Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Third-party risk reporting dashboard with vendor tiers, open findings, overdue assessments and concentration

Third-Party Risk Reporting Guide 2026

Third-party risk reporting is how the results of vendor due diligence, assessments and monitoring reach the people who must act on them. A program can do excellent assessment work and still fail if leaders never see the exposure, vendor owners never hear about the findings, and nobody can say how many critical suppliers have current reviews. Reporting turns data into decisions.

This guide explains how to design third-party risk reporting for different audiences, which metrics matter, how to show concentration and findings, how to keep reports short enough to read, and what mistakes to avoid.

Free gap assessment

Where do you actually stand against ISO 27001?

Score every management system clause and all 93 Annex A controls, free, and get a prioritised gap list back.

Run the free ISO 27001 gap assessment →  or  View premium report sample

Who needs third-party risk reporting

Different audiences ask different questions, so a single report rarely serves them all. Design at least three views.

AudienceMain questionTypical content
Board or risk committeeAre we within appetite, and what needs a decision?Top exposures, concentration, major incidents, program coverage, exceptions
Senior management and risk leadersIs the program working, and where are the gaps?Coverage by tier, overdue reviews, open findings, trends, resource needs
Vendor owners in the businessWhat must I do about my vendors?Their vendors’ status, findings, actions and dates
Regulators and auditorsCan you evidence your process?Inventory, tiering, assessments, monitoring and decisions

Regulators in several sectors expect senior oversight of third-party risk. The framework described in our guide to the third-party risk management framework covers the governance that reporting supports, and the EU Digital Operational Resilience Act requires financial entities to maintain and report on registers of ICT third-party arrangements.

Core metrics for third-party risk reporting

Choose a small set of measures that describe coverage, exposure, findings and performance. Fewer well-defined measures beat a dashboard crowded with numbers.

  • Inventory completeness. Number of vendors, and share with an assigned owner and tier.
  • Coverage. Percent of critical and high-tier vendors with a current assessment and due diligence file.
  • Overdue reviews. Number and age of assessments past their due date, by tier.
  • Open findings. Count by severity and age, and the share past their target date.
  • Concentration. Dependence on single vendors, sub-suppliers, locations or platforms.
  • Incidents. Vendor-related incidents and near misses, with impact and status.
  • Exceptions. Vendors accepted outside policy, with approver and expiry.
  • Contract and exit readiness. Share of critical vendors with required contract terms and tested exit plans.

Make every metric actionable

For each measure, define the source, the owner, the target and the threshold at which action is required. A number without a threshold cannot tell you whether to worry. Our guide to KRI thresholds shows how to set them, and KRI reporting explains how to present them.

Tiering views in third-party risk reporting

Report by tier, because the risk sits mostly in a small share of vendors. A view showing performance for critical vendors separately from the long tail keeps attention on what matters. Our guide to vendor risk tiering explains how to classify. For each tier show the number of vendors, the share assessed on time, the number of open high findings and any changes since the last report.

Showing findings and their progress

Findings are the most actionable content. Present them by severity, owner and age, and show which are overdue. Distinguish findings about the vendor from findings about your own controls, since the fix belongs to different teams. Include the trend, for example the number opened and closed in the period, because a rising backlog is a warning even when the total looks small. Our article on third-party risk assessment findings explains how to record and track them.

Free third-party risk assessment

How much risk does this vendor bring?

Tier the vendor, check the evidence, rate the risks from 30 third-party scenarios and choose controls referenced to ISO 27001, NIST CSF 2.0 and DORA. You get a tier, a heat map and the findings an auditor would raise, free.

Start the free vendor risk assessment →  or  View premium report sample

Concentration and dependency views

Individual assessments miss concentration. Show how many critical activities depend on each of the largest vendors, which vendors share an underlying provider, and which geographic or platform dependencies are present. A simple table of the top ten vendors by dependency, with substitutability and exit time, tells leaders where a single failure could hurt most. See vendor concentration risk for how to measure it.

Cadence, format and length

Consistency matters more than sophistication, since readers learn where to look for what changed.

Set a regular rhythm: monthly operational reports for the program team and vendor owners, quarterly summaries for the risk committee and an annual review for the board. Keep board packs to a page or two, with a short narrative that says what changed, what it means and what decision is needed. Use color sparingly and consistently, and define what red, amber and green mean. Attach detail behind a link for those who want it. Where continuous monitoring produces alerts, summarize them by theme instead of listing each one, as described in our guide to third-party continuous monitoring.

Data quality behind third-party risk reporting

Reports are only as reliable as the inventory and records behind them. Reconcile the vendor list with accounts payable, contracts and access records, and investigate differences. Assign owners for data fields, and check a sample of entries each quarter. Say plainly in the report where data is incomplete, rather than presenting a tidy picture that hides gaps. Keep the same fields and definitions from one period to the next so that trends are meaningful. Standard question sets, such as those published by Shared Assessments, can improve consistency in what you collect from vendors.

Reports for vendor owners in the business

The people closest to each vendor are often the least informed about its risk position. Give each vendor owner a short monthly or quarterly summary for their suppliers: the tier, the date of the last assessment, the next review date, open findings with target dates, contract renewal dates and any alerts received. Ask them to confirm that the vendor is still used for the same purpose and that nothing has changed in the data shared. A simple response form keeps this light, and the answers update your inventory at the same time.

Escalate when owners do not respond. A rule such as two missed confirmations triggers a note to their manager makes ownership real, and the numbers on non-response themselves belong in the management report. Where a vendor owner leaves the company, reassign the vendors before the departure date so that no supplier is left without a named person.

Reporting incidents and near misses

Incidents involving suppliers need their own route, because timing matters. Define what counts as a reportable vendor incident, who must be told and within what time, and how the incident is followed through to closure with lessons learned. Regulators in some sectors set deadlines for reporting significant incidents affecting outsourced services, so check the expectations that apply to you. In periodic reports, summarize incidents by cause, vendor tier and impact, and show whether the same vendor or the same cause recurs. A pattern across several vendors, such as a shared software component, may indicate a systemic weakness that individual reports would miss.

Include near misses and complaints where they reveal a weakness in controls or service. Reports that mention only serious incidents give leaders a view that is too comfortable.

A short worked example

A company’s quarterly report for its risk committee shows 420 vendors, of which 38 are critical or high tier. Coverage of critical vendors with a current assessment is 92 percent against a target of 100, and three assessments are more than 30 days overdue. There are 17 open high findings, of which five are past their date, all belonging to two vendors. The concentration view shows that eleven critical activities rely on one cloud platform. The report asks the committee to approve a plan for a second provider for two activities and to escalate the overdue findings to the vendor executives. The committee makes both decisions and the minutes record them.

Common mistakes in third-party risk reporting

Programs report activity instead of risk, such as the number of questionnaires sent, present metrics without targets, use one report for every audience, omit concentration, hide data gaps and fail to record decisions taken. Another mistake is producing dashboards that no one reads. Ask each recipient what they did with the last report. If the answer is nothing, redesign it around a decision.

Using a ready structure

To avoid building the records and views from scratch, the Third-Party Risk Assessment Report and Workbook provides a structured report, scoring and register that supply the data for summary views. Whichever tool you use, design third-party risk reporting around decisions and keep it consistent from one period to the next.

Third-party risk reporting FAQ

What should third-party risk reporting include?

Inventory and coverage, overdue reviews, open findings by severity and age, concentration, incidents, exceptions and contract or exit readiness, with targets and thresholds.

How often should it be produced?

Monthly for the program team and vendor owners, quarterly for the risk committee and at least annually for the board, with ad hoc reports for major incidents.

Who should receive it?

The board or risk committee, senior management, vendor owners and, where required, regulators and auditors, each with a view suited to their questions.

How long should a board report be?

One to two pages of headline metrics, exceptions and decisions needed, with supporting detail available separately.

How do I know the data is reliable?

Reconcile the vendor inventory with finance and contract records, assign data owners, sample-check entries and state clearly where data is incomplete.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.