Govern & Assure
Third-Party Risk
Third-party risk management support covering programme design, supplier due diligence, and individual supplier assessments, delivered as focused consultancy or combined with Clarity for ongoing management.
- A TPRM framework that fits the organisation
- Risk-based supplier due diligence
- Independent supplier assessments
- Clear findings and decisions
- Proportionate assurance
Most organisations depend on suppliers, SaaS providers, MSPs, and other third parties to support critical systems, services, and data. The problem is that organisations often assess supplier risk once at onboarding, record it in a spreadsheet, and then let it drift as services, access, and business dependencies change.
Engagements vary in scope. We design or improve TPRM frameworks, carry out due diligence on new suppliers, independently assess higher-risk third parties, and help build a more consistent way to prioritise and manage supplier risk across the organisation.
Not every supplier needs the same questionnaire. We help you focus effort where it matters most, based on factors such as the service being provided, access to systems or data, business criticality, and the impact of failure. You can then use findings to support onboarding decisions, remediation, risk acceptance, or further assurance.
Where the requirement is ongoing, our Clarity Managed platform supports the same approach, giving you a central supplier register, tiering, assessments, evidence, actions, reassessment cycles, and reporting. You can use our consultancy on its own, use the platform with your own team, or combine the two.
Get a quote for Third-Party Risk
Tell us your scope and objectives, and we’ll come back with a clear, fixed proposal, usually the same working day.
Get a Quoteor call +44 (0) 203 393 7795- CREST-accredited
- UK-based specialists
- Crown Commercial Service supplier
How it works
- 01
Understand the requirement
We start with what you need to achieve, whether that is a TPRM programme, support with supplier onboarding, an assessment of a particular third party, or a wider ongoing service.
- 02
Establish risk and tiering
We look at your supplier population, business dependencies, and risk criteria so the level of assurance can be matched to the importance of each supplier.
- 03
Carry out due diligence and assessment
Depending on your needs, we review questionnaires, supporting evidence, existing assurance, and other relevant information to establish the supplier's security position.
- 04
Review findings and risk
We identify material weaknesses, assess what they mean for your organisation and distinguish issues requiring action from those that can reasonably be accepted.
- 05
Agree the next step
That could mean onboarding the supplier, requesting remediation, seeking additional evidence, carrying out a deeper assessment, or escalating the risk for a business decision.
- 06
Maintain oversight where needed
For ongoing programmes, suppliers can be reassessed as risk, services, or dependencies change, with activity and reporting managed through our Clarity Managed Platform if required.
What you get
A TPRM framework that fits the organisation
We help define supplier risk criteria, tiering, responsibilities, assessment routes, escalation, and review, rather than one process for every supplier.
Risk-based supplier due diligence
We help you gather and assess the security information needed to support supplier selection and onboarding decisions.
Independent supplier assessments
Where a third party needs closer scrutiny, we assess its controls, evidence, and responses and set out the risks that matter.
Clear findings and decisions
Assessment output is translated into risks, recommendations, and next steps so you can decide whether to remediate, accept, escalate, or seek further assurance.
Proportionate assurance
Lower-risk suppliers get a lighter-touch review; more important or higher-risk suppliers get deeper assessment and evidence review.
A route to ongoing management
Where supplier risk needs to be managed continuously, Clarity can provide the workflow, ownership, reassessment, and reporting layer around the programme.
Frequently asked questions
Straight answers to what prospective clients ask us most.
We do not have a formal TPRM programme. Where do we start?
Start with the supplier landscape and the decisions you need the programme to support. We help define the framework, risk criteria, supplier tiers, ownership, and assessment approach before you start issuing questionnaires.
Do all suppliers need a full security assessment?
No. Treating every supplier the same usually creates work without improving the decisions you make. We help you tier suppliers so more effort is applied where access, business dependency, or potential impact justify it.
Can you assess a single supplier for us?
Yes. TPRM does not have to begin as a large programme. We can carry out due diligence or a more detailed assessment of an individual supplier to support procurement, onboarding, renewal, or an existing risk concern.
What happens if a supplier has security gaps?
We help you understand which findings matter and what should happen next: requesting remediation, obtaining further evidence, applying contractual or operational controls, accepting the risk, or reconsidering the relationship. The final supplier and risk decision remains with you.
Can this be managed through Clarity?
Yes. Consultancy and assessments can be delivered as standalone engagements, but Clarity gives you a more structured way to manage the supplier population over time: a central supplier register, tiering, questionnaires, evidence, actions, reassessment, and management reporting, combined with Blackfoot support if you want it.
What if we already have a TPRM process but it is not working well?
You do not need to replace everything. We review the existing framework, identify where the process is creating unnecessary effort or weak assurance, and help improve the parts that are not working.
Ready to talk about third-party risk?
Get a fixed-scope quote, usually the same working day.