Skip to content

Third Parties

Where to find it: Third-Party Risk, then Third Parties (/third-party-risk).

A Third Party (TP-YYYY-NNNN) is the record of an external organisation you have a relationship with. It answers who.


What lives on the party

FieldPurpose
Business referenceTP-YYYY-NNNN, immutable
Legal name and trading nameLegal identity
Registration detailsJurisdiction, registration number
Address and contactWhere and who
Entity typeThe nature of the organisation
CertificationsStandards certifications held, with validity
Security and resilience postureEntity-level facts about the organisation
Relationship ownerWho owns the relationship internally
StatusActive or offboarded

What does not live on the party

A party carries no risk rating and no criticality

Criticality, regulatory classification, due diligence outcome, risk assessment, approval status and contract dates all live on the engagement, never on the party.

The reason is simple. A cloud provider hosting your core banking platform and providing your marketing analytics is one legal entity and two entirely different risk propositions. A single party-level rating would have to be wrong about one of them.


Entity facts versus engagement facts

FactWhere it livesWhy
Certification heldPartyIt is a property of the organisation
Whether that certification covers this serviceEngagementCertification scope varies by service
Financial standingPartyAn entity-level attribute
Concentration exposureEngagementDepends on what you use them for
Data protection posturePartyOrganisational
Whether personal data is processed hereEngagementDepends on the arrangement

The pattern: general capability is a party fact; how it applies to a specific arrangement is an engagement fact.


Certifications

Recording certifications with their validity dates lets you see when assurance is about to lapse across your supplier base.

A certification is not assurance for your engagement

A certification held by a party covers a defined scope. It does not automatically cover the service you buy. Recording the certification is useful; confirming its scope covers your engagement is the assessment work.


Party offboarding

Offboarding is a separate, explicit, party-level action. Terminating one engagement never auto-offboards the party.

It is valid only once every engagement under that party is already terminated. Attempting it while an active engagement exists is blocked, with the blocking engagement identified.

The single explicit action and the "no active relationships remain" safety check are the same precondition, not alternatives.

Requires tprm.manage.


What is preserved after offboarding

Nothing is deleted. Assessments, classifications, questionnaire runs, decisions, findings and enterprise risk links all remain reachable.

An offboarded relationship is still an auditable historical record — which matters when an incident emerges relating to a supplier you stopped using eighteen months ago.


Permissions

ActionPermission
View parties and engagementstprm.read
Create and edit parties, offboardtprm.manage

Requires the vendor_risk entitlement.


Example

Third party TP-2026-0018 — a cloud infrastructure provider.

FieldValue
Entity typeTechnology service provider
CertificationsInformation security management certification, valid to December; service organisation control report, annual
Relationship ownerHead of Technology Sourcing
StatusActive

Engagements under this party:

EngagementServiceCriticality
ENG-2026-0041Core banking platform hostingCritical
ENG-2026-0042Development and test environmentsMedium
ENG-2026-0057Marketing analytics platformLow

Three engagements, three criticality tiers, three different due diligence depths, three different review cadences, three different approval authorities.

The certification recorded at party level is relevant to all three — but whether its scope covers each service is an engagement-level question, and for ENG-2026-0057 it turned out it did not.


Troubleshooting

"I cannot offboard a party." An engagement under it is still active. The blocking engagements are identified; terminate them first.

"Where do I set the risk rating?" On the engagement. Parties do not carry ratings.

"Third Parties is not visible." Requires the vendor_risk entitlement and tprm.read.


OrviQ Enterprise Governance, Risk & Compliance Platform