Appearance
Third-Party Risk
Where to find it: Third-Party Risk, then Third Parties (/third-party-risk).
Third-Party Risk Management in OrviQ rests on one structural decision that shapes everything else.
Party and engagement
| Third Party | Engagement | |
|---|---|---|
| Answers | Who | What |
| Holds | Legal identity, entity facts, posture, certifications | Criticality, classification, due diligence, approval, contract lifecycle |
| Risk rating | Never | Always |
| Reference | TP-YYYY-NNNN | ENG-YYYY-NNNN |
A third party does not have a risk rating
Risk lives on the engagement, never on the party.
One provider might host your core banking platform and also supply office stationery. Those are radically different risk propositions from the same legal entity. Rating the party would force you to pick one, and both answers would be wrong.
One party may carry many engagements at very different risk levels, each independently assessed, classified, approved and reviewed.
Articles
| Article | What it covers |
|---|---|
| Third Parties | The party register: entity facts, posture, certifications, offboarding |
| Engagements | The engagement register: criticality, contract dates, lifecycle |
| Assessments | Criticality determination, regulatory classification, risk assessment |
| TPRM Governance | Decisions, segregation of duties, reassessment, termination |
The chain
Everything is insert-only
Criticality determinations, regulatory classifications, risk assessments and engagement decisions are insert-only. A redetermination supersedes the previous row; nothing is ever overwritten.
The consequence is that the state of any engagement at any past instant is reconstructable — which is what a supervisor asks for when examining outsourcing governance.
No parallel registers
TPRM owns no separate risk register and no separate findings table. Enterprise risk exposure and due-diligence deficiencies are created in and linked to the same Enterprise Risk Register and Findings register every other module uses.
Approval and risk acceptance reuse the same organisational workflow layer as everything else.
Permissions and segregation
| Permission | Grants |
|---|---|
tprm.read | View parties, engagements, business services and registers |
tprm.manage | Create and edit parties and engagements, lifecycle metadata, contract dates, owner administration, termination, offboarding |
tprm.assess | Governed inherent-risk and control-effectiveness assessment |
tprm.classify | Propose and confirm regulatory classifications |
tprm.decide | Approve, conditionally approve, reject or record risk acceptance |
Administrative rights do not confer assessment authority
tprm.assess, tprm.classify and tprm.decide are never auto-granted. A Tenant Administrator holds tprm.manage — they can configure lifecycle dates, terminate and offboard — but cannot reassess, classify or make a risk decision.
That separation exists because those three are professional judgements, not administrative operations.
Requires the vendor_risk entitlement.
Related domains
- Risk & Remediation — where third-party risks and findings live
- Controls & Assurance — controls over outsourced arrangements
- Operational Resilience — third parties as service dependencies
- Audit & Oversight — third-party audit engagements