Third-Party Risk Management Template

Standardize how your team handles every third-party assessment. The template ships with 6 stages, 8 fields and 4 automations you can adjust in minutes.

Stages
6
Fields
8
Automations
4
Setup
15 minutes

Quick answer

The Third-Party Risk Management template is a pre-built compliance & risk workflow used to run a proportionate, repeatable risk process across the whole third-party population. It runs across 6 stages, from assessment initiated to approved and monitored, captures 8 standard fields including third party and controls assessed, and applies 4 automations so routing, checks and record-keeping happen without manual chasing.

Inside the Third-Party Risk Management template

The Third-Party Risk Management template turns an informal process into a structured one. Instead of tracking each third-party assessment across email, spreadsheets and chat, every request enters one workflow with 8 fields captured at submission, 6 stages that make the current status obvious, and approval routing that reaches the compliance officer automatically. risk managers get a single view of what is open, what is waiting and what is closed. The template is built for compliance teams in financial services and connects to ServiceNow and SharePoint, so records stay aligned with the systems finance already relies on.

The problem it solves. Third-party risk is assessed at onboarding and never revisited, so the risk picture ages badly. Putting the process in Zapro means the information is captured once and stays current for everyone who needs it.

The 6 stages in this template

Every third-party assessment follows the same 6 stages, so anyone can see where a record is without asking. Stages, owners and exit conditions are configurable if your policy differs.

  1. Assessment initiated

    The third-party assessment is triggered at onboarding, at renewal, or whenever the risk tier of the relationship changes.

  2. Questionnaire issued

    The right questionnaire is issued based on category, data access and spend, so low-risk suppliers are not over-assessed.

  3. Evidence review

    Certificates, policies and responses are reviewed against the control set and stored against the vendor record.

  4. Risk scoring

    Scores are calculated per domain and rolled into a single tier that everyone reads the same way.

  5. Mitigation plan

    Findings get owners, due dates and agreed controls rather than sitting in a closed report.

  6. Approved and monitored

    The compliance officer approves the residual risk and Zapro schedules the next review automatically.

Every field the Third-Party Risk Management template captures

These 8 fields are pre-configured on the intake form. Mandatory rules, picklists and validation are already applied, so a third-party assessment cannot progress with gaps in it.

  • Third party
  • Service criticality
  • Data access level
  • Inherent risk
  • Controls assessed
  • Residual risk
  • Owner
  • Next review

Automations that ship with this template

Inherent risk scoring at intake

It triggers the moment the condition is met, so nothing waits on someone noticing it first.

Control assessment depth driven by criticality

This runs as a built-in rule, which removes the follow-up chasing that usually surrounds it.

Residual risk approval by the risk owner

Zapro applies this to every third-party assessment as it enters the workflow, so nobody has to remember to do it.

Automatic review scheduling by tier

Configured once during setup, then enforced consistently on every record without further effort.

What changes once the Third-Party Risk Management template is running

  • Risk assessments are proportionate to the exposure
  • Evidence is stored against the vendor, not in a shared drive
  • Re-assessment happens on schedule automatically
  • Regulators and auditors get a complete trail on request
  • The team can run a proportionate, repeatable risk process across the whole third-party population from a single record

Manual process versus the Third-Party Risk Management template

AspectManual processWith the Zapro template
Third-party assessment handlingThird-party risk is assessed at onboarding and never revisited, so the risk picture ages badlyOne workflow that helps you run a proportionate, repeatable risk process across the whole third-party population
Audit readinessEvidence reassembled from mailboxes at audit timeComplete trail generated as the work happens
Cycle timeDepends on who is chasing this weekPredictable, with reminders and escalation built in
Status visibilityChase people on email or Slack to find out where it isLive status on every record, visible to requester and approver
ApprovalsForwarded emails with no record of who approved whatRules-based routing with a time-stamped approval trail

Systems this template connects to

This template is designed to run alongside your finance and operations stack rather than beside it, so records stay consistent in both places.

  • ServiceNow
  • SharePoint
  • Zapro Vendor Master
  • Slack
  • Microsoft Teams
  • Zapro Supplier Portal

Guides that go with this template

Third-Party Risk Management template FAQs

What is the Third-Party Risk Management template?

It is a pre-built compliance & risk workflow in Zapro that lets compliance teams run a proportionate, repeatable risk process across the whole third-party population. Each third-party assessment is captured on an 8-field form, moves through 6 stages with a named owner at each step, and is supported by 4 automations covering routing, validation and record updates.

How long does the Third-Party Risk Management template take to set up?

Most teams have it running in about 15 minutes. The stages, fields and automations are already configured, so setup is mainly adjusting approval thresholds, field labels and owner assignments to match your own policy.

Who uses the Third-Party Risk Management template?

Primarily risk managers, working with compliance officers and legal counsel. It is most commonly used by compliance teams in financial services, though the workflow itself is not sector-specific.

Can assessment depth vary by supplier tier?

Yes. Questionnaire length and evidence requirements are driven by risk tier, so low-risk suppliers are not put through an enterprise-grade assessment.

Is re-assessment automatic?

Yes. Zapro schedules the next assessment based on tier and last review date, and raises it without anyone tracking dates manually.

Start with the Third-Party Risk Management template

Zapro ships with this template plus the rest of the procurement and vendor management suite. Start with the third-party assessment process and expand into sourcing, contracts, invoices and spend when you are ready.