Skip to content

Third-Party Risk

Where to find it: Third-Party Risk, then Third Parties (/third-party-risk).

Third-Party Risk Management in OrviQ rests on one structural decision that shapes everything else.


Party and engagement

Third PartyEngagement
AnswersWhoWhat
HoldsLegal identity, entity facts, posture, certificationsCriticality, classification, due diligence, approval, contract lifecycle
Risk ratingNeverAlways
ReferenceTP-YYYY-NNNNENG-YYYY-NNNN

A third party does not have a risk rating

Risk lives on the engagement, never on the party.

One provider might host your core banking platform and also supply office stationery. Those are radically different risk propositions from the same legal entity. Rating the party would force you to pick one, and both answers would be wrong.

One party may carry many engagements at very different risk levels, each independently assessed, classified, approved and reviewed.


Articles

ArticleWhat it covers
Third PartiesThe party register: entity facts, posture, certifications, offboarding
EngagementsThe engagement register: criticality, contract dates, lifecycle
AssessmentsCriticality determination, regulatory classification, risk assessment
TPRM GovernanceDecisions, segregation of duties, reassessment, termination

The chain


Everything is insert-only

Criticality determinations, regulatory classifications, risk assessments and engagement decisions are insert-only. A redetermination supersedes the previous row; nothing is ever overwritten.

The consequence is that the state of any engagement at any past instant is reconstructable — which is what a supervisor asks for when examining outsourcing governance.


No parallel registers

TPRM owns no separate risk register and no separate findings table. Enterprise risk exposure and due-diligence deficiencies are created in and linked to the same Enterprise Risk Register and Findings register every other module uses.

Approval and risk acceptance reuse the same organisational workflow layer as everything else.


Permissions and segregation

PermissionGrants
tprm.readView parties, engagements, business services and registers
tprm.manageCreate and edit parties and engagements, lifecycle metadata, contract dates, owner administration, termination, offboarding
tprm.assessGoverned inherent-risk and control-effectiveness assessment
tprm.classifyPropose and confirm regulatory classifications
tprm.decideApprove, conditionally approve, reject or record risk acceptance

Administrative rights do not confer assessment authority

tprm.assess, tprm.classify and tprm.decide are never auto-granted. A Tenant Administrator holds tprm.manage — they can configure lifecycle dates, terminate and offboard — but cannot reassess, classify or make a risk decision.

That separation exists because those three are professional judgements, not administrative operations.

Requires the vendor_risk entitlement.


OrviQ Enterprise Governance, Risk & Compliance Platform