checklist lists 32 provisions a third-party contract should carry, each mapped to the regime that requires it, with a standard column, a critical-arrangement column and a space for the clause reference in the signed contract. It covers all 17 of the Interagency Guidance’s contract considerations and all 15 elements of DORA Article 30(2) and 30(3).
Behind the checklist, the TPRM Toolkit carries a clause library with model wording in standard and critical forms, an information security schedule drafted to bind, a GDPR Article 28 processor agreement, a HIPAA business associate agreement checklist, a service level schedule, and five clause guides on audit rights, subcontracting, incident notification, termination and exit, and offshoring. The incident guide carries the regulatory clocks with their anchors, because the NIS2 final report runs from the notification and not from awareness, and a contract that gets that wrong puts the organisation in breach.
Exit and concentration, treated as first-class
DORA Article 28(8) requires exit strategies for critical services that are documented, tested and reviewed. The TPRM Toolkit gives them a policy, a plan template, a transition plan, a stranded-service contingency plan for the days after a provider fails without notice, a data return and destruction certificate, and a test record. Concentration has its own procedure, register, substitutability analysis and multi-vendor strategy, because the dependency that individual relationship reviews cannot see is the one that hurts.
Two developments make this the moment to have the TPRM Toolkit in place. The UK’s Critical Third Parties regime went live on 13 July 2026 with the first four designations, and the PRA’s updated supervisory statement on outsourcing, published with PS7/26, brings third-party reporting into force on 18 March 2027.
Registers in the TPRM Toolkit that ship populated
8 of the 20 workbooks arrive filled in rather than empty. The crosswalk carries every requirement and every document. The gap assessment tool lists all 90 Interagency Guidance items with the document that closes each. The programme evidence index carries the ten documentation classes examiners ask for and all 86 documents. The inherent risk scoring workbook carries its twelve weighted questions and the tier thresholds. The failure scenario analysis carries ten scenarios. And the three questionnaires carry their questions.
Written against the primary texts, and dated
The TPRM Toolkit was written against the Federal Register text of the Interagency Guidance, NIST’s own CSF 2.0 export, the SP 800-53 Rev 5.2.0 OSCAL catalog, the Official Journal texts of DORA, NIS2 and GDPR, the eCFR text of 45 CFR Part 164, and 23 NYCRR 500 as amended on 1 November 2023. Every document states its sources. Two of them have replacements in flight, and the TPRM Toolkit says so: EBA/GL/2019/02 remains the applicable EBA text while its replacement (EBA/CP/2025/12) is not yet final, and PRA SS2/21’s new version applies from March 2027.
ISO/IEC 27001, the AICPA Trust Services Criteria and PCI DSS are cited by identifier with the intent paraphrased. No licensed text is reproduced; you need your own copy of each standard.
Where the TPRM Toolkit sits beside the rest of the catalogue
The DORA Toolkit remains the DORA-specific ICT third-party pack, with its register of information build. The NIS2 Toolkit, ISO 27001 Toolkit, SOC 2 Toolkit, PCI DSS Toolkit, HIPAA Toolkit and SAMA Toolkit each carry the supplier documents their own regime requires. The TPRM Toolkit is the sector-agnostic programme that sits across all of them: one inventory, one tiering method, one set of questionnaires, one contract checklist, one exit discipline, mapped outward to every regime at once.
Honest about the boundaries
- The TPRM Toolkit does not answer questionnaires on your behalf. The questionnaires are for you to send.
- It is not the DORA register of information template itself; the regulator-format register is compatible with that structure so the two reconcile.
- The clause library is a drafting starting position, not legal advice; counsel reviews it for the governing law of each contract.
- The regulatory clocks are those in the primary texts at the date stated in each document; confirm each against the current text and its national transposition before relying on it.
- Five SP 800-53 controls on component provenance, tamper resistance and inspection are outside the scope of a services programme and are listed as such.
What you get in the TPRM Toolkit
| Section | Documents | What it holds |
|---|---|---|
| 00 Programme Guide | 4 | Implementation guide, crosswalk, gap tool, evidence index |
| 01 Governance and Policy | 9 | Policy, charter, appetite, RACI, committee, board pack, training, independent review, exceptions |
| 02 Inventory and Tiering | 9 | Inventory, tiering, critical functions, data access, fourth parties, concentration, intake |
| 03 Planning and Sourcing | 7 | Pre-engagement assessment, materiality, build-versus-buy, exit-ability, cloud, intra-group |
| 04 Due Diligence | 14 | Tiered procedure, three questionnaires, scoring, viability, privacy, resilience, assurance review, on-site, screening, report, decision |
| 05 Contracting | 12 | Requirements checklist, security schedule, clause library, DPA, BAA, SLA, five clause guides, contract register |
| 06 Ongoing Monitoring | 13 | Monitoring by tier, dashboard, schedule, continuous monitoring, assurance tracker, findings, incidents, change, reviews, fourth parties, access |
| 07 Termination and Exit | 7 | Exit policy, exit plan, termination, data destruction certificate, transition, contingency, testing |
| 08 Resilience and Concentration | 6 | Concentration, substitutability, failure scenarios, continuity integration, testing, multi-vendor |
| 09 Reporting and Regulatory | 5 | Regulator-format register, notification procedure and templates, metrics, annual report |
00 Programme Guide
- TPRM Programme Implementation Guide
- Regulatory Crosswalk Workbook (Excel)
- TPRM Gap Assessment Tool (Excel)
- Programme Evidence Index (Excel)
01 Governance and Policy
- Third-Party Risk Management Policy
- TPRM Framework and Programme Charter
- Third-Party Risk Appetite Statement
- Roles, Responsibilities and RACI Matrix
- Third-Party Risk Committee Terms of Reference
- Board and Senior Management Reporting Pack
- TPRM Training and Awareness Plan
- Independent Review Programme for TPRM
- Policy Exception and Risk Acceptance Procedure
02 Inventory and Tiering
- Third-Party Inventory Register (Excel)
- Inherent Risk Questionnaire and Tiering Methodology
- Inherent Risk Scoring Workbook (Excel)
- Critical or Important Function Mapping Procedure
- Critical or Important Function Register (Excel)
- Data Access and Classification Assessment
- Fourth-Party and Subcontractor Register (Excel)
- Concentration Risk Register (Excel)
- Third-Party Onboarding Workflow and Intake Form
03 Planning and Sourcing
- Pre-Engagement Risk Assessment Procedure
- Sourcing Risk Assessment Template
- Outsourcing and Materiality Assessment Procedure
- Build-versus-Buy and Substitutability Assessment
- Exit-ability Assessment Template
- Cloud and SaaS Engagement Risk Assessment
- Intra-Group and Affiliate Arrangements Procedure
04 Due Diligence
- Due Diligence Procedure
- Vendor Security Questionnaire – Standard (Excel)
- Vendor Security Questionnaire – Enhanced (Excel)
- Vendor Security Questionnaire – Lite (Excel)
- Questionnaire Scoring and Response Evaluation Guide
- Financial Viability Assessment Checklist
- Data Protection and Privacy Due Diligence Checklist
- Business Continuity and Operational Resilience Due Diligence Checklist
- Assurance Report Review Procedure
- Assurance Report Review Template (Excel)
- On-Site and Remote Assessment Checklist
- Sanctions, Adverse Media and Anti-Bribery Screening Checklist
- Due Diligence Report Template
- Third-Party Selection Decision Record
05 Contracting
- Contract Requirements Checklist
- Information Security Schedule for Third-Party Contracts
- Contractual Clause Library
- Data Processing Agreement Template
- Business Associate Agreement Checklist
- Service Level and KPI Schedule Template
- Audit, Access and Information Rights Clause Guide
- Subcontracting and Chain Outsourcing Clause Guide
- Incident and Breach Notification Clause Guide
- Termination, Exit and Transition Assistance Clause Guide
- International Transfer and Offshoring Assessment
- Contract Register (Excel)
06 Ongoing Monitoring
- Ongoing Monitoring Procedure
- Third-Party Performance Dashboard (Excel)
- Periodic Reassessment Schedule (Excel)
- Continuous Monitoring Procedure
- Annual Assurance Renewal Tracker (Excel)
- Issue and Finding Management Register (Excel)
- Remediation Plan Template
- Third-Party Incident Management Procedure
- Third-Party Incident Log (Excel)
- Third-Party Change Management Procedure
- Relationship Review Meeting Template
- Fourth-Party Monitoring Procedure
- Third-Party Access Review Procedure
07 Termination and Exit
- Exit Strategy Policy
- Exit Plan Template for Critical Arrangements
- Termination Procedure and Checklist
- Data Return and Secure Destruction Certificate
- Transition Plan Template
- Stranded-Service Contingency Plan
- Exit Plan Testing Record
08 Resilience and Concentration
- Concentration Risk Assessment Procedure
- Substitutability and Alternative Provider Analysis
- Third-Party Failure Scenario Analysis (Excel)
- Business Continuity Integration Procedure
- Third-Party Resilience Testing Plan
- Multi-Vendor and Backup Provider Strategy
09 Reporting and Regulatory
- Third-Party Arrangements Register – Regulator Submission Format (Excel)
- Regulatory Notification Procedure
- Regulatory Notification Templates
- TPRM Metrics and KRI Definitions
- Annual TPRM Programme Report Template
ISO 20000 Toolkit - Comprehensive ITSM Templates 




































Reviews
There are no reviews yet