A complete third-party risk management system — from vendor identification and due diligence through residual-risk assessment, continuous monitoring, audit and offboarding — informed by ISO/IEC 27036, ISO 31000:2018 and NIST SP 800-161 Rev. 1.
Overview
Most organisations now run on other organisations: cloud platforms, SaaS providers, outsourced processors, critical suppliers. Regulators and certification auditors have followed the risk outward — ISO/IEC 27001:2022 sharpened its supplier controls (Annex A 5.19–5.22), ISO 22301:2019 expects continuity across outsourced activities, and NIST SP 800-161 Rev. 1 (updated 2024) sets the reference for supply-chain risk practice. What most vendor programmes actually run on, though, is a spreadsheet of contract dates and a backlog of unanswered questionnaires.
This toolkit documents a proprietary AGS framework informed by ISO 31000:2018, ISO/IEC 27036 Parts 1–3, ISO/IEC 27001:2022, ISO 22301:2019, ISO 19011:2026, NIST SP 800-161 Rev. 1, NIST SP 1326 and NIST SP 800-18 Rev. 2. Its assessment methodology keeps inherent risk, control effectiveness and residual risk as separate quantities across fourteen risk domains, so that only residual risk drives decisions, while a twelve-factor weighted criticality model sets how deep each relationship's due diligence, assessment and monitoring regime must go. A reference and alignment matrix maps every system requirement to the source clauses — including the NIST SP 800-53 Rev. 5 SR control family — together with the evidence each control produces. It is not an ISO standard and makes no certification claim; it is the documented machinery of a defensible programme.
What this system covers
The documentation is tiered the way a mature management system is: a system manual defines governance, scope and the lifecycle; policies state the mandatory rules and risk appetite; procedures define how each activity is executed, by whom, and with what records; forms, checklists and Excel registers capture the evidence that it happened. Guidance documents and training modules carry the reasoning, so the method survives staff turnover. The whole set follows one lifecycle: identify, classify, due diligence, assess, approve, onboard, monitor, audit, remediate, reassess, offboard.
- A fourteen-domain residual-risk engine with matching Excel calculators, registers and a KPI dashboard
- Specialist modules for cybersecurity assessment, data privacy, business continuity, due diligence, audit and remediation/CAPA
- Enhanced regimes for critical third parties, fourth-party and concentration risk — including AI and emerging-technology vendors
- Sector checklists for cloud, SaaS and IT service providers, plus a portable Third-Party Risk Passport for each vendor
Who it's for
Chief risk officers and heads of vendor management building or formalising a TPRM programme; CISOs and information security teams answering for supplier controls under ISO/IEC 27001:2022; procurement, compliance and resilience leads in regulated sectors; and internal auditors and consultancies deploying a complete, editable system across clients. It suits vendor estates from a few dozen relationships to several hundred — the criticality model is what keeps the effort proportionate.
By document type
Key documents
Need the complete document list for this toolkit? Request it — sent the same day. Want to check the quality first? Preview free sample documents.
Everything you get
Every toolkit gives you a full set of working documents for your standard, ready to edit and use.
Native Microsoft files. Add your logo and adapt every document to how you work.
Your full toolkit arrives as a ZIP the moment payment clears.
One purchase covers everyone in your organisation. No per-seat fees.
Built by people who run real audits, so the content matches what assessors check.
One payment, perpetual licence for your organisation. No subscriptions, no renewals.
Full refund if your files are faulty, incomplete or not as described and we can't put it right
From purchase to audit-ready
Buy & download instantly
Pay securely by card. Your ZIP download link appears immediately on the confirmation page and in your email.
Edit & brand as your own
Open the native Word & Excel files, add your logo and details, and adapt everything to your organisation.
Implement & get audit-ready
Roll out the manuals, procedures, forms and checklists to build a working, certification-ready system.
Frequently asked questions
What exactly do I receive?
A downloadable ZIP containing the full set of ready-to-use documents for this toolkit — manuals, procedures, forms, records, checklists, guidance and training material, all in editable Word and Excel format. The exact document count is shown at the top of this page.
Are the documents really editable?
Yes. Every file is native Microsoft Word or Excel — no locked PDFs. Add your logo, change wording, and tailor the content to your organisation. The toolkit is yours to keep and reuse.
Does this certify my organisation?
No. These are documentation toolkits aligned to the relevant standard to help you prepare. Certification itself is issued by an accredited certification body after their audit. Our toolkits give you a strong, audit-ready starting point.
How is it delivered?
Instantly and digitally. There's no physical shipment — you download the files right after payment and receive a backup link by email.
Do I get updates?
Yes. If we revise this toolkit, you're entitled to the updated version at no extra cost — just contact us with your order details.
What is your refund policy?
These are digital products, so once a toolkit has been downloaded we cannot take it back. If you have not downloaded yet, contact us and we will cancel the order and refund you in full. We also refund in full if the files are damaged, incomplete, or not what the product page described.
Tell us which scheme you work to. We will point you to the right toolkit.
