Skip to content

Third-Party Assessments

Four distinct assessment records attach to an engagement. Each answers a different question, each is separately permissioned, and each is insert-only.


The four assessments

AssessmentQuestionPermission
Criticality determinationHow much does the business depend on this?tprm.assess
Regulatory classificationWhat does the regulator call this arrangement?tprm.classify
Due diligence questionnaireWhat did the provider tell us?tprm.manage
Risk assessmentGiven all of it, what is the residual exposure?tprm.assess

They are separate because they can legitimately disagree. An arrangement can be operationally low-criticality and regulatorily material, or business-critical and outside any regulatory outsourcing definition.


Criticality determination

Criticality answers how much the business depends on the arrangement — independently of what any regulator calls it.

Determinations record the tier, the methodology and rule version applied, the reasoning, who determined it and when. A determination can be overridden with a justification, and the override is recorded as such rather than replacing the derived value silently.

StateMeaning
activeThe current determination
supersededReplaced by a later determination
overriddenThe derived tier was overridden with justification

Criticality drives due diligence depth, review cadence and approval authority.


Regulatory classification

Classification answers what the applicable regulatory regime calls this arrangement — for example whether it constitutes material outsourcing, or an arrangement supporting a critical or important function.

Classification follows a propose then confirm flow:

StateMeaning
draftBeing prepared
issuedProposed
under_reviewUnder review
confirmedConfirmed as the governing classification
supersededReplaced by a later classification

Classification carries the framework code and rule version applied, so the basis of the classification is reconstructable even after the rules change.

Requires tprm.classify, which is never auto-granted.

Criticality and classification are not the same judgement

Your internal view of business criticality and the regulator's definition of materiality are different tests with different criteria. Recording them separately means you can hold both truthfully, and can explain the difference when asked.


Due diligence questionnaires

Questionnaire runs capture what the provider told you: their responses, the evidence they supplied, and the review of both.

StateMeaning
openIssued, awaiting response
respondedThe provider has responded
reviewedResponses reviewed internally

A questionnaire is provider testimony, not assurance. Its value is as an input to the risk assessment and as a record of what was represented to you.


Risk assessment

The risk assessment is the governed judgement: inherent risk, the effectiveness of controls (theirs and yours), and the resulting residual risk.

It draws on the criticality determination, the classification, the questionnaire responses and any independent assurance the provider has supplied.

Assessments are insert-only. A reassessment adds a new row; the previous assessment remains, so the trajectory of an arrangement's risk over time is visible.

Requires tprm.assess, which is never auto-granted.


Insert-only history

Nothing is ever overwritten

Every one of these four record types is insert-only. A redetermination, reclassification, new questionnaire run or reassessment supersedes its predecessor rather than replacing it.

This is what makes the question "what was our assessment of this arrangement in March 2025, and on what basis?" answerable rather than a matter of recollection.


Findings from due diligence

Deficiencies identified during due diligence are raised as canonical findings with the source Third-Party Risk, carrying the same status vocabulary and lifecycle as compliance findings.

They are not held in a TPRM-only issue log. The provider's remediation is tracked in the same place as everything else.


Permissions

ActionPermission
View assessments and historytprm.read
Run questionnaires, manage engagement datatprm.manage
Determine criticality, assess risk, initiate reassessmenttprm.assess
Propose and confirm regulatory classificationtprm.classify

Requires the vendor_risk entitlement.


Example

Engagement ENG-2026-0041 — Core banking platform hosting.

AssessmentOutcomeBasis
Criticality determinationCriticalThe service supports the core banking business service; an outage of more than four hours breaches the stated impact tolerance
Regulatory classificationMaterial outsourcing, confirmedThe arrangement supports a critical function under the applicable regime
Questionnaire runResponded and reviewed84 questions; provider supplied a service organisation control report and a penetration test summary
Risk assessmentInherent Critical, residual MediumProvider controls independently assured; exit plan documented and tested; concentration exposure noted

Findings raised: two.

  • FND-2026-0088 — the provider's control report scope excludes the disaster recovery region used by this engagement.
  • FND-2026-0089 — the exit plan has not been tested since the arrangement's scope expanded.

Engagement decision: approved with conditions, the conditions being remediation of both findings within 90 days.

Note the sequence. The criticality determination is an internal business judgement. The classification is a regulatory test. The questionnaire is the provider's testimony. Only the risk assessment weighs all three — and it found a gap in the provider's own assurance that the questionnaire response did not disclose.


Troubleshooting

"I cannot record a criticality determination." Requires tprm.assess, which is not granted by administrative rights.

"A classification cannot be confirmed." Requires tprm.classify. Proposal and confirmation are the same permission but distinct states.

"An old assessment disappeared." It did not. It is superseded and remains in the history.

"Reassessment overwrote my previous assessment." It did not. Reassessment advances the review date; recording a new assessment adds a row.


OrviQ Enterprise Governance, Risk & Compliance Platform