Skip to content

Latest commit

 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

A Generalized Framework for Third-Party Risk Management

One vendor assessment presents a different rating face to each engagement.

This is a generalized framework for third-party risk management (TPRM): an object model, workflows, and data flows for capturing Inherent Risk, Quality of Risk Management (QRM), and Residual Risk at the third-party, engagement, and risk-domain levels. It is written for a US financial services context and aligned to the 2023 Interagency Guidance on Third-Party Relationships, but the design is not institution-specific.

The central idea

Risk is engagement-specific, but the vendor relationship is singular. Regulators require due diligence tailored to each specific activity a third party performs; vendors are one organization with one set of documents. The framework resolves the mismatch by splitting what is assessed from how it is scored:

  • Due diligence runs once per third party — one document collection, one AI-assisted evaluation of control evidence against the full program control catalog, one steward-managed question dialogue covering the union of all engagements' applicable controls.
  • Ratings are computed per engagement and per risk domain — rule-driven scoping determines which controls, evaluation results, and issues count toward each engagement's QRM and Residual Risk. An engagement requiring 25% of the vendor's evaluated controls is rated on exactly that 25%.
  • Ratings are living values — control scores derive from open issues, improve on remediation, and recompute on scope or risk changes using retained evaluations, with full effective-dated history.

Contents

Path Description
index.html The complete framework document, single file, diagrams render in any browser (also served via GitHub Pages)
docs/01-executive-summary.md Overview, benefits, scope
docs/02-object-model.md Entities, relationships, key attributes, calculation summary, ERD
docs/03-workflows-data-flows.md Five workflows (IRA/IRR, due diligence/QRM, residual risk, issue management, scope change review), reassessment trigger taxonomy, data flow
docs/04-implementation-recommendations.md AI evaluation safeguards, scoring defaults, catalog sourcing, examiner-readiness, sources
docs/erd.mermaid Entity-relationship diagram source
CITATION.cff Citation metadata
LICENSE CC BY 4.0

Markdown files include Mermaid diagrams, which GitHub renders natively.

Status

Version 1.0 (July 2026). Feedback, critique, and discussion are welcome — please open an issue. Substantive contributions to future versions are credited; see CONTRIBUTING.md.

License and citation

© 2026 Robert Ham. Licensed under Creative Commons Attribution 4.0 International (CC BY 4.0) — share and adapt freely, with attribution.

Ham, R. (2026). A Generalized Framework for Third-Party Risk Management, v1.0.

Acknowledgments

Forthcoming.

About

A generalized framework for third-party risk management

Topics

Resources

Contributing

Stars

0 stars

Watchers

0 watching

Forks

Releases

Contributors

Languages