| Date | Venue | Fees | |
|---|---|---|---|
| 26 - 30 Oct 2026 | London - UK | $ 7,500 | |
| 19 - 23 Apr 2027 | London - UK | $ 7,500 | |
| 25 - 29 Oct 2027 | London - UK | $ 7,500 |
Introduction
This Third-Party Risk Management (TPRM) training course provides professionals with a structured approach to identifying, assessing, governing and monitoring risks arising from suppliers, vendors, service providers, technology partners and other external relationships. As organisations become increasingly dependent on outsourcing, cloud services, SaaS providers and complex supply chains, third-party failures can create significant operational, financial, cyber, regulatory and reputational exposure. Effective TPRM therefore requires coordinated governance extending from initial due diligence and contracting through continuous monitoring, assurance and eventual exit.
The training course examines the complete third-party risk lifecycle through a risk-based and practical perspective. Participants will explore governance and accountability, supplier classification, due diligence, contractual controls, cyber and technology exposure, fourth-party dependencies, supply chain resilience, ESG considerations and geopolitical risk. The training course also addresses emerging challenges including AI vendors, digital concentration risk and evolving regulatory expectations. Participants will ultimately develop the capability to establish proportionate controls, strengthen third-party resilience and build a more mature TPRM framework.
This GLOMACS Third-Party Risk Management (TPRM) training course will highlight:
- Establishing effective governance and accountability for third-party risk
- Applying risk-based due diligence, onboarding and supplier classification
- Managing cyber, cloud, SaaS, AI and fourth-party exposures
- Strengthening supply chain resilience against operational and geopolitical disruption
- Integrating ESG and responsible-sourcing considerations into third-party oversight
- Developing continuous monitoring, assurance and executive reporting capabilities
Objectives
By the end of this Third-Party Risk Management (TPRM) training course, participants will be able to:
- Establish a risk-based TPRM governance framework aligned with enterprise risk management.
- Apply proportionate due diligence, supplier tiering and onboarding methodologies.
- Assess cyber, technology, cloud, AI and fourth-party risks across the extended enterprise.
- Evaluate supply chain, ESG, geopolitical and concentration risks.
- Implement continuous monitoring, assurance and third-party performance oversight.
- Develop executive reporting and a practical roadmap for improving TPRM maturity.
Training Methodology
This Third-Party Risk Management (TPRM) training course combines expert-led presentations, structured discussions, third-party risk scenarios, due diligence applications, supplier assessment examples and practical case studies. Participants will examine vendor classification, risk assessment, cyber exposure, supply chain dependencies, contractual controls, monitoring indicators and assurance approaches. Emphasis is placed on applying proportionate controls according to the criticality and risk profile of individual third-party relationships.
Organisational Impact
Organisations will benefit from:
- Stronger governance and accountability across third-party relationships.
- More consistent and risk-based supplier due diligence.
- Improved visibility of critical vendor and fourth-party dependencies.
- Greater resilience against cyber, operational and supply chain disruption.
- Stronger monitoring and assurance throughout the third-party lifecycle.
- Improved executive oversight of material third-party exposures.
Personal Impact
Participants will develop:
- Stronger understanding of the complete third-party risk lifecycle.
- Practical capability in vendor risk assessment and due diligence.
- Greater awareness of cyber, cloud, AI and digital supply chain risks.
- Improved ability to assess supplier resilience and concentration exposure.
- Stronger third-party monitoring, assurance and reporting capabilities.
- Greater confidence in developing and improving organisational TPRM frameworks.
Who should Attend?
This GLOMACS Third-Party Risk Management (TPRM) training course is suitable for professionals responsible for managing, assessing or overseeing risks associated with suppliers, vendors and other external relationships, including:
- Third-Party Risk Managers
- Enterprise Risk Managers
- Vendor and Supplier Risk Professionals
- Procurement and Supply Chain Managers
- Operational Risk Professionals
- Compliance Professionals
- Information Security and Cyber Risk Professionals
- Technology Risk Managers
- Business Continuity and Resilience Professionals
- Internal Auditors
- Contract and Commercial Managers
- Governance and Assurance Professionals
Building the Foundations of Third-Party Governance
- Outsourcing, cloud and SaaS are reshaping third-party risk
- Embedding TPRM into ERM and the Three Lines Model
- Governance structures with clear accountability and ownership
- Setting risk appetite for supplier relationships
- Board oversight of the extended enterprise
- Navigating DORA and sector-specific regulations
Due Diligence, Onboarding and Governing the Supplier Base
- Screening and onboarding vendors before contract award
- Risk-proportionate due diligence frameworks
- Tiering suppliers by risk exposure
- Operational risk across the vendor lifecycle
- Evaluating supplier financial health and viability
- Embedding risk clauses into contracts and SLAs
Managing Cyber, Technology and Digital Supply Chain Risk
- Cyber risk frameworks — ISO/IEC 27036, NIST SP 800-161
- Cybersecurity due diligence questionnaires
- Cloud and SaaS shared-responsibility risk models
- ICT concentration and fourth-party exposure
- AI vendor risk — data governance and model assurance
- Coordinated incident response and resilience testing
Supply Chain Resilience, ESG and Geopolitical Exposure
- Mapping single points of failure and dependencies
- Diversified sourcing and contingency planning
- ESG risk frameworks across the supplier base
- Modern slavery and responsible-sourcing due diligence
- Geopolitical, sanctions and country-risk evaluation
- Scenario planning for supply chain disruption
Monitoring, Assurance, Reporting and Long-Term Maturity
- Continuous monitoring built on Key Risk Indicators
- Tracking vendor performance and SLA compliance
- Third-party audits and independent assurance
- Executive and board risk dashboards
- Managing vendor offboarding and exit planning
- Roadmap for continuous TPRM maturity
- Upon successful completion of this training course, GLOMACS Certificate will be awarded to the delegates. Continuing Professional Education credits (CPE): In accordance with the standards of the National Registry of CPE Sponsors, one CPE credit is granted per 50 minutes of attendance
Endorsed Education Provider