Third-Party Risk Management Standard Operating Procedure

All states Compliance & Regulatory Updated September 6, 2026 Free Word and PDF

THIRD-PARTY RISK MANAGEMENT STANDARD OPERATING PROCEDURE

Organization: [________________________________]
SOP Number: TPRM-[____]
Version: [____]
Effective Date: [__/__/____]
Approved By: [________________________________]
Document Owner: [________________________________]


TABLE OF CONTENTS

  1. Purpose and Scope
  2. Regulatory Framework and Authority
  3. Definitions
  4. Risk Tiering Methodology
  5. Third-Party Lifecycle Management
  6. Roles, Responsibilities, and RACI Matrix
  7. Documentation and Systems of Record
  8. Metrics, Key Risk Indicators, and Reporting
  9. Exceptions and Compensating Controls
  10. Review Cadence and Version Control
  11. Annexes

1. PURPOSE AND SCOPE

1.1 Purpose

This Standard Operating Procedure ("SOP") establishes the framework for identifying, assessing, managing, monitoring, and offboarding third-party relationships throughout their lifecycle. It draws on OCC Bulletin 2023-17, FFIEC handbook guidance, and the DOJ's Evaluation of Corporate Compliance Programs. OCC Bulletin 2023-17 is risk-based supervisory guidance for banking organizations supervised by the Board, FDIC, or OCC; it does not have the force and effect of law or impose new requirements. An organization outside that audience may use its lifecycle principles as a voluntary framework, subject to the laws and regulatory guidance actually applicable to that organization. The SOP also supports an organization's fact-specific compliance-program analysis under Federal Sentencing Guidelines § 8B2.1.

1.2 Scope

This SOP applies to all third-party relationships where the third party:

☐ Accesses, processes, stores, or transmits company data
☐ Has connectivity to company information systems
☐ Interacts directly with the organization's customers or end users
☐ Performs critical business functions or provides essential operational support
☐ Is a subcontractor of a direct vendor performing any of the above

This includes vendors, service providers, consultants, outsourcing partners, joint ventures, affiliates performing services, and other relationships the organization places within this policy. For a supervised banking organization, OCC Bulletin 2023-17 uses "business arrangement" broadly and treats it as synonymous with "third-party relationship."

1.3 Exclusions

The following relationships may be excluded from full lifecycle procedures, though they must still be inventoried:

☐ Utility providers (electricity, water, basic telecommunications)
☐ One-time purchases of goods with no data access or system connectivity
☐ Government regulators and auditors


2. REGULATORY FRAMEWORK AND AUTHORITY

This SOP is informed by the following potentially applicable authorities and voluntary frameworks. Applicability must be determined for the organization and relationship; an item below is not automatically a legal requirement merely because it is listed here:

Authority Key Requirements
OCC Bulletin 2023-17 Risk-based supervisory principles for supervised banking organizations across planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination; not law and not a source of new requirements
OCC Bulletin 2013-29 Rescinded and replaced by the 2023 interagency guidance; historical reference only
FFIEC IT Handbook Technology risk assessments, vendor management for outsourced IT
CFPB Bulletin 2012-03 Oversight of service providers handling consumer financial products
DOJ Compliance Evaluation Third-party management as element of effective compliance
Federal Sentencing Guidelines § 8B2.1 Due diligence to prevent and detect criminal conduct
NIST SP 800-161 Rev. 1 Cyber supply chain risk management practices
ISO/IEC 27001:2022 A.5.19-5.22 Information security in supplier relationships

3. DEFINITIONS

Term Definition
Third Party Any entity that has entered into a business relationship with the organization, including vendors, service providers, consultants, and subcontractors
Critical Third Party A third party that supports critical business functions, has access to significant volumes of sensitive data, or whose failure would materially impact operations
Risk Tier Classification (Critical, High, Medium, Low) based on assessed risk factors
Due Diligence Assessment of a third party's ability to perform contracted activities and manage associated risks
Subprocessor/Fourth Party An entity engaged by a third party to perform part of the contracted services
Business Owner The individual responsible for the third-party relationship and accountable for its performance
KRI Key Risk Indicator — a metric that provides an early warning of increasing risk exposure
TPRM Platform The system of record for third-party risk management documentation and workflows

4. RISK TIERING METHODOLOGY

4.1 Tiering Criteria

Each third party shall be assigned a risk tier based on the following factors:

Factor Critical High Medium Low
Data Sensitivity PHI, PCI, high-volume PII, trade secrets PII, confidential business data Internal data, limited PII Public data, no data access
System Access Privileged access, critical systems, direct network Direct system access, read/write Limited application access, read-only No system access
Operational Criticality Business cannot operate; no alternative Significant impact; limited alternatives Moderate impact; workarounds exist Minimal impact; easily replaceable
Regulatory Impact Directly regulated activity; regulatory reporting Significant compliance obligations Some compliance requirements Minimal regulatory implications
Financial Exposure >$[____] annually $[____]–$[____] $[____]–$[____] <$[____]
Customer Impact Direct customer-facing Indirect customer impact No customer impact No customer impact
Geographic Risk High-risk jurisdictions; cross-border data Moderate-risk jurisdictions Domestic, standard jurisdictions Low-risk locations

4.2 Scoring and Assignment

Risk tier is determined by the highest-rated factor unless overridden by documented professional judgment. Override decisions require approval from [________________________________] and must be documented with rationale.

4.3 Tier-Based Requirements

Activity Critical High Medium Low
Due Diligence Depth Full questionnaire + on-site + evidence Full questionnaire + evidence Standard questionnaire Abbreviated assessment
Approval Authority [Board/ExCo] [SVP/CISO/CCO] [VP/Director] [Manager]
Contract Review Legal + Compliance + Security + Privacy Legal + Compliance + Security Legal + Security Standard terms
Monitoring Frequency Continuous + Annual reassessment Semi-Annual Annual Biennial or event-driven
Reassessment Cycle 12 months 18 months 24 months 36 months

5. THIRD-PARTY LIFECYCLE MANAGEMENT

5.1 Phase 1: Planning and Intake

Objective: Identify the business need, assess alternatives, and initiate the TPRM process.

Step Activity Responsible Deliverable
5.1.1 Business Owner completes Third-Party Intake Form Business Owner Completed intake form
5.1.2 Describe use case, data types, system integrations, geographies, and alternatives considered Business Owner Intake form details
5.1.3 Preliminary risk scoring and tier assignment TPRM Team Risk score and tier
5.1.4 Compliance/Security review of tier assignment Compliance / Security Tier confirmation or adjustment
5.1.5 Identify approval authority based on tier TPRM Team Approval routing

☐ Intake form submitted to TPRM Platform
☐ Preliminary tier assigned
☐ Approval authority identified

5.2 Phase 2: Due Diligence and Risk Assessment

Objective: Assess the third party's ability to deliver services while managing risk.

Step Activity Responsible Deliverable
5.2.1 Issue tier-appropriate questionnaire TPRM Team Completed questionnaire
5.2.2 Collect evidence and artifacts per tier requirements TPRM Team Evidence package
5.2.3 Sanctions/PEP/adverse media screening Compliance Screening report
5.2.4 Export controls/licensing review (if applicable) Compliance / Legal Export assessment
5.2.5 Security controls assessment Security Security assessment report
5.2.6 Privacy assessment (DSR handling, data flows, transfers) Privacy Privacy assessment
5.2.7 Financial viability review (Critical/High tier) Finance Financial assessment
5.2.8 BC/DR capability assessment Security / Business Owner Resilience assessment
5.2.9 Consolidated risk assessment and recommendation TPRM Team Risk assessment report
5.2.10 Present findings and recommendation to approval authority TPRM Team Approval or rejection

☐ Questionnaire completed and reviewed
☐ Evidence collected and validated
☐ Screenings clear (or findings documented)
☐ Risk assessment report completed
☐ Approval decision documented

5.3 Phase 3: Contract Negotiation and Execution

Objective: Ensure contractual terms appropriately allocate risk and address regulatory requirements.

Internal baseline contract terms by risk tier are listed below. These are organization policy choices to tailor to relationship risk and applicable law; OCC Bulletin 2023-17 does not prescribe every listed term for every relationship:

Clause Critical High Medium Low
Data Processing Agreement (DPA) ☐ Required ☐ Required ☐ If data processed ☐ If data processed
Security Addendum ☐ Required ☐ Required ☐ Required ☐ Standard terms
SLA / Uptime Commitments ☐ Required ☐ Required ☐ Recommended ☐ Optional
Breach Notification Timeline ☐ Required (≤24 hrs) ☐ Required (≤48 hrs) ☐ Required (≤72 hrs) ☐ Reasonable
Audit / Pen Test Rights ☐ Required ☐ Required ☐ Required ☐ Optional
Subcontractor Approval Rights ☐ Required ☐ Required ☐ Notification ☐ N/A
Data Return / Deletion on Termination ☐ Required ☐ Required ☐ Required ☐ Required
Insurance Minimums ☐ Required ☐ Required ☐ Recommended ☐ Optional
Indemnification ☐ Required ☐ Required ☐ Required ☐ Standard
Regulatory Compliance Representations ☐ Required ☐ Required ☐ Recommended ☐ Optional
Standard Contractual Clauses (int'l transfers) ☐ If applicable ☐ If applicable ☐ If applicable ☐ If applicable

☐ Contract reviewed by Legal
☐ Contract reviewed by Compliance/Security/Privacy (per tier)
☐ Deviations from required terms documented with compensating controls
☐ Contract executed and filed in contract repository

5.4 Phase 4: Onboarding

Step Activity Responsible
5.4.1 Validate controls are implemented before go-live Security
5.4.2 Provision system access with least-privilege IT / Security
5.4.3 Enable logging and monitoring Security
5.4.4 Assign relationship owner and document in TPRM platform TPRM Team
5.4.5 Set monitoring schedule and next reassessment date TPRM Team

☐ Controls validated
☐ Access provisioned
☐ Monitoring enabled
☐ TPRM system updated

5.5 Phase 5: Ongoing Monitoring

Monitoring Activity Frequency by Tier (C/H/M/L) Responsible
SLA performance tracking Monthly / Quarterly / Semi-Annual / Annual Business Owner
Security incident monitoring Continuous Security
Subprocessor change notices As received Compliance / Security
Financial health monitoring (Critical) Quarterly Finance
Regulatory and sanctions rescreening Annual / Annual / Biennial / Biennial Compliance
Complaint and escalation tracking Ongoing Business Owner
News/adverse media monitoring Continuous (Critical/High) / Event-driven Compliance

☐ Monitoring schedule documented
☐ Incidents tracked and escalated per SOP
☐ Material changes evaluated and acted upon

5.6 Phase 6: Periodic Reassessment

Tier Reassessment Cycle Trigger Events
Critical 12 months Incident, scope change, data/geo expansion, M&A, regulatory change
High 18 months Same as above
Medium 24 months Same as above
Low 36 months Same as above

☐ Reassessment questionnaire issued
☐ Updated evidence collected
☐ Risk tier re-evaluated
☐ Findings documented and remediation tracked

5.7 Phase 7: Offboarding and Termination

Step Activity Responsible
5.7.1 Confirm data return or deletion; obtain written certification Business Owner / Privacy
5.7.2 Revoke all system access and credentials IT / Security
5.7.3 Migrate services to replacement vendor (if applicable) Business Owner
5.7.4 Collect final deliverables and resolve open items Business Owner
5.7.5 Close out records in TPRM platform TPRM Team
5.7.6 Retain records per document retention policy Compliance

☐ Data returned or deletion certified
☐ Access revoked
☐ TPRM system updated to "Terminated"
☐ Records retained per policy


6. ROLES, RESPONSIBILITIES, AND RACI MATRIX

6.1 Key Roles

Role Responsibilities
Business Owner Initiates intake, funds vendor, owns day-to-day relationship, escalates issues
TPRM Team Administers program, facilitates assessments, maintains platform, tracks metrics
Compliance Policy oversight, sanctions/export review, regulatory clause review, exception approval
Security Technical security assessment, penetration test reviews, monitoring requirements
Privacy Data mapping, DPA/SCC review, DSR process assessment, transfer risk
Legal Contract review, clause negotiation, regulatory interpretation
Procurement Commercial terms, RFP management, payment controls
Finance Financial viability assessment, payment controls
Internal Audit Independent program testing and assessment (if applicable)
Board/Committee Ultimate oversight, approve program charter, review critical relationships

6.2 RACI Matrix

Activity Business Owner TPRM Team Compliance Security Privacy Legal Procurement
Intake R/A C I I I I I
Tier Assignment I R A C C I I
Due Diligence C R C C C I I
Contract Review I C C C C R/A C
Onboarding R C I R I I I
Ongoing Monitoring R C C R C I I
Reassessment C R C C C I I
Offboarding R C I R C I I

R = Responsible, A = Accountable, C = Consulted, I = Informed


7. DOCUMENTATION AND SYSTEMS OF RECORD

7.1 TPRM Platform

All TPRM activities shall be documented in the designated platform: [________________________________]

The platform shall maintain:

☐ Third-party inventory (active and terminated)
☐ Intake forms and tier assignments
☐ Questionnaires and evidence packages
☐ Screening results
☐ Risk assessment reports
☐ Approval records
☐ Contract references (linked to contract repository)
☐ Monitoring notes and incident records
☐ Reassessment history
☐ Exception requests and approvals
☐ Offboarding checklists and certifications

7.2 Record Retention

TPRM records shall be retained for a minimum of [____] years after termination of the relationship, or longer if required by applicable law or regulation.


8. METRICS, KEY RISK INDICATORS, AND REPORTING

8.1 Program Metrics

Metric Target Frequency
Time-to-approve (by tier) Critical: [____] days; High: [____] days Monthly
Due diligence completion rate [____]% Monthly
Reassessment completion (on schedule) [____]% Quarterly
Open exception count and aging <[____] open; <[____] days avg age Quarterly
Incident notification timeliness [____]% within SLA Quarterly
SLA breaches by critical vendors <[____] per quarter Quarterly
Critical vendor concentration risk Documented for all Quarterly
Training completion rate [____]% Annual

8.2 Reporting

Audience Report Content Cadence
[Board/Committee] Program overview, critical vendor risks, incident summary, exception status, regulatory changes Quarterly
Senior Management Detailed metrics, reassessment status, remediation tracking Monthly
Business Owners Vendor-specific status, upcoming reassessments, open actions As needed

9. EXCEPTIONS AND COMPENSATING CONTROLS

9.1 Exception Process

Step Activity
9.1.1 Business Owner submits exception request with risk justification
9.1.2 TPRM Team reviews and documents compensating controls
9.1.3 Exception approved by [Compliance Lead / CISO / CCO] based on risk tier
9.1.4 Exception recorded with: risk owner, approver, expiration date, compensating controls
9.1.5 Exception reviewed at expiration; renewed or remediated

9.2 Approval Authority for Exceptions

Tier Approver
Critical [Board/ExCo Member]
High [SVP / CCO / CISO]
Medium [VP / Director]
Low [Manager / TPRM Lead]

10. REVIEW CADENCE AND VERSION CONTROL

Field Information
SOP Owner [________________________________]
Review Frequency Annual, or upon material change (regulation, major incident, program redesign)
Next Review Date [__/__/____]
Approval Authority [________________________________]

Version History:

Version Date Author Changes
[____] [__/__/____] [________________] [________________________________]

11. ANNEXES

Annex A: Third-Party Intake Form Fields

☐ Vendor legal name and contact information
☐ Business use case and justification
☐ Data types and volumes
☐ System integrations and access requirements
☐ Geographies (vendor operations and data locations)
☐ Alternatives considered
☐ Estimated contract value and term
☐ Requested risk tier (subject to TPRM review)

Annex B: Risk Tiering Scoring Model

[Insert organization-specific scoring rubric with point values for each factor in Section 4.1]

Annex C: Required Contract Clauses Checklist by Tier

[Reference the table in Section 5.3 for minimum contractual requirements]

Annex D: Reassessment Checklist and Evidence Requirements

☐ Updated questionnaire responses
☐ Current SOC 2 / ISO 27001 / PCI DSS report or certificate
☐ Recent penetration test summary
☐ Updated subprocessor list
☐ Insurance certificate renewal
☐ Incident history since last assessment
☐ SLA performance report
☐ Financial review (Critical/High tier)
☐ Updated sanctions/PEP screening
☐ Privacy assessment update (if data types/flows changed)


SOURCES AND REFERENCES

  • OCC Bulletin 2023-17, "Third-Party Relationships: Risk Management Guidance" (June 6, 2023; risk-based supervisory guidance for banking organizations supervised by the Board, FDIC, or OCC; not law)
  • OCC Bulletin 2013-29, "Third-Party Relationships" (Oct. 30, 2013; rescinded and replaced by OCC Bulletin 2023-17)
  • FFIEC IT Examination Handbook, "Outsourcing Technology Services"
  • CFPB Bulletin 2012-03, "Service Providers" (Apr. 13, 2012)
  • DOJ, "Evaluation of Corporate Compliance Programs" (rev. Mar. 2023)
  • U.S. Sentencing Guidelines § 8B2.1 (Effective Compliance and Ethics Program)
  • NIST SP 800-161 Rev. 1, "Cybersecurity Supply Chain Risk Management Practices" (May 2022)
  • ISO/IEC 27001:2022, Annex A Controls 5.19–5.22

This template is provided for informational purposes only and does not constitute legal advice. Consult qualified legal counsel before use.

Insert Image

Insert Table

Watch Ezel in action (sample case)Choose a plan

All changes saved
Save
Export
Export as DOCX
Export as PDF
Generating PDF...
third_party_risk_management_sop_universal.pdf
Ready to export as PDF or Word
AI is editing...
Chat
Review

Draft it in the editor

The AI drafts each section from your answers and you review every word. Drafting from scratch takes hours; finish yours for $99 one time.

  • Built on this template
    Uses the state version and the statutes it cites.
  • Formatted like the template
    Captions, numbering and layout stay intact.
  • AI editing
    Rewrite any section from your own notes.
  • Export as PDF and Word
    Yours to review, sign, or file.
Secure checkout via Stripe
Need to customize this document?

About this template

Last updated
September 6, 2026
Jurisdiction
All states
Category
Compliance & Regulatory

Legal authority

  • OCC Bulletin 2023-17 (Risk-Based Supervisory Guidance for Banking Organizations; Not Law)
  • OCC Bulletin 2013-29 (Rescinded and Replaced by OCC Bulletin 2023-17)
  • FFIEC IT Examination Handbook – Outsourcing Technology Services
  • CFPB Bulletin 2012-03 (Service Providers)
  • DOJ Evaluation of Corporate Compliance Programs (Updated September 2024)
  • Federal Sentencing Guidelines § 8B2.1 (Effective Compliance Program)
  • NIST SP 800-161 Rev. 1 (Supply Chain Risk Management)
  • ISO/IEC 27001:2022 Annex A.5.19–A.5.22

Compliance documents are what regulated businesses use to prove they follow the rules that apply to their industry, whether that is privacy, anti-money-laundering, consumer protection, or sector-specific requirements. Regulators look for consistent policies, up-to-date records, and clear evidence of employee training. The cost of getting compliance paperwork right is almost always smaller than the cost of an enforcement action, fine, or public disclosure.

Not legal advice

This template is provided for informational purposes. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.

Checked against the law it cites

The statutes this template relies on are listed under Legal authority.

OCC Bulletin 2023-17 / 88 Fed. Reg. 37920 (checked September 6, 2026): "This guidance is relevant to all banking organizations supervised by the agencies. Supervisory guidance does not have the force and effect of law and does not impose any new requirements on banking organizations."

OCC Bulletin 2013-29 rescission (checked September 6, 2026): "The agencies have each previously issued general guidance for their respective supervised banking organizations to address appropriate risk management practices for third-party relationships, each of which is rescinded and replaced by this final guidance."

DOJ Evaluation of Corporate Compliance Programs (Updated September 2024) (checked September 5, 2026): "This document is meant to assist prosecutors in making informed decisions as to whether, and to what extent, the corporation’s compliance program was effective at the time of the offense, and is effective at the time of a charging decision or resolution, for purposes of determining the appropriate (1) form of any resolution or prosecution; (2) monetary penalty, if any; and (3) compliance obligations contained in any corporate criminal resolution (e.g., monitorship or reporting obligations)."

Draft your Third-Party Risk Management Standard Operating Procedure in the editor

Answer a few questions, let the AI editor draft each section from your answers, review it, and download Word and PDF. $99 one time, or $249 per month for every document and every Ezel app.