ciso.diy
TPRM Program Kit preview
Vendor Risk TPRMthird-party riskvendor risksupplier assurance

TPRM Program Kit

Tier your vendors in an afternoon, then run the programme — a seven-factor tiering model everything else computes from, a 150-question bank across 15 domains (with an AI-vendor domain) mapped to CSF 2.0 / ISO 27001 / SOC 2, 20 contract clauses with a fallback ladder, an ERR-01-compatible risk register, monitoring cadence, and fourth-party concentration scoring.

What this actually gives you

  • A 150-question bank across 15 domains — original content, not a re-typed SIG — with Q20 and Q60 as tested subsets of the same bank rather than separate documents that drift apart.
  • Every question maps to NIST CSF 2.0, ISO 27001:2022 and SOC 2, so a vendor’s answers double as evidence for your own audits.
  • Includes an AI-vendor domain most off-the-shelf sets still lack: training-data use, model change control, sub-processor disclosure.
  • Seven-factor tiering with weights you can change and a Tier 2 floor override, so anyone holding domain admin cannot score their way down. Register rows, concentration counts and the board slide all compute from that sheet.

Every framework you are measured against has a supplier-risk requirement — SOC 2 CC9.2, ISO 27001:2022 A.5.19–A.5.23, NIST CSF 2.0's whole GV.SC function, DORA Articles 28–30, NIS2, CMMC. Most organisations answer them with a spreadsheet of vendor names and a folder of SOC 2 reports nobody has read. This kit is the programme those requirements actually describe.

The catalogue already sells the Enterprise Questionnaire Response Kit — the inbound side, for when someone assesses you. This is the outbound side.

01 TPRM Policy & Program Charter (DOCX) — policy statements, roles, charter objectives and measures, governance cadence and the approval block. The document that makes procurement a gate rather than a suggestion.

02 Vendor Inventory & Tiering Model (XLSX) — seven-factor inherent-risk scoring into Tiers 1–4, each tier carrying its own due-diligence depth. The weights are yours to change, and there is a Tier 2 floor override so anyone holding domain admin cannot score their way down. Inventory sized for 100 vendors with an auto-computed summary. Every other number in the kit — register rows, concentration counts, the board slide — computes from this sheet.

03 Vendor Questionnaire Set (XLSX + questionnaire.json) — a 150-question bank across 15 domains, original content rather than a re-typed SIG, with Q20 and Q60 as tested subsets of the same bank rather than separate documents that drift apart. Every question is mapped to NIST CSF 2.0, ISO 27001:2022 and SOC 2, so a vendor's answers double as evidence for your own audits. Includes an AI-vendor domain most off-the-shelf sets still lack — training-data use, model change control, sub-processor disclosure.

04 Evidence Acceptance Guide (PDF) — what a SOC 2, an ISO certificate, a pen test, a ratings score and a completed questionnaire each actually prove, what they do not, and what to ask for instead. Evidence minimums by tier. This is the file that stops a Type I report with a three-month scope from being accepted as assurance.

05 Contract Clause Library (DOCX) — 20 drop-in clauses with drafting notes and a negotiation fallback ladder for when the vendor says no, plus regulatory add-ons for GDPR, HIPAA, DORA Art. 30, NIS2, CMMC, CCPA, CRA and PCI. The AI-training clause belongs on your Tier 1 and 2 paper now.

06 Continuous-Monitoring Cadence (XLSX) — 12 monitoring activities by tier, and 10 trigger events with SLA and escalation, so reassessment is driven by change rather than by anniversary.

07 Vendor Risk Register (XLSX) — one row per risk, not per vendor, with inherent and residual scoring, a heatmap and a summary. ERR-01-compatible: the risk ids roll up to your enterprise register, and the control ref column takes your own ISMS-01 control_key values. Vendor findings reference controls; they never write control state.

08 Fourth-Party & Concentration Worksheet (XLSX) — sub-processor map, concentration counts with flags, and substitutability and exit-readiness scoring. Concentration is now supervisor-visible under DORA Arts. 28–30, and this is the sheet that answers it.

09 Onboarding & Offboarding Runbooks (DOCX) — intake to approval, change and renewal, offboarding, and the vendor incident inquiry you send when their breach becomes your problem.

10 Board Metrics Slide (PPTX) — one quarterly slide: five numbers, top risks, concentration, decisions needed. Populated from 02 and 07.

11 Program Guide (PDF) — the operating model, where to source your inventory (AP, IdP, CASB/DNS, contracts), the tiering rationale, evidence, contracts, monitoring, fourth parties, AI vendors, the regulatory map, a 90-day stand-up and the failure modes.

Calibrate before you trust it. Run ten vendors you already know through the tiering sheet. If your hosting provider does not land in Tier 1, move the cut-offs — not the vendor.

Pairs with ERR-01 for the enterprise register the vendor rows feed, and the CCPA Cybersecurity Audit Kit, whose audit component CA-15 is third-party oversight.

What's included

  • Complete Library (.zip) — all formats included — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
  • Practitioner License: unlimited client use (vCISO / MSP)

Choose your license:

  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.0
Last updated 2026-09-03
Pages 11