Information & Communications Technology

Third-Party IT Vendor Risk Assessment Programmes

Build a third-party IT vendor risk assessment programme that tiers suppliers by exposure, verifies their controls with evidence, and monitors risk continuously after onboarding.

Duration5 training days
Content4 modules · 8 sessions
On completionAccredited attendance certificate
About the programme

Course Overview

Outsourcing a function does not outsource the risk, and a single unassessed IT supplier with weak controls can expose an organisation to a breach, an outage or a compliance failure just as effectively as an internal system would. This course teaches you to build a vendor risk assessment programme that scales sensibly, tiering suppliers by the actual exposure they represent rather than subjecting every vendor to the same lengthy questionnaire. You will design due diligence assessments that verify claimed controls with evidence such as audit reports and penetration test summaries, negotiate contractual protections including right-to-audit and breach notification clauses, and set up continuous monitoring that catches a supplier's risk profile changing after onboarding rather than only at renewal. Sessions also address fourth-party risk, the suppliers your suppliers depend on, and a structured offboarding process that closes access and recovers data cleanly when a vendor relationship ends.

Expected Learning Outcomes

01

Tier third-party IT vendors by data sensitivity, system criticality and access level to scale assessment effort appropriately.

02

Design due diligence questionnaires and evidence requests calibrated to each vendor tier's actual risk exposure.

03

Verify vendor-claimed controls using independent evidence such as audit reports and penetration test summaries.

04

Negotiate contractual protections, including right-to-audit, breach notification and data return clauses, into vendor agreements.

05

Establish continuous monitoring that detects material changes in a vendor's risk profile after onboarding.

06

Assess fourth-party risk arising from the subcontractors and cloud providers a vendor itself depends on.

07

Run a structured vendor offboarding process that closes access and recovers or destroys data on schedule.

Who Should Attend

01

Vendor risk management and third-party risk teams

02

IT procurement staff negotiating supplier contracts with security requirements

03

Information security professionals assessing supplier control environments

04

Compliance officers responsible for regulatory third-party risk obligations

05

IT operations managers who own ongoing relationships with critical suppliers

06

Legal and contracts staff drafting vendor risk and data protection clauses

Course Modules

Select any module to see its sessions and points.

01

Tiering Vendors by Risk Exposure

2 sessions · 8 points

Session 1Building a Vendor Risk Tiering Model

  • Classify vendors by the sensitivity of data they access and the criticality of systems they support.
  • Weight tiering criteria to reflect access level, such as whether a vendor holds standing privileged access.
  • Assign each vendor a tier that determines the depth of due diligence and monitoring required.
  • Reassess vendor tiers when the scope of a supplier relationship changes materially.

Session 2Scaling Assessment Effort to Tier

  • Apply a lightweight assessment for low-tier vendors to avoid wasting effort disproportionate to their risk.
  • Reserve full due diligence, including on-site or evidence-based review, for the highest-risk vendor tier.
  • Set assessment renewal frequency according to tier rather than a single organisation-wide schedule.
  • Justify the tiering model to auditors and regulators as a proportionate, risk-based approach.
02

Conducting Due Diligence Assessments

2 sessions · 8 points

Session 1Designing Assessment Questionnaires

  • Design due diligence questionnaires that ask for verifiable evidence rather than self-certified assurances alone.
  • Tailor questionnaire depth and topics, such as encryption, access control and incident response, to the vendor's tier.
  • Include questions specific to cloud-hosted vendors, covering data residency and shared responsibility boundaries.
  • Avoid duplicating questions already answered by a recognised independent audit report the vendor can provide.

Session 2Verifying Evidence and Closing Gaps

  • Review independent audit reports and penetration test summaries to verify a vendor's claimed control environment.
  • Identify gaps between a vendor's questionnaire answers and the evidence actually supplied.
  • Require remediation commitments with dates before onboarding a vendor with identified control gaps.
  • Escalate unresolved high-risk gaps to a risk committee for an informed accept, reject or mitigate decision.
03

Embedding Risk into Contracts and Monitoring

2 sessions · 8 points

Session 1Negotiating Contractual Protections

  • Negotiate right-to-audit clauses that allow verification of a vendor's controls during the contract term.
  • Include breach notification timelines in contracts that are fast enough to support the organisation's own obligations.
  • Require data return or destruction commitments with verifiable evidence at contract termination.
  • Define liability and insurance requirements proportionate to the risk the vendor relationship represents.

Session 2Monitoring Vendor Risk Continuously

  • Set up continuous monitoring signals, such as security ratings services and breach disclosure feeds, for critical vendors.
  • Define triggers that prompt an out-of-cycle reassessment, such as a vendor's own reported security incident.
  • Track vendor remediation commitments to completion rather than closing the item once a promise is made.
  • Report vendor risk status changes to relevant business owners promptly rather than waiting for the next review cycle.
04

Managing Fourth-Party Risk and Offboarding

2 sessions · 8 points

Session 1Assessing Fourth-Party Exposure

  • Identify the critical subcontractors and cloud providers a key vendor depends on to deliver its service.
  • Request disclosure of material fourth parties as part of the due diligence and contract renewal process.
  • Assess concentration risk where multiple vendors depend on the same underlying fourth-party provider.
  • Extend monitoring triggers to cover significant incidents disclosed by a vendor's own critical suppliers.

Session 2Running a Clean Vendor Offboarding

  • Plan offboarding steps in advance for critical vendors rather than improvising when a contract ends.
  • Revoke system and data access promptly and verify revocation rather than assuming it occurred.
  • Confirm data return or destruction with documented evidence before closing the vendor record.
  • Capture lessons from the relationship, including unresolved risk items, to inform future vendor selection.

What the participant receives

4 course modules

A structured syllabus

8 training sessions

across 5 days

32 detailed points

Applied, detailed content

Accredited attendance certificate

On completing the programme

Complete your registration

We will contact you within one business day to confirm.

Ready to start?

Reserve your seat and start building the skill.

Enroll now

Share this course