One vendor assessment presents a different rating face to each engagement.
This is a generalized framework for third-party risk management (TPRM): an object model, workflows, and data flows for capturing Inherent Risk, Quality of Risk Management (QRM), and Residual Risk at the third-party, engagement, and risk-domain levels. It is written for a US financial services context and aligned to the 2023 Interagency Guidance on Third-Party Relationships, but the design is not institution-specific.
Risk is engagement-specific, but the vendor relationship is singular. Regulators require due diligence tailored to each specific activity a third party performs; vendors are one organization with one set of documents. The framework resolves the mismatch by splitting what is assessed from how it is scored:
- Due diligence runs once per third party — one document collection, one AI-assisted evaluation of control evidence against the full program control catalog, one steward-managed question dialogue covering the union of all engagements' applicable controls.
- Ratings are computed per engagement and per risk domain — rule-driven scoping determines which controls, evaluation results, and issues count toward each engagement's QRM and Residual Risk. An engagement requiring 25% of the vendor's evaluated controls is rated on exactly that 25%.
- Ratings are living values — control scores derive from open issues, improve on remediation, and recompute on scope or risk changes using retained evaluations, with full effective-dated history.
| Path | Description |
|---|---|
index.html |
The complete framework document, single file, diagrams render in any browser (also served via GitHub Pages) |
docs/01-executive-summary.md |
Overview, benefits, scope |
docs/02-object-model.md |
Entities, relationships, key attributes, calculation summary, ERD |
docs/03-workflows-data-flows.md |
Five workflows (IRA/IRR, due diligence/QRM, residual risk, issue management, scope change review), reassessment trigger taxonomy, data flow |
docs/04-implementation-recommendations.md |
AI evaluation safeguards, scoring defaults, catalog sourcing, examiner-readiness, sources |
docs/erd.mermaid |
Entity-relationship diagram source |
CITATION.cff |
Citation metadata |
LICENSE |
CC BY 4.0 |
Markdown files include Mermaid diagrams, which GitHub renders natively.
Version 1.0 (July 2026). Feedback, critique, and discussion are welcome — please open an issue. Substantive contributions to future versions are credited; see CONTRIBUTING.md.
© 2026 Robert Ham. Licensed under Creative Commons Attribution 4.0 International (CC BY 4.0) — share and adapt freely, with attribution.
Ham, R. (2026). A Generalized Framework for Third-Party Risk Management, v1.0.
Forthcoming.