Appearance
Third Parties
Where to find it: Third-Party Risk, then Third Parties (/third-party-risk).
A Third Party (TP-YYYY-NNNN) is the record of an external organisation you have a relationship with. It answers who.
What lives on the party
| Field | Purpose |
|---|---|
| Business reference | TP-YYYY-NNNN, immutable |
| Legal name and trading name | Legal identity |
| Registration details | Jurisdiction, registration number |
| Address and contact | Where and who |
| Entity type | The nature of the organisation |
| Certifications | Standards certifications held, with validity |
| Security and resilience posture | Entity-level facts about the organisation |
| Relationship owner | Who owns the relationship internally |
| Status | Active or offboarded |
What does not live on the party
A party carries no risk rating and no criticality
Criticality, regulatory classification, due diligence outcome, risk assessment, approval status and contract dates all live on the engagement, never on the party.
The reason is simple. A cloud provider hosting your core banking platform and providing your marketing analytics is one legal entity and two entirely different risk propositions. A single party-level rating would have to be wrong about one of them.
Entity facts versus engagement facts
| Fact | Where it lives | Why |
|---|---|---|
| Certification held | Party | It is a property of the organisation |
| Whether that certification covers this service | Engagement | Certification scope varies by service |
| Financial standing | Party | An entity-level attribute |
| Concentration exposure | Engagement | Depends on what you use them for |
| Data protection posture | Party | Organisational |
| Whether personal data is processed here | Engagement | Depends on the arrangement |
The pattern: general capability is a party fact; how it applies to a specific arrangement is an engagement fact.
Certifications
Recording certifications with their validity dates lets you see when assurance is about to lapse across your supplier base.
A certification is not assurance for your engagement
A certification held by a party covers a defined scope. It does not automatically cover the service you buy. Recording the certification is useful; confirming its scope covers your engagement is the assessment work.
Party offboarding
Offboarding is a separate, explicit, party-level action. Terminating one engagement never auto-offboards the party.
It is valid only once every engagement under that party is already terminated. Attempting it while an active engagement exists is blocked, with the blocking engagement identified.
The single explicit action and the "no active relationships remain" safety check are the same precondition, not alternatives.
Requires tprm.manage.
What is preserved after offboarding
Nothing is deleted. Assessments, classifications, questionnaire runs, decisions, findings and enterprise risk links all remain reachable.
An offboarded relationship is still an auditable historical record — which matters when an incident emerges relating to a supplier you stopped using eighteen months ago.
Permissions
| Action | Permission |
|---|---|
| View parties and engagements | tprm.read |
| Create and edit parties, offboard | tprm.manage |
Requires the vendor_risk entitlement.
Example
Third party TP-2026-0018 — a cloud infrastructure provider.
| Field | Value |
|---|---|
| Entity type | Technology service provider |
| Certifications | Information security management certification, valid to December; service organisation control report, annual |
| Relationship owner | Head of Technology Sourcing |
| Status | Active |
Engagements under this party:
| Engagement | Service | Criticality |
|---|---|---|
ENG-2026-0041 | Core banking platform hosting | Critical |
ENG-2026-0042 | Development and test environments | Medium |
ENG-2026-0057 | Marketing analytics platform | Low |
Three engagements, three criticality tiers, three different due diligence depths, three different review cadences, three different approval authorities.
The certification recorded at party level is relevant to all three — but whether its scope covers each service is an engagement-level question, and for ENG-2026-0057 it turned out it did not.
Troubleshooting
"I cannot offboard a party." An engagement under it is still active. The blocking engagements are identified; terminate them first.
"Where do I set the risk rating?" On the engagement. Parties do not carry ratings.
"Third Parties is not visible." Requires the vendor_risk entitlement and tprm.read.