Third-Party Risk Management

Every organization is different and for that reason, a one size fits all approach should not be applied to your third-party risk management program.

Protiviti delivers third-party risk management (TPRM) solutions that are embedded into day-to-day business functions while aligning to industry and regulatory expectations. We identify cost savings, create efficiencies in processes, and mitigate today’s most critical risks.

Successful TPRM drives value by helping to focus business leaders understanding where the usage of third parties will help increase profitability while ensuring your organization’s ecosystem is built to withstand new and unexpected challenges.

If you're in a regulated environment we help you drive compliance if you're in a non-regulated environment we will help increase profitability.

Slash costs, improve processes, and mitigate the most critical risks of today

Our Third-Party Risk Management Services

TPRM Strategy and Programme Assessment, Design and Implementation/Transformation

We provide better information that helps drive business decisions and generates revenue enhancing activities from assessing the current state, designing and building end-to-end programs, enhancing individual life cycle components and implementing impactful changes.


Improvement of Individual Risk Domains: Operational Resilience (Business Continuity), IT Security, Privacy, PCI, and Compliance

We help leaders streamline data gathering and assessment activities to produce actionable information for each risk domain, support the creation of meaningful and real-time monitoring mechanisms and inform contracting processes through the creation of governance mechanisms that drive stronger Key Risk Indicators, Key Performance Indicators and Service Level Agreements.


Third-Party Audits (IT Security/ Shared Assessments, Operations, Compliance)

Protiviti’s assessment services drive decision making and inform risk stakeholders in a manner that is consistent with how your organization manages its risks. We deliver meaningful output to our clients that informs whether a third party meets your expectations across the many risk domains.


Technology Enablement

Implement robust TPRM programs across a variety of industries and geographies. TPRM requires technology enablement to make life cycle processes connect seamlessly and provide stakeholders with the information required to make better decisions. Protiviti helps you navigate through these implementations to help streamline programs and processes to keep costs down.


Targeted Issue Remediation and Incident Response

Identify and resolve TPRM issues in a manner that supports your business and reduces the future risk of the same or similar issues repeating at a third party. Issues will arise with third parties no matter how strong your program may be.

web graphic

An integrated approach to driving value

Procurement and Third-Party Risk Management should be integrated across the life cycle to enhance your visibility, efficiency, risk management and cost management. The four sections of the TPRM life cycle each have an important part to play in helping you determine the right partners to drive your business growth and customer success. Protiviti offers an integrated one-stop solution for financial, information technology, compliance and operational due diligence. Transactions that have been through a comprehensive due diligence process are the most successful, and you are able to realize their expected value.

  • Planning: Successful TPRM starts with strong linkages to business strategies and the value creation process.
  • Due Diligence & Third-Party Selection: Risk Assessment, Due Diligence & Third-Party Selection should be coordinated, risk focused and intended to drive business value decisioning.
  • Contract Management: Contract Management should be informed from the results of due diligence and end in contracts that align to business needs and provide appropriate risk mitigation requirements.
  • Monitoring and Management: Strong contracts drive accountability for oversight activities which helps establish expectations for all parties on what will be required to have a successful relationship.
web graphic


Brian Kostek
Brian is a Managing Director with Protiviti and is part of the Risk and Compliance team located in Tampa, Florida. Brian’s experience and expertise focuses on regulatory risk and compliance, Third-Party risk management, and operational risk. Prior to joining Protiviti, ...
Chris Monk
Chris is a Managing Director and one of the leaders of the Global Supply Chain Solutions practice at Protiviti. He has over 18 years’ experience in supply chain, both within industry and serving clients as a consultant. He has a proven track record of analyzing, ...


Resilience Practices Can Help Firms Mitigate Supply Chain and Third-Party Provider Risks - Top of Mind Compliance Issues for 2021

Resilience Practices Can Help Firms Mitigate Supply Chain and Third-Party Provider Risks - Top of Mind Compliance Issues for 2021

Customers are major drivers of change in the marketplace. In times of stress, how well companies manage customer experience and expectation can determine whether they succeed. At the height of the COVID-19 pandemic, amid demand spikes and panic...
Read More


Customer Service and Complaints

Customer Service and Complaints: How Firms Can Build Long-Term Resilience and New Capabilities

Regulatory agencies around the world have intensified their focus on financial institutions’ customer service activities amid a dramatic COVID-19- related surge in complaints. These stepped-up regulatory efforts come during a period when many...
Read More


operational resilience

Operational Resilience: Considerations For Boards, The C-Suite and Enterprisewide Implementation

Since the beginning of 2020, organizations have been working tirelessly to address the range of complex issues accentuated by the COVID-19 pandemic. While this work continues for many organizations, forward-thinking business leaders are also looking...
Read More

Case Studies

Protiviti partnered with a G-SIFI to design and implement a third-party risk management (TPRM) programme in alignment with global regulatory standards with an additional goal of aligning programme development with available technologies within the client’s environment. The company’s current TPRM programme relied heavily on manual processes, data collection, and reporting which limited reporting on the overall programme – status, risks, and performance. Protiviti completed a pilot of the inherent risk questionnaire across ~300 engagements to confirm scoring logic and approach and aligned the TPRM programme to the revised issue management standard and procedures. In the end, enhanced risk assessment methodologies that align with regulatory expectations across the client’s global locations were implemented and due diligence methodologies and templates that provide more consistent results across subject matter areas were provided by Protiviti.

A major U.S.-based manufacturer of technology products realisd its success was outpacing its capabilities in two key areas: sales, inventory and operations planning (SIOP) and warehouse management. The company’s foremost goal in SIOP was to increase top-line revenue by being more responsive to growth in demand. Protiviti conducted a comprehensive assessment of the organisation’s capabilities, analysed process metrics and researched emerging functionalities that could significantly upgrade SIOP capabilities. The result was a detailed list of recommendations that included: redesigned workflow and stakeholder engagement, better definition of the roles and responsibilities of key personnel, improved data flow among departments, substantially increased automation, and new metrics to improve visibility and accountability. Protiviti worked closely with IT and warehouse personnel to document business requirements for the D365 warehouse management system. The collaboration led the firm to redesign and update processes to account for both current and future workflows.

A large global financial institution requested a transformation of its third-party risk management programme and wanted to identify opportunities for enhancement. Protiviti designed and implemented an automated TPRM programme, including an operating model, policies, frameworks, procedures, and enabling technology. The Protiviti team improved and streamlined processes throughout the third-party management function that provided deeper insight into performance, risk and compliance for the bank.