Vendor Risk Complete
The TPRM Program Kit + the Vendor Risk Operations Kit — design the programme, then actually run it. Tiering, questionnaires and clauses on one side; dossiers, scorecards, exit tests and the Register of Information on the other.
What this actually gives you
- The operations kit assumes tiers exist, questionnaires have gone out and contracts carry the clauses — all of which the programme kit produces. Bought alone it is an operating layer with nothing underneath.
- Bought the other way round you have a designed programme that nobody runs after the first quarter — the more common failure, and the harder one to notice.
- Together they answer the two questions a supervisor asks in order: how do you manage vendor risk here, and what is the state of this vendor right now.
The programme and the operating layer, which only work as a pair.
TPRM Program Kit — the design. The policy and charter, a seven-factor tiering model everything downstream computes from, a 150-question bank across 15 domains with Q20 and Q60 as tested subsets, 20 contract clauses with a negotiation fallback ladder, the monitoring cadence, an ERR-01-compatible register and fourth-party concentration scoring.
Vendor Risk Operations Kit — the running of it. The per-vendor dossier, a quarterly scorecard whose PREFERRED / WATCH / AT RISK rating carries consequences, an annual review that must end in a recorded decision, the vendor incident playbook, a tested exit plan for DORA Art. 28(8), an AI due-diligence overlay with hard stops, and the Register of Information builder with ten quality checks.
Why the pair. The operations kit assumes tiers exist, questionnaires have gone out and contracts carry the clauses — all of which the programme kit produces. Bought alone it is an operating layer with nothing underneath. Bought the other way round you have a designed programme that nobody runs after the first quarter, which is the more common failure and the harder one to notice.
Together they cover the two questions a supervisor asks in order: how do you manage vendor risk here, and what is the state of this vendor right now.
Delivered as two separate ZIP downloads.
What's in this bundle
TPRM Program Kit
Tier your vendors in an afternoon, then run the programme — a seven-factor tiering model everything else computes from, a 150-question bank across 15 domains (with an AI-vendor domain) mapped to CSF 2.0 / ISO 27001 / SOC 2, 20 contract clauses with a fallback ladder, an ERR-01-compatible risk register, monitoring cadence, and fourth-party concentration scoring.
Vendor Risk Operations Kit
The programme is designed — this is how you run it, vendor by vendor, and what you hand the examiner. The dossier, a quarterly scorecard whose rating has consequences, an annual review that ends in a decision, the incident playbook, a tested exit plan, an AI overlay with hard stops, and a Register of Information builder with ten quality checks aimed at the failures supervisors actually flag.
What's included
- Complete Library (.zip) — all formats included — fully editable
- Instant download after purchase
- Free updates — re-download when we release new versions
- Practitioner License: unlimited client use (vCISO / MSP)
More from the CISO Marketplace ecosystem
Choose your license:
- Secure checkout via Stripe
- All major cards accepted
- 30-day satisfaction guarantee