TPR-240Third-Party & Supply Chain Risk

Continuous Vendor Monitoring: Breach Intelligence, Attestation Expiry and Recertification

Vendor risk changes between annual reviews. Monitor vendors continuously, catch expiring reports and DPAs, and offboard cleanly.

6 lessons About 3.5 hours 3 ALCs Certificate on completion

What you'll be able to do

  • Decide what events trigger a vendor reassessment
  • Track expiring SOC reports and contracts before they lapse
  • Use breach intelligence to spot vendor incidents early
  • Offboard vendors so data and access really end
You finish with

A vendor monitoring standard

What's in it. What triggers a reassessment, expiry ladders for SOC reports and DPAs, and an offboarding checklist.

You build it lesson by lesson, using your own organization, and submit it for your certificate. It's yours to keep and adapt.

Who it's for

Third-party risk teams and vendor managers.

What's inside

  1. Part 1Where the requirement comes from 20 min
  2. Part 2How small teams and enterprises meet it 18 min
  3. Part 3The method, step by step 22 min
  4. Part 4Hands-on lab: small team choose one 90 min
  5. Part 5Hands-on lab: enterprise choose one 120 min
  6. Part 6Finish and submit your deliverable 20 min

Built for your size

The requirement is the same everywhere. How you meet it depends on who you have. You pick the lab that matches your organization.

Small team or early-stageAlerts to one inbox, act on the critical ones.
EnterpriseEscalation chain, KRIs and risk register integration.

How you earn the certificate

Submit your finished deliverable, which is scored against a published rubric, and pass a short scenario quiz. Your certificate goes to your wallet and can be checked by anyone on the public register.

Ready to build a vendor monitoring standard?6 lessons, about 3.5 hours. Start whenever you're ready.
Join and enroll