TPR-201Third-Party & Supply Chain Risk

Building a Third-Party Risk Program: From Zero and At Scale

You can't review every vendor the same way. Build a third-party risk program, from scratch or at scale, with tiering that puts effort where the risk is.

6 lessons About 3 hours 4 ALCs Certificate on completion

What you'll be able to do

  • Tier vendors by the risk they really bring
  • Set assessment depth for each tier
  • Design an annual cycle your team can sustain
  • Run the program with a small team or at enterprise scale
You finish with

A third-party risk operating model

What's in it. Tiering criteria, inherent risk questionnaire, assessment depth by tier, and an annual cycle.

You build it lesson by lesson, using your own organization, and submit it for your certificate. It's yours to keep and adapt.

Who it's for

Third-party risk managers, procurement and security teams building or rebuilding a vendor program.

What's inside

  1. Part 1Where the requirement comes from 16 min
  2. Part 2How small teams and enterprises meet it 14 min
  3. Part 3The method, step by step 20 min
  4. Part 4Hands-on lab: small team choose one 90 min
  5. Part 5Hands-on lab: enterprise choose one 120 min
  6. Part 6Finish and submit your deliverable 20 min

Built for your size

The requirement is the same everywhere. How you meet it depends on who you have. You pick the lab that matches your organization.

Small team or early-stageTwenty vendors, one owner, a spreadsheet that becomes a system.
EnterpriseThousands of vendors, procurement integration, second-line oversight.

How you earn the certificate

Submit your finished deliverable, which is scored against a published rubric, and pass a short scenario quiz. Your certificate goes to your wallet and can be checked by anyone on the public register.

Ready to build a third-party risk operating model?6 lessons, about 3 hours. Start whenever you're ready.
Join and enroll