TPRM: Monitoring Third Parties
A vendor questionnaire filed in March 2025 would have gone stale the day the vendor’s transformation started. With a scoped credential, the third-party risk management (TPRM) analyst watches the score move as the environment does. (Full data: Security Transformation.)
The moment that matters is October:
| scoreDate | score | What happened |
|---|---|---|
| 2025-09-15 | 62 | Foundations in place, trending up |
| 2025-10-20 | 59 | Cutover dip, localized to two pillars |
| 2025-11-30 | 68 | Segmentation complete, recovered above pre-dip |
What the analyst reads
Section titled “What the analyst reads”A dip becomes a conversation, not a surprise. The analyst sees the drop the week it happens. The pillar breakdown shows it’s localized to Structural Integrity and Failure Resistance, the two pillars under re-architecture, while Device Health and Recovery hold steady. One call confirms the vendor is mid-cutover, and the recovery is visible in the data within weeks. Compare that to discovering the same event in next year’s questionnaire.
Thresholds slot into vendor tiering. Grades map to review triggers: a drop out of Strengthen prompts a check-in, a sustained Prioritize escalates. The monitoring program runs on rules, not calendar anniversaries.
Access matches the relationship. The vendor issues the credential, scopes it to the data the program needs, and revokes it when the relationship ends (see Authentication). No standing questionnaire debt on their side; no stale assessments on yours.
In the workflow
Section titled “In the workflow”- Poll Get Score daily per vendor (scores update once a day) and alert on grade transitions
- Pull Get Pillars on any composite move to localize what changed before the vendor call
