Introduction

Third-Party Risk Management (TPRM) training course equips organisations with practical approaches to strengthen vendor oversight, manage third-party risks, and build resilient supply chain relationships across the extended enterprise.

Organisations increasingly depend on external providers, outsourcing partners, contractors, technology vendors, and strategic suppliers to support essential operations and business growth. While these relationships generate significant value, they can also expose organisations to operational disruption, cyber incidents, regulatory challenges, financial instability, and reputational harm if not managed effectively.

This training course provides a comprehensive framework for establishing and enhancing third-party risk management programmes aligned with recognised international standards and governance principles. Participants will gain practical skills in due diligence, supplier governance, cyber risk oversight, resilience planning, continuous monitoring, and executive reporting to improve organisational control, accountability, and strategic decision-making.

Key focus areas of this Third-Party Risk Management (TPRM): Governance, Due Diligence and Supply Chain Resilience training course include:

Key Learning Outcomes

At the end of this Third-Party Risk Management (TPRM): Governance, Due Diligence and Supply Chain Resilience training course, participants will be able to:

Training Methodology

This training course combines expert-led instruction, interactive learning, group discussions, practical exercises, applied scenarios, and real-world examples. Participants will develop vendor risk frameworks, due diligence methodologies, supplier risk models, monitoring scorecards, and executive dashboards that can be directly adapted to their organisational environments.

Third-Party Risk Management (TPRM)

Who Should Attend?

This Third-Party Risk Management (TPRM): Governance, Due Diligence and Supply Chain Resilience training course is designed for:

  • Risk Managers
  • Compliance Managers
  • Governance Managers
  • Vendor Managers
  • Supplier Relationship Managers
  • Procurement Managers
  • Category Managers
  • Strategic Sourcing Managers
  • Internal Auditors
  • Assurance Managers
  • Information Security Managers
  • Cyber Risk Specialists
  • Business Continuity Managers
  • Operational Resilience Managers
  • Legal Counsel
  • Contract Managers
  • ESG Managers
  • Sustainability Managers
  • Board Members
  • Executive Directors

Course Outline

Day 1

Establishing Third-Party Governance & the TPRM Framework

  • The evolving third-party risk landscape — outsourcing, cloud, SaaS and the extended enterprise
  • Integrating TPRM within Enterprise Risk Management (ERM) and the three lines of defence
  • Defining governance structures, accountability and clear ownership across functions
  • Setting risk appetite and tolerance for third-party and supplier relationships
  • Board and executive responsibilities for oversight of the extended enterprise
  • Mapping the regulatory landscape — DORA, interagency guidance and sector expectations
Day 2

Risk-Based Due Diligence, Onboarding & Supplier Governance

  • Vendor onboarding, qualification and pre-contract screening processes
  • Designing proportionate, risk-based due diligence frameworks and methodologies
  • Supplier tiering and classification models — focusing effort where risk is greatest
  • Operational risk assessment methodologies across the vendor lifecycle
  • Financial, credit and viability risk evaluation of suppliers
  • Embedding risk requirements into contracts, SLAs and right-to-audit clauses
Day 3

Cyber, Technology & Digital Supply Chain Resilience

  • Third-party cyber risk management frameworks (ISO/IEC 27036, NIST SP 800-161)
  • Cybersecurity due diligence and assessment methodologies, including standardised questionnaires
  • Cloud and SaaS provider risk assessment and shared-responsibility models
  • Managing digital / ICT concentration risk and fourth-party (subcontractor) exposure
  • Artificial Intelligence vendor risk — transparency, data governance and model assurance
  • Coordinated incident response, breach notification and joint resilience testing
Day 4

Supply Chain Resilience, ESG & Geopolitical Risk

  • Supply chain risk mapping and single-point-of-failure / dependency analysis
  • Building resilient, diversified sourcing and contingency strategies
  • ESG risk assessment frameworks for the supplier base
  • Human rights, modern slavery and responsible-sourcing due diligence
  • Geopolitical, sanctions and country-risk assessment methodologies
  • Scenario planning and stress testing for supply chain disruption
Day 5

Continuous Monitoring, Assurance, Reporting & Future-Proofing

  • Designing continuous monitoring frameworks and key risk indicators (KRIs)
  • Vendor performance management and SLA / obligation tracking systems
  • Third-party audit programmes and independent assurance approaches
  • Executive and board dashboards — translating third-party risk into decisions
  • Managing vendor exit, offboarding and contingency / step-in arrangements
  • Building a strategic roadmap for continuous TPRM maturity improvement

Ready to Take the Next Step?

Reserve your slot today and start your learning journey with us.

Got a Question?

Reach out to us anytime — we're here to help and guide you.

Related Courses

FAQs

Organisations rely on a diverse ecosystem of suppliers, outsourcing providers, cloud platforms, technology vendors, and strategic partners to support critical operations. While these relationships create efficiencies and enable growth, they also introduce operational, cyber, regulatory, financial, and reputational risks. Effective third-party risk management helps organisations strengthen oversight, reduce vulnerabilities, and maintain operational resilience.

Participants will develop practical knowledge in governance design, supplier risk assessment, due diligence methodologies, cyber risk oversight, ESG risk evaluation, supplier resilience, continuous monitoring, and executive reporting. The course focuses on building a structured approach that supports effective vendor risk management throughout the entire third-party lifecycle.

Risk-based due diligence enables organisations to allocate resources efficiently by focusing greater attention on suppliers and vendors that present higher exposure. By implementing supplier tiering, classification models, and proportionate assessment processes, organisations can improve decision-making, reduce uncertainty, and strengthen third-party governance.

A key component of the course focuses on cyber and technology-related risks, including cloud services, SaaS providers, digital supply chains, fourth-party dependencies, and artificial intelligence vendors. Participants learn how recognised frameworks and assessment methodologies can be applied to improve cyber resilience and supply chain security.

The course examines practical approaches to supply chain mapping, dependency analysis, supplier diversification, ESG risk assessment, responsible sourcing, and geopolitical risk management. Participants learn how these practices strengthen resilience while supporting sustainability, ethical business conduct, and long-term organisational performance.

This course is highly beneficial for professionals responsible for risk management, procurement, sourcing, compliance, governance, information security, business continuity, internal audit, supplier management, and operational resilience. It is also valuable for executives and board members seeking greater oversight of third-party risk across the extended enterprise.

GRC Academy training courses are delivered in leading international business destinations, including London, Amsterdam, and Dubai. Sessions are hosted in carefully selected four- and five-star business hotels with professional meeting facilities that support focused learning, interaction, comfort, and confidentiality.

View All Training Locations

GRC Academy provides both online and in-person options for all our training courses. Participants may join interactive virtual sessions or attend scheduled courses in major international locations, allowing them to select the option that best suits their professional commitments and availability.

GRC Academy develops customised in-house training courses that address each organisation’s strategic priorities, operational environment, and workforce capability requirements. Our team works closely with clients to tailor the course content, learning outcomes, and practical emphasis.

These tailored courses are designed to strengthen organisational capability, improve team performance, and support measurable and sustainable outcomes. For customised in-house training enquiries, please contact the GRC Academy Customer Service team at [email protected]

Click here to know more details about our customized or in-house training solutions

Related Categories

Find Your Perfect Course in Related Categories

Find the Right Professional Training Course

Use our course finder to explore training by capability area, role focus, location, or delivery format.