Case Study · Third-Party Risk Management

Redesigning Third-Party Risk Management for a Global SaaS Enterprise

As Staff GRC Analyst at Diligent Corporation, I led the security risk and third-party risk functions with a team of five risk professionals. This is an account of how the third-party risk framework and operating model were rebuilt against SOC 2 and BSI C5, why the programme was structured that way, and what it delivered.

Outcomes

~30%

Improvement in operating efficiency following the redesign of the third-party risk framework and operating model against SOC 2 and BSI C5.

250+

Risk-based vendor assessments governed each year with no service-level breach recorded.

50+

Critical supplier reviews delivered annually, sustaining audit and IPO readiness across the estate.

Context: what third-party risk management has to withstand

A software enterprise operating in regulated markets inherits risk from every supplier that processes its data, supports a critical service or sits inside its delivery chain. Customers test that exposure during procurement, auditors test it during SOC 2 and BSI C5 engagements, and investors test it during diligence. A third-party risk programme therefore has to satisfy three audiences simultaneously: the business that needs suppliers onboarded quickly, the assurance functions that need evidence, and leadership that needs a defensible view of residual exposure.

The problems identified

Assessment depth untied to risk

Every supplier attracted broadly the same due diligence, so critical providers received no more scrutiny than low-impact ones while assessment queues lengthened.

Overlapping control frameworks

SOC 2 and BSI C5 obligations were evidenced separately, duplicating effort across assessment cycles and audit preparation.

Detective, not preventive, assurance

Control deficiencies surfaced during audit rather than in the ordinary course of business, compressing remediation windows.

Reporting without a risk narrative

Executive reporting captured assessment throughput but not residual risk, concentration exposure or remediation health.

The redesign

  1. 01

    Risk-tiered due diligence

    Policies, standards and control requirements were rewritten so inherent risk — data sensitivity, criticality of the supported service, integration depth and substitutability — determines the depth of assessment, the evidence demanded and the reassessment cadence.

  2. 02

    Control mapping to SOC 2 and BSI C5

    Supplier control requirements were mapped once against both frameworks, so a single evidence set satisfies each obligation and the programme remains continuously audit-ready rather than being reconstructed each cycle.

  3. 03

    Second-line controls surveillance

    A surveillance capability was established to test control operation independently and identify deficiencies proactively, strengthening assurance coverage ahead of audit and measurably reducing findings.

  4. 04

    Critical supplier review cycle

    More than fifty critical supplier reviews are conducted annually, examining resilience, subcontracting, concentration and remediation progress rather than repeating the onboarding questionnaire.

  5. 05

    Executive risk reporting

    Reporting was reframed around residual risk, exception ageing and remediation health, giving leadership a defensible view of the supplier estate through IPO readiness.

What I would carry into the next programme

  • Tiering is the single highest-return change. Until assessment depth is tied to inherent risk, additional headcount only lengthens the queue.
  • Map controls to every applicable framework once. Duplicated evidence gathering is the largest hidden cost in most TPRM functions.
  • Assurance must be continuous. A second line that tests control operation between audits converts findings into managed work rather than escalations.
  • Report residual risk, not throughput. Boards act on exposure and concentration; assessment counts alone do not support a decision.

Common questions on third-party risk management

What is third-party risk management?
Third-party risk management (TPRM) is the discipline of identifying, assessing, treating and monitoring the risks an organisation inherits from its suppliers, vendors and service providers — spanning information security, resilience, privacy, financial stability and regulatory compliance across the full engagement lifecycle.
How is a third-party risk assessment tiered?
Assessments are tiered by inherent risk: the data the supplier handles, whether it supports a critical business service, the depth of system integration and its concentration or substitutability. Criticality drives the depth of due diligence, the evidence required and the frequency of reassessment, so scarce assurance effort is spent where the exposure is greatest.
How does TPRM map to SOC 2 and BSI C5?
Both frameworks expect documented supplier due diligence, contractual security obligations, ongoing monitoring of critical suppliers and evidence that findings are tracked to closure. Designing TPRM controls so a single set of artefacts satisfies both avoids duplicated assessment cycles and keeps the programme audit-ready.

If you are assessing a third-party risk mandate, I am happy to discuss how this approach would apply to your estate.