Appearance
Third-Party Assessments
Four distinct assessment records attach to an engagement. Each answers a different question, each is separately permissioned, and each is insert-only.
The four assessments
| Assessment | Question | Permission |
|---|---|---|
| Criticality determination | How much does the business depend on this? | tprm.assess |
| Regulatory classification | What does the regulator call this arrangement? | tprm.classify |
| Due diligence questionnaire | What did the provider tell us? | tprm.manage |
| Risk assessment | Given all of it, what is the residual exposure? | tprm.assess |
They are separate because they can legitimately disagree. An arrangement can be operationally low-criticality and regulatorily material, or business-critical and outside any regulatory outsourcing definition.
Criticality determination
Criticality answers how much the business depends on the arrangement — independently of what any regulator calls it.
Determinations record the tier, the methodology and rule version applied, the reasoning, who determined it and when. A determination can be overridden with a justification, and the override is recorded as such rather than replacing the derived value silently.
| State | Meaning |
|---|---|
active | The current determination |
superseded | Replaced by a later determination |
overridden | The derived tier was overridden with justification |
Criticality drives due diligence depth, review cadence and approval authority.
Regulatory classification
Classification answers what the applicable regulatory regime calls this arrangement — for example whether it constitutes material outsourcing, or an arrangement supporting a critical or important function.
Classification follows a propose then confirm flow:
| State | Meaning |
|---|---|
draft | Being prepared |
issued | Proposed |
under_review | Under review |
confirmed | Confirmed as the governing classification |
superseded | Replaced by a later classification |
Classification carries the framework code and rule version applied, so the basis of the classification is reconstructable even after the rules change.
Requires tprm.classify, which is never auto-granted.
Criticality and classification are not the same judgement
Your internal view of business criticality and the regulator's definition of materiality are different tests with different criteria. Recording them separately means you can hold both truthfully, and can explain the difference when asked.
Due diligence questionnaires
Questionnaire runs capture what the provider told you: their responses, the evidence they supplied, and the review of both.
| State | Meaning |
|---|---|
open | Issued, awaiting response |
responded | The provider has responded |
reviewed | Responses reviewed internally |
A questionnaire is provider testimony, not assurance. Its value is as an input to the risk assessment and as a record of what was represented to you.
Risk assessment
The risk assessment is the governed judgement: inherent risk, the effectiveness of controls (theirs and yours), and the resulting residual risk.
It draws on the criticality determination, the classification, the questionnaire responses and any independent assurance the provider has supplied.
Assessments are insert-only. A reassessment adds a new row; the previous assessment remains, so the trajectory of an arrangement's risk over time is visible.
Requires tprm.assess, which is never auto-granted.
Insert-only history
Nothing is ever overwritten
Every one of these four record types is insert-only. A redetermination, reclassification, new questionnaire run or reassessment supersedes its predecessor rather than replacing it.
This is what makes the question "what was our assessment of this arrangement in March 2025, and on what basis?" answerable rather than a matter of recollection.
Findings from due diligence
Deficiencies identified during due diligence are raised as canonical findings with the source Third-Party Risk, carrying the same status vocabulary and lifecycle as compliance findings.
They are not held in a TPRM-only issue log. The provider's remediation is tracked in the same place as everything else.
Permissions
| Action | Permission |
|---|---|
| View assessments and history | tprm.read |
| Run questionnaires, manage engagement data | tprm.manage |
| Determine criticality, assess risk, initiate reassessment | tprm.assess |
| Propose and confirm regulatory classification | tprm.classify |
Requires the vendor_risk entitlement.
Example
Engagement ENG-2026-0041 — Core banking platform hosting.
| Assessment | Outcome | Basis |
|---|---|---|
| Criticality determination | Critical | The service supports the core banking business service; an outage of more than four hours breaches the stated impact tolerance |
| Regulatory classification | Material outsourcing, confirmed | The arrangement supports a critical function under the applicable regime |
| Questionnaire run | Responded and reviewed | 84 questions; provider supplied a service organisation control report and a penetration test summary |
| Risk assessment | Inherent Critical, residual Medium | Provider controls independently assured; exit plan documented and tested; concentration exposure noted |
Findings raised: two.
FND-2026-0088— the provider's control report scope excludes the disaster recovery region used by this engagement.FND-2026-0089— the exit plan has not been tested since the arrangement's scope expanded.
Engagement decision: approved with conditions, the conditions being remediation of both findings within 90 days.
Note the sequence. The criticality determination is an internal business judgement. The classification is a regulatory test. The questionnaire is the provider's testimony. Only the risk assessment weighs all three — and it found a gap in the provider's own assurance that the questionnaire response did not disclose.
Troubleshooting
"I cannot record a criticality determination." Requires tprm.assess, which is not granted by administrative rights.
"A classification cannot be confirmed." Requires tprm.classify. Proposal and confirmation are the same permission but distinct states.
"An old assessment disappeared." It did not. It is superseded and remains in the history.
"Reassessment overwrote my previous assessment." It did not. Reassessment advances the review date; recording a new assessment adds a row.