FALCON OAKS Establishing a secure connection
Senior-led GRC and audit readiness consulting
Third-Party Risk Management

Manage Vendor Risk Across the Full Third-Party Lifecycle

Falcon Oaks helps organizations identify, assess, contract for, monitor and report on the risks introduced by vendors, partners, cloud providers and other external dependencies—with a program designed to scale and stand up to audit or regulatory scrutiny.

The Challenge

Your Organization Keeps the Accountability — Even When a Third Party Delivers the Service

Third parties can improve speed, capability and efficiency, but they also extend your risk surface. A vendor outage, data breach, control failure or subcontractor issue can interrupt critical operations and create regulatory, financial and reputational consequences for your organization.

Falcon Oaks builds practical TPRM programs that apply the right level of diligence and oversight to each relationship. The objective is to understand criticality, apply proportionate controls and maintain defensible evidence throughout the lifecycle.

Third-Party Risk Management

What We Deliver

TPRM Framework and Policy

A clear program model covering governance, scope, roles, risk appetite, lifecycle activities, escalation and reporting.

Third-Party Inventory

A reliable source of truth for vendors, services, data access, critical dependencies, owners and contractual status.

Risk Segmentation and Tiering

A practical method for assigning diligence and monitoring based on criticality and risk.

Due-Diligence Process

Questionnaires, evidence requirements, review criteria, approvals and exception handling.

Contract Security Requirements

Criteria for security, privacy, notification, audit rights, resilience, subcontractors and exit.

Vendor Risk Register

Documented findings, treatment actions, owners, acceptance decisions and residual risk.

Ongoing Monitoring Model

Reassessment triggers, review frequencies, performance indicators and issue escalation.

Executive and Board Reporting

Reporting on critical vendors, concentration, overdue issues, incidents and emerging exposure.

Third-Party Risk Management

Designed for Proportionate Oversight

Critical Vendors

Enhanced diligence, stronger contracts, frequent monitoring, resilience review and senior oversight.

Elevated-Risk Vendors

Targeted security and privacy assessment, issue remediation and periodic reassessment.

Standard Vendors

Streamlined screening and baseline contractual requirements appropriate to exposure.

Low-Risk Suppliers

Efficient documentation and approval without unnecessary assessment burden.

Our Process

The TPRM Lifecycle

A structured, evidence-first path from discovery to sustainable execution.

01

Inventory and Classify

Identify third parties, services, data access, dependencies and business owners.

02

Assess Inherent Risk

Determine criticality and exposure before selecting the level of diligence.

03

Perform Due Diligence

Review security, privacy, resilience, compliance, financial and operational evidence.

04

Set Contract Controls

Address obligations, notification, audit rights, service levels, subcontractors and exit requirements.

05

Approve and Onboard

Document decisions, exceptions, accepted risk, required remediation and ownership.

06

Monitor and Reassess

Track performance, incidents, changes and control posture throughout the relationship.

07

Manage Exit

Address access removal, data return or destruction, continuity and transition risk.

Framework Alignment

Aligned to the requirements that matter

  • OSFI Guideline B-10 Third-Party Risk Management
  • OSFI Guideline B-13 technology and cyber risk expectations
  • NIST Cybersecurity Framework 2.0 supply-chain risk outcomes
  • ISO/IEC 27001 supplier relationship controls
  • SWIFT Customer Security Programme expectations
  • SOC 2 vendor and subservice organization considerations
  • Privacy, data-processing and sector-specific obligations
Who This Is For

Designed for organizations ready to act

  • Financial institutions and regulated organizations subject to third-party oversight expectations
  • Organizations with growing cloud, SaaS, outsourcing or data-processing ecosystems
  • Companies preparing for SOC 2, ISO 27001, customer review or regulatory examination
  • Teams relying on manual spreadsheets and inconsistent questionnaires
  • Organizations that cannot clearly identify critical vendors or accepted risk
  • Leadership teams seeking better visibility into concentration and supply-chain risk
Frequently Asked Questions

Clear answers before you begin

Speak with a senior Falcon Oaks advisor if your situation requires a more specific answer.

Do all vendors need the same questionnaire?

No. A mature program uses risk and criticality to determine the depth of diligence. Low-risk vendors should not receive the same assessment as a provider hosting sensitive data or supporting a critical operation.

Can you improve our existing TPRM program?

Yes. Falcon Oaks can assess governance, inventory quality, tiering, due diligence, contracts, monitoring, reporting and evidence, then prioritize improvements.

Do you review vendor security documentation?

Yes. Depending on scope, we can review questionnaires, SOC reports, ISO certificates, policies, penetration-test summaries, incident information and resilience evidence.

Can you align the program with OSFI B-10?

Yes. We can assess and design governance, lifecycle processes, risk-based tiering, due diligence, monitoring and reporting in the context of OSFI B-10 and related expectations.

Build Vendor Oversight You Can Defend

Whether you are creating a TPRM program or strengthening an existing one, Falcon Oaks will help you focus on the vendors, risks and controls that matter most.