Vendors
TPRM → Vendors
The vendor register is the list of third parties you depend on. Everything else in the module hangs off it.
Adding a vendor
| Field | Notes |
|---|---|
| Name / Name (Arabic) | As it appears on the contract. |
| Vendor code | Your own reference. Shown next to the name in lists and reports. |
| Service category | Cloud, SaaS, BPO, data processing, physical security and so on. |
| Tier | Critical, high, medium or low. |
| Contact | Who receives questionnaires. Use a named person, not a shared mailbox. |
| Next assessment date | Drives the review-due reporting. |
Tiering
Tier is your judgement of how much the relationship matters — how much damage this vendor could do if it failed or was breached. It is set on the vendor, not derived, and it drives:
- how deep a questionnaire you send,
- how often you re-assess,
- where the vendor sits in the reports.
A small supplier holding your customer data is critical. A large supplier selling you office furniture is not. Tier on data access, business dependency and regulatory exposure.
Inherent and residual
Inherent risk is the exposure before any of the vendor's controls — driven by tier and service category.
Residual risk is what remains after their controls, and it is derived from assessment results, not typed in. A vendor with no completed assessment has no residual score, and that blank means "not assessed" — not "safe".
Vendor detail
Opening a vendor shows its assessments, findings, evidence and contacts in one place, with the current rating and next review date. This is the page to open before a contract renewal.
Offboarding
Offboarding a vendor keeps its history. Assessments, findings and evidence stay readable — you may need to show a regulator what you knew about a vendor you no longer use.