Instant downloadAuditor-writtenSecure Stripe checkout
Third-Party Risk Documentation Pack – TPRM Templates to Pinterest (opens in a new window)

Third-Party Risk Documentation Pack – TPRM Templates

$99.00

86 editable templates – 66 Word documents and 20 Excel workbooks – organised on the vendor lifecycle every supervisor asks about. Instant download, Microsoft Office format, one payment.

30-Day Money-Back Guarantee
Instant Download After Purchase
Secure Checkout via Stripe
Written by Certified Auditors

Every supervisor that asks to see a vendor programme asks for the same five things in the same order: how you plan, how you check before signing, what the contract says, how you monitor, and how you get out. This third-party risk documentation set is organised on exactly that.

On this page:

One lifecycle, twelve regimes: why third-party risk documentation should not be rewritten per audit

The 2023 Interagency Guidance from the Federal Reserve, the FDIC and the OCC sets the lifecycle out in full. DORA Chapter V, the EBA outsourcing guidelines, PRA SS2/21 and the Financial Stability Board toolkit all follow the same shape. That is unusual and it is useful: a programme built on the lifecycle can be shown to a US bank examiner, a DORA supervisor, a SOC 2 auditor, a PCI DSS assessor or a data protection authority without being rebuilt for each.

What defeats most programmes is not the framework but the questionnaire. Teams write one, find it too long for small vendors, write a shorter one, and end up with two documents that drift apart until the answers cannot be compared.

This third-party risk documentation claims 188 requirement identifiers across 12 regimes, and the crosswalk workbook lists every one against the document that answers it – including all 90 considerations of the Interagency Guidance item by item, and the five NIST SP 800-53 supply chain controls that are out of scope listed as out of scope rather than quietly omitted.

What is inside the third-party risk documentation pack

The third-party risk documentation pack is 86 editable templates – 66 Word documents and 20 Excel workbooks – across 10 sections following the lifecycle.

  • Programme and governance – policy, standard, roles, risk appetite and the board reporting a supervisor expects to see.
  • Planning – the engagement case, the criticality and tiering criteria, and the decision record before anyone talks to a vendor.
  • Due diligence – three security questionnaires generated from one question bank so they cannot drift: Lite at 21 questions, Standard at 84, Enhanced at 136 across 20 control domains.
  • Scoring – evidence expected against every question, a mandatory flag on the ten questions where a zero is a finding whatever the total, reviewer columns and a domain score sheet.
  • Contracting – 32 provisions mapped clause by clause to the regime that requires each, with standard and critical-vendor columns.
  • Onboarding – the handover from assessment to operation, so the conditions of approval do not evaporate at signature.
  • Monitoring – performance and risk reviews, the reassessment cadence by tier, and the trigger events that force an off-cycle review.
  • Incidents and issues – vendor incident handling, findings management and escalation.
  • Exit and concentration – exit plans, stressed and non-stressed scenarios, and concentration analysis treated as a first-class register rather than a paragraph.
  • Registers – the vendor inventory, the register of information, the contract register and the crosswalk of all 188 identifiers.

third-party risk documentation - editable Word and Excel templates from iso-toolkits.com

The three questionnaires are the third-party risk documentation teams use daily

Lite is for a low-tier provider with limited data or access. Standard covers the core of a portfolio. Enhanced adds resilience, subcontracting, physical security, cloud, artificial intelligence and exit for critical providers. All three are generated from one bank, so a vendor that moves up a tier is asked a superset of what it already answered rather than a different set.

Each carries the evidence expected for every question, which is the part that turns a questionnaire from an opinion poll into an assessment. The mandatory flags matter too: ten questions where a zero is a finding regardless of the overall score, so a vendor cannot average its way past a missing control.

A scoring guide sits beside them so that two reviewers reading the same response reach the same score. Without it, third-party risk documentation produces numbers that cannot be compared across a portfolio, which is the failure mode nobody notices until the board asks for a trend.

Who the third-party risk documentation pack is written for

  • Banks, insurers and financial market infrastructures under the Interagency Guidance, DORA, the EBA guidelines or PRA SS2/21.
  • Any organisation whose customers or auditors ask how vendors are assessed – SOC 2, ISO 27001, PCI DSS, HIPAA or GDPR Article 28.
  • Procurement and risk teams building a programme from scratch, or replacing a spreadsheet that has outgrown itself.
  • Consultancies standing up vendor programmes for clients who need the regime mapping to be checkable.

What the third-party risk documentation pack does not do

It does not assess your vendors. It gives you the questionnaires, the scoring method and the registers; running the assessments is your work.

It is not a procurement or GRC platform, and it does not integrate with one. Several clients use it as the content layer inside a platform they already own.

It does not supply legal contract language for your jurisdiction. The contract requirements checklist states what each provision has to achieve and which regime requires it; drafting to local law is a lawyer task.

Frequently asked questions

Which regimes are mapped?

Twelve: the 2023 Interagency Guidance, NIST CSF 2.0 GV.SC, NIST SP 800-53 Rev 5, ISO/IEC 27001 Annex A 5.19 to 5.23, DORA Articles 28 to 30, NIS2 Article 21, SOC 2 CC9.2, PCI DSS v4.0.1, GDPR Article 28, the HIPAA business associate rules, 23 NYCRR 500.11 and EBA/GL/2019/02.

We are not a financial institution. Is this still relevant?

Yes. The lifecycle is the same and the mapping includes ISO 27001, SOC 2, PCI DSS and GDPR. The banking-specific documents are marked so you can leave them out.

Does it cover DORA register of information?

Yes, as one of the registers, alongside the vendor inventory and contract register.

What formats are the files in?

Native Microsoft Word and Excel, fully editable, with placeholders marked throughout.

It pairs naturally with the DORA toolkit for EU financial entities, the ISO 27001 toolkit for the Annex A supplier controls, and the SOC 2 toolkit where customers ask for an attestation. The Interagency Guidance is published in the Federal Register.

Implementing for clients? The Consultant Package licenses all 86 toolkits and assessment tools on this site for unlimited client engagements, under one firm-wide licence. One payment of $1,399, no subscription and no per-client fee.

Delivery, format and licence

The third-party risk documentation pack downloads immediately after checkout as native Microsoft Word and Excel files. Nothing is locked, nothing is a PDF you cannot edit, and no add-on or portal login is needed to open it. Every organisation-specific value is marked as a placeholder so you can see what still has to be decided.

One payment, no subscription and no annual renewal. The source files behind the third-party risk documentation pack are yours to adapt for your own organisation for as long as you need them, including future revisions of your own documents.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Shopping Cart