| Third-party inventory and tiering model | Establish scope and priorities | Vendor profile, data handled, service criticality, locations, access, subcontractors and inherent-risk tier | Procurement, risk, data and security teams |
| Assessment methodology | Create repeatable decisions | Scoring rules, evidence standards, control domains, approval criteria, exceptions and review frequency | Risk owners and governance teams |
| Vendor risk profiles | Document assessed exposure | Inherent risk, evidence, control findings, residual risk, assumptions, limitations and approval recommendation | Business owners and approvers |
| Data-flow and dependency map | Make exposure understandable | Systems, transfers, subprocessors, integrations, retention, deletion, backup and exit dependencies | Architecture, privacy and operations teams |
| Remediation and exception register | Drive action and accountability | Finding, priority, owner, due date, compensating control, escalation and acceptance status | Vendor owners, PMO and risk committees |
| Monitoring and reporting framework | Sustain oversight | Review cycles, trigger events, KRIs, evidence refresh, incidents, dashboards and committee reporting | Vendor management and leadership |