Third-Party Risk Management Standard Operating Procedure
THIRD-PARTY RISK MANAGEMENT STANDARD OPERATING PROCEDURE
Organization: [________________________________]
SOP Number: TPRM-[____]
Version: [____]
Effective Date: [__/__/____]
Approved By: [________________________________]
Document Owner: [________________________________]
TABLE OF CONTENTS
- Purpose and Scope
- Regulatory Framework and Authority
- Definitions
- Risk Tiering Methodology
- Third-Party Lifecycle Management
- Roles, Responsibilities, and RACI Matrix
- Documentation and Systems of Record
- Metrics, Key Risk Indicators, and Reporting
- Exceptions and Compensating Controls
- Review Cadence and Version Control
- Annexes
1. PURPOSE AND SCOPE
1.1 Purpose
This Standard Operating Procedure ("SOP") establishes the framework for identifying, assessing, managing, monitoring, and offboarding third-party relationships throughout their lifecycle. It draws on OCC Bulletin 2023-17, FFIEC handbook guidance, and the DOJ's Evaluation of Corporate Compliance Programs. OCC Bulletin 2023-17 is risk-based supervisory guidance for banking organizations supervised by the Board, FDIC, or OCC; it does not have the force and effect of law or impose new requirements. An organization outside that audience may use its lifecycle principles as a voluntary framework, subject to the laws and regulatory guidance actually applicable to that organization. The SOP also supports an organization's fact-specific compliance-program analysis under Federal Sentencing Guidelines § 8B2.1.
1.2 Scope
This SOP applies to all third-party relationships where the third party:
☐ Accesses, processes, stores, or transmits company data
☐ Has connectivity to company information systems
☐ Interacts directly with the organization's customers or end users
☐ Performs critical business functions or provides essential operational support
☐ Is a subcontractor of a direct vendor performing any of the above
This includes vendors, service providers, consultants, outsourcing partners, joint ventures, affiliates performing services, and other relationships the organization places within this policy. For a supervised banking organization, OCC Bulletin 2023-17 uses "business arrangement" broadly and treats it as synonymous with "third-party relationship."
1.3 Exclusions
The following relationships may be excluded from full lifecycle procedures, though they must still be inventoried:
☐ Utility providers (electricity, water, basic telecommunications)
☐ One-time purchases of goods with no data access or system connectivity
☐ Government regulators and auditors
2. REGULATORY FRAMEWORK AND AUTHORITY
This SOP is informed by the following potentially applicable authorities and voluntary frameworks. Applicability must be determined for the organization and relationship; an item below is not automatically a legal requirement merely because it is listed here:
| Authority | Key Requirements |
|---|---|
| OCC Bulletin 2023-17 | Risk-based supervisory principles for supervised banking organizations across planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination; not law and not a source of new requirements |
| OCC Bulletin 2013-29 | Rescinded and replaced by the 2023 interagency guidance; historical reference only |
| FFIEC IT Handbook | Technology risk assessments, vendor management for outsourced IT |
| CFPB Bulletin 2012-03 | Oversight of service providers handling consumer financial products |
| DOJ Compliance Evaluation | Third-party management as element of effective compliance |
| Federal Sentencing Guidelines § 8B2.1 | Due diligence to prevent and detect criminal conduct |
| NIST SP 800-161 Rev. 1 | Cyber supply chain risk management practices |
| ISO/IEC 27001:2022 A.5.19-5.22 | Information security in supplier relationships |
3. DEFINITIONS
| Term | Definition |
|---|---|
| Third Party | Any entity that has entered into a business relationship with the organization, including vendors, service providers, consultants, and subcontractors |
| Critical Third Party | A third party that supports critical business functions, has access to significant volumes of sensitive data, or whose failure would materially impact operations |
| Risk Tier | Classification (Critical, High, Medium, Low) based on assessed risk factors |
| Due Diligence | Assessment of a third party's ability to perform contracted activities and manage associated risks |
| Subprocessor/Fourth Party | An entity engaged by a third party to perform part of the contracted services |
| Business Owner | The individual responsible for the third-party relationship and accountable for its performance |
| KRI | Key Risk Indicator — a metric that provides an early warning of increasing risk exposure |
| TPRM Platform | The system of record for third-party risk management documentation and workflows |
4. RISK TIERING METHODOLOGY
4.1 Tiering Criteria
Each third party shall be assigned a risk tier based on the following factors:
| Factor | Critical | High | Medium | Low |
|---|---|---|---|---|
| Data Sensitivity | PHI, PCI, high-volume PII, trade secrets | PII, confidential business data | Internal data, limited PII | Public data, no data access |
| System Access | Privileged access, critical systems, direct network | Direct system access, read/write | Limited application access, read-only | No system access |
| Operational Criticality | Business cannot operate; no alternative | Significant impact; limited alternatives | Moderate impact; workarounds exist | Minimal impact; easily replaceable |
| Regulatory Impact | Directly regulated activity; regulatory reporting | Significant compliance obligations | Some compliance requirements | Minimal regulatory implications |
| Financial Exposure | >$[____] annually | $[____]–$[____] | $[____]–$[____] | <$[____] |
| Customer Impact | Direct customer-facing | Indirect customer impact | No customer impact | No customer impact |
| Geographic Risk | High-risk jurisdictions; cross-border data | Moderate-risk jurisdictions | Domestic, standard jurisdictions | Low-risk locations |
4.2 Scoring and Assignment
Risk tier is determined by the highest-rated factor unless overridden by documented professional judgment. Override decisions require approval from [________________________________] and must be documented with rationale.
4.3 Tier-Based Requirements
| Activity | Critical | High | Medium | Low |
|---|---|---|---|---|
| Due Diligence Depth | Full questionnaire + on-site + evidence | Full questionnaire + evidence | Standard questionnaire | Abbreviated assessment |
| Approval Authority | [Board/ExCo] | [SVP/CISO/CCO] | [VP/Director] | [Manager] |
| Contract Review | Legal + Compliance + Security + Privacy | Legal + Compliance + Security | Legal + Security | Standard terms |
| Monitoring Frequency | Continuous + Annual reassessment | Semi-Annual | Annual | Biennial or event-driven |
| Reassessment Cycle | 12 months | 18 months | 24 months | 36 months |
5. THIRD-PARTY LIFECYCLE MANAGEMENT
5.1 Phase 1: Planning and Intake
Objective: Identify the business need, assess alternatives, and initiate the TPRM process.
| Step | Activity | Responsible | Deliverable |
|---|---|---|---|
| 5.1.1 | Business Owner completes Third-Party Intake Form | Business Owner | Completed intake form |
| 5.1.2 | Describe use case, data types, system integrations, geographies, and alternatives considered | Business Owner | Intake form details |
| 5.1.3 | Preliminary risk scoring and tier assignment | TPRM Team | Risk score and tier |
| 5.1.4 | Compliance/Security review of tier assignment | Compliance / Security | Tier confirmation or adjustment |
| 5.1.5 | Identify approval authority based on tier | TPRM Team | Approval routing |
☐ Intake form submitted to TPRM Platform
☐ Preliminary tier assigned
☐ Approval authority identified
5.2 Phase 2: Due Diligence and Risk Assessment
Objective: Assess the third party's ability to deliver services while managing risk.
| Step | Activity | Responsible | Deliverable |
|---|---|---|---|
| 5.2.1 | Issue tier-appropriate questionnaire | TPRM Team | Completed questionnaire |
| 5.2.2 | Collect evidence and artifacts per tier requirements | TPRM Team | Evidence package |
| 5.2.3 | Sanctions/PEP/adverse media screening | Compliance | Screening report |
| 5.2.4 | Export controls/licensing review (if applicable) | Compliance / Legal | Export assessment |
| 5.2.5 | Security controls assessment | Security | Security assessment report |
| 5.2.6 | Privacy assessment (DSR handling, data flows, transfers) | Privacy | Privacy assessment |
| 5.2.7 | Financial viability review (Critical/High tier) | Finance | Financial assessment |
| 5.2.8 | BC/DR capability assessment | Security / Business Owner | Resilience assessment |
| 5.2.9 | Consolidated risk assessment and recommendation | TPRM Team | Risk assessment report |
| 5.2.10 | Present findings and recommendation to approval authority | TPRM Team | Approval or rejection |
☐ Questionnaire completed and reviewed
☐ Evidence collected and validated
☐ Screenings clear (or findings documented)
☐ Risk assessment report completed
☐ Approval decision documented
5.3 Phase 3: Contract Negotiation and Execution
Objective: Ensure contractual terms appropriately allocate risk and address regulatory requirements.
Internal baseline contract terms by risk tier are listed below. These are organization policy choices to tailor to relationship risk and applicable law; OCC Bulletin 2023-17 does not prescribe every listed term for every relationship:
| Clause | Critical | High | Medium | Low |
|---|---|---|---|---|
| Data Processing Agreement (DPA) | ☐ Required | ☐ Required | ☐ If data processed | ☐ If data processed |
| Security Addendum | ☐ Required | ☐ Required | ☐ Required | ☐ Standard terms |
| SLA / Uptime Commitments | ☐ Required | ☐ Required | ☐ Recommended | ☐ Optional |
| Breach Notification Timeline | ☐ Required (≤24 hrs) | ☐ Required (≤48 hrs) | ☐ Required (≤72 hrs) | ☐ Reasonable |
| Audit / Pen Test Rights | ☐ Required | ☐ Required | ☐ Required | ☐ Optional |
| Subcontractor Approval Rights | ☐ Required | ☐ Required | ☐ Notification | ☐ N/A |
| Data Return / Deletion on Termination | ☐ Required | ☐ Required | ☐ Required | ☐ Required |
| Insurance Minimums | ☐ Required | ☐ Required | ☐ Recommended | ☐ Optional |
| Indemnification | ☐ Required | ☐ Required | ☐ Required | ☐ Standard |
| Regulatory Compliance Representations | ☐ Required | ☐ Required | ☐ Recommended | ☐ Optional |
| Standard Contractual Clauses (int'l transfers) | ☐ If applicable | ☐ If applicable | ☐ If applicable | ☐ If applicable |
☐ Contract reviewed by Legal
☐ Contract reviewed by Compliance/Security/Privacy (per tier)
☐ Deviations from required terms documented with compensating controls
☐ Contract executed and filed in contract repository
5.4 Phase 4: Onboarding
| Step | Activity | Responsible |
|---|---|---|
| 5.4.1 | Validate controls are implemented before go-live | Security |
| 5.4.2 | Provision system access with least-privilege | IT / Security |
| 5.4.3 | Enable logging and monitoring | Security |
| 5.4.4 | Assign relationship owner and document in TPRM platform | TPRM Team |
| 5.4.5 | Set monitoring schedule and next reassessment date | TPRM Team |
☐ Controls validated
☐ Access provisioned
☐ Monitoring enabled
☐ TPRM system updated
5.5 Phase 5: Ongoing Monitoring
| Monitoring Activity | Frequency by Tier (C/H/M/L) | Responsible |
|---|---|---|
| SLA performance tracking | Monthly / Quarterly / Semi-Annual / Annual | Business Owner |
| Security incident monitoring | Continuous | Security |
| Subprocessor change notices | As received | Compliance / Security |
| Financial health monitoring (Critical) | Quarterly | Finance |
| Regulatory and sanctions rescreening | Annual / Annual / Biennial / Biennial | Compliance |
| Complaint and escalation tracking | Ongoing | Business Owner |
| News/adverse media monitoring | Continuous (Critical/High) / Event-driven | Compliance |
☐ Monitoring schedule documented
☐ Incidents tracked and escalated per SOP
☐ Material changes evaluated and acted upon
5.6 Phase 6: Periodic Reassessment
| Tier | Reassessment Cycle | Trigger Events |
|---|---|---|
| Critical | 12 months | Incident, scope change, data/geo expansion, M&A, regulatory change |
| High | 18 months | Same as above |
| Medium | 24 months | Same as above |
| Low | 36 months | Same as above |
☐ Reassessment questionnaire issued
☐ Updated evidence collected
☐ Risk tier re-evaluated
☐ Findings documented and remediation tracked
5.7 Phase 7: Offboarding and Termination
| Step | Activity | Responsible |
|---|---|---|
| 5.7.1 | Confirm data return or deletion; obtain written certification | Business Owner / Privacy |
| 5.7.2 | Revoke all system access and credentials | IT / Security |
| 5.7.3 | Migrate services to replacement vendor (if applicable) | Business Owner |
| 5.7.4 | Collect final deliverables and resolve open items | Business Owner |
| 5.7.5 | Close out records in TPRM platform | TPRM Team |
| 5.7.6 | Retain records per document retention policy | Compliance |
☐ Data returned or deletion certified
☐ Access revoked
☐ TPRM system updated to "Terminated"
☐ Records retained per policy
6. ROLES, RESPONSIBILITIES, AND RACI MATRIX
6.1 Key Roles
| Role | Responsibilities |
|---|---|
| Business Owner | Initiates intake, funds vendor, owns day-to-day relationship, escalates issues |
| TPRM Team | Administers program, facilitates assessments, maintains platform, tracks metrics |
| Compliance | Policy oversight, sanctions/export review, regulatory clause review, exception approval |
| Security | Technical security assessment, penetration test reviews, monitoring requirements |
| Privacy | Data mapping, DPA/SCC review, DSR process assessment, transfer risk |
| Legal | Contract review, clause negotiation, regulatory interpretation |
| Procurement | Commercial terms, RFP management, payment controls |
| Finance | Financial viability assessment, payment controls |
| Internal Audit | Independent program testing and assessment (if applicable) |
| Board/Committee | Ultimate oversight, approve program charter, review critical relationships |
6.2 RACI Matrix
| Activity | Business Owner | TPRM Team | Compliance | Security | Privacy | Legal | Procurement |
|---|---|---|---|---|---|---|---|
| Intake | R/A | C | I | I | I | I | I |
| Tier Assignment | I | R | A | C | C | I | I |
| Due Diligence | C | R | C | C | C | I | I |
| Contract Review | I | C | C | C | C | R/A | C |
| Onboarding | R | C | I | R | I | I | I |
| Ongoing Monitoring | R | C | C | R | C | I | I |
| Reassessment | C | R | C | C | C | I | I |
| Offboarding | R | C | I | R | C | I | I |
R = Responsible, A = Accountable, C = Consulted, I = Informed
7. DOCUMENTATION AND SYSTEMS OF RECORD
7.1 TPRM Platform
All TPRM activities shall be documented in the designated platform: [________________________________]
The platform shall maintain:
☐ Third-party inventory (active and terminated)
☐ Intake forms and tier assignments
☐ Questionnaires and evidence packages
☐ Screening results
☐ Risk assessment reports
☐ Approval records
☐ Contract references (linked to contract repository)
☐ Monitoring notes and incident records
☐ Reassessment history
☐ Exception requests and approvals
☐ Offboarding checklists and certifications
7.2 Record Retention
TPRM records shall be retained for a minimum of [____] years after termination of the relationship, or longer if required by applicable law or regulation.
8. METRICS, KEY RISK INDICATORS, AND REPORTING
8.1 Program Metrics
| Metric | Target | Frequency |
|---|---|---|
| Time-to-approve (by tier) | Critical: [____] days; High: [____] days | Monthly |
| Due diligence completion rate | [____]% | Monthly |
| Reassessment completion (on schedule) | [____]% | Quarterly |
| Open exception count and aging | <[____] open; <[____] days avg age | Quarterly |
| Incident notification timeliness | [____]% within SLA | Quarterly |
| SLA breaches by critical vendors | <[____] per quarter | Quarterly |
| Critical vendor concentration risk | Documented for all | Quarterly |
| Training completion rate | [____]% | Annual |
8.2 Reporting
| Audience | Report Content | Cadence |
|---|---|---|
| [Board/Committee] | Program overview, critical vendor risks, incident summary, exception status, regulatory changes | Quarterly |
| Senior Management | Detailed metrics, reassessment status, remediation tracking | Monthly |
| Business Owners | Vendor-specific status, upcoming reassessments, open actions | As needed |
9. EXCEPTIONS AND COMPENSATING CONTROLS
9.1 Exception Process
| Step | Activity |
|---|---|
| 9.1.1 | Business Owner submits exception request with risk justification |
| 9.1.2 | TPRM Team reviews and documents compensating controls |
| 9.1.3 | Exception approved by [Compliance Lead / CISO / CCO] based on risk tier |
| 9.1.4 | Exception recorded with: risk owner, approver, expiration date, compensating controls |
| 9.1.5 | Exception reviewed at expiration; renewed or remediated |
9.2 Approval Authority for Exceptions
| Tier | Approver |
|---|---|
| Critical | [Board/ExCo Member] |
| High | [SVP / CCO / CISO] |
| Medium | [VP / Director] |
| Low | [Manager / TPRM Lead] |
10. REVIEW CADENCE AND VERSION CONTROL
| Field | Information |
|---|---|
| SOP Owner | [________________________________] |
| Review Frequency | Annual, or upon material change (regulation, major incident, program redesign) |
| Next Review Date | [__/__/____] |
| Approval Authority | [________________________________] |
Version History:
| Version | Date | Author | Changes |
|---|---|---|---|
| [____] | [__/__/____] | [________________] | [________________________________] |
11. ANNEXES
Annex A: Third-Party Intake Form Fields
☐ Vendor legal name and contact information
☐ Business use case and justification
☐ Data types and volumes
☐ System integrations and access requirements
☐ Geographies (vendor operations and data locations)
☐ Alternatives considered
☐ Estimated contract value and term
☐ Requested risk tier (subject to TPRM review)
Annex B: Risk Tiering Scoring Model
[Insert organization-specific scoring rubric with point values for each factor in Section 4.1]
Annex C: Required Contract Clauses Checklist by Tier
[Reference the table in Section 5.3 for minimum contractual requirements]
Annex D: Reassessment Checklist and Evidence Requirements
☐ Updated questionnaire responses
☐ Current SOC 2 / ISO 27001 / PCI DSS report or certificate
☐ Recent penetration test summary
☐ Updated subprocessor list
☐ Insurance certificate renewal
☐ Incident history since last assessment
☐ SLA performance report
☐ Financial review (Critical/High tier)
☐ Updated sanctions/PEP screening
☐ Privacy assessment update (if data types/flows changed)
SOURCES AND REFERENCES
- OCC Bulletin 2023-17, "Third-Party Relationships: Risk Management Guidance" (June 6, 2023; risk-based supervisory guidance for banking organizations supervised by the Board, FDIC, or OCC; not law)
- OCC Bulletin 2013-29, "Third-Party Relationships" (Oct. 30, 2013; rescinded and replaced by OCC Bulletin 2023-17)
- FFIEC IT Examination Handbook, "Outsourcing Technology Services"
- CFPB Bulletin 2012-03, "Service Providers" (Apr. 13, 2012)
- DOJ, "Evaluation of Corporate Compliance Programs" (rev. Mar. 2023)
- U.S. Sentencing Guidelines § 8B2.1 (Effective Compliance and Ethics Program)
- NIST SP 800-161 Rev. 1, "Cybersecurity Supply Chain Risk Management Practices" (May 2022)
- ISO/IEC 27001:2022, Annex A Controls 5.19–5.22
This template is provided for informational purposes only and does not constitute legal advice. Consult qualified legal counsel before use.
About this template
- Last updated
- September 6, 2026
- Jurisdiction
- All states
- Category
- Compliance & Regulatory
Legal authority
- OCC Bulletin 2023-17 (Risk-Based Supervisory Guidance for Banking Organizations; Not Law)
- OCC Bulletin 2013-29 (Rescinded and Replaced by OCC Bulletin 2023-17)
- FFIEC IT Examination Handbook – Outsourcing Technology Services
- CFPB Bulletin 2012-03 (Service Providers)
- DOJ Evaluation of Corporate Compliance Programs (Updated September 2024)
- Federal Sentencing Guidelines § 8B2.1 (Effective Compliance Program)
- NIST SP 800-161 Rev. 1 (Supply Chain Risk Management)
- ISO/IEC 27001:2022 Annex A.5.19–A.5.22
Compliance documents are what regulated businesses use to prove they follow the rules that apply to their industry, whether that is privacy, anti-money-laundering, consumer protection, or sector-specific requirements. Regulators look for consistent policies, up-to-date records, and clear evidence of employee training. The cost of getting compliance paperwork right is almost always smaller than the cost of an enforcement action, fine, or public disclosure.
Not legal advice
This template is provided for informational purposes. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.
Checked against the law it cites
The statutes this template relies on are listed under Legal authority.
OCC Bulletin 2023-17 / 88 Fed. Reg. 37920 (checked September 6, 2026): "This guidance is relevant to all banking organizations supervised by the agencies. Supervisory guidance does not have the force and effect of law and does not impose any new requirements on banking organizations."
OCC Bulletin 2013-29 rescission (checked September 6, 2026): "The agencies have each previously issued general guidance for their respective supervised banking organizations to address appropriate risk management practices for third-party relationships, each of which is rescinded and replaced by this final guidance."
DOJ Evaluation of Corporate Compliance Programs (Updated September 2024) (checked September 5, 2026): "This document is meant to assist prosecutors in making informed decisions as to whether, and to what extent, the corporation’s compliance program was effective at the time of the offense, and is effective at the time of a charging decision or resolution, for purposes of determining the appropriate (1) form of any resolution or prosecution; (2) monetary penalty, if any; and (3) compliance obligations contained in any corporate criminal resolution (e.g., monitorship or reporting obligations)."
Draft your Third-Party Risk Management Standard Operating Procedure in the editor
Answer a few questions, let the AI editor draft each section from your answers, review it, and download Word and PDF. $99 one time, or $249 per month for every document and every Ezel app.