← Help Center

TPRM Glossary

Plain-English definitions of the third-party risk management terms you'll run into — from inherent risk to FAIR.

Annual Loss Expectancy (ALE)
The expected cost of a risk over a year, calculated as loss event frequency × loss magnitude. It is a core output of quantitative risk models like FAIR and lets teams compare vendor risk in dollars rather than colors.
Attestation
A formal, independent statement that an organization meets a standard or that its controls operate as described — for example, a SOC 2 report signed by an auditor. Stronger evidence than a vendor's own self-assessment.
Bridge letter (gap letter)
A short statement from a vendor covering the period between the end date of a SOC 2 report and today, affirming that no material changes occurred. It is a stopgap, not a substitute for a current audited report.
CMMC (Cybersecurity Maturity Model Certification)
A U.S. Department of Defense framework that requires defense contractors — and their subcontractors — to meet defined cybersecurity levels in order to handle Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).
Concentration risk
The risk that many of your vendors rely on the same underlying provider (a shared fourth party), so a single outage or breach at that provider cascades across your supply chain at once.
Continuous monitoring
Ongoing surveillance of a vendor's risk signals — breach and fraud news, security posture, financial health — between formal assessments, rather than relying only on a point-in-time review.
Control effectiveness
How well a vendor's security controls actually reduce risk, usually expressed as a score derived from an assessment. It is distinct from whether a control merely exists on paper.
Controlled Unclassified Information (CUI)
Sensitive but unclassified U.S. government information that requires safeguarding under specific rules. Handling CUI is central to CMMC Level 2 requirements.
Data classification
Categorizing the types of data a vendor will handle — for example public, internal, confidential, or PII — by sensitivity, so you can gauge the impact a breach at that vendor would have.
Due diligence
The investigation of a vendor's security, privacy, financial, and operational risk before signing and throughout the relationship. Modern due diligence favors reviewing real evidence over sending long questionnaires.
Exception (risk acceptance)
A documented, time-bound decision to accept a known gap or risk rather than remediate it now, recorded with a reason, an owner, and a review date so it is auditable instead of forgotten.
FAIR (Factor Analysis of Information Risk)
A standard model for quantifying information risk in financial terms. Its core equation is Risk = Loss Event Frequency × Loss Magnitude, producing an annualized dollar figure for a given risk.
Fourth party
A vendor's own vendors. Your fourth parties are the subprocessors and providers your third parties depend on — a common source of hidden, cascading risk.
Inherent risk
The risk a vendor poses before any of their controls are taken into account, based on the data, access, and business dependency involved. It is the starting point for deciding how much scrutiny a vendor needs.
ISO 27001
An international standard for an information security management system (ISMS). Certification signals that a vendor runs a formally scoped, independently audited security program.
Loss Event Frequency (LEF)
In FAIR, how often a loss is expected to occur in a year — the product of threat event frequency and vulnerability. Controls generally reduce frequency rather than the size of a loss.
Loss Magnitude
In FAIR, the financial impact of a single loss event. Inherent risk (the data and access at stake) tends to drive magnitude, while controls drive how often losses happen.
Penetration test (pen test)
An authorized, simulated attack on a system to find exploitable weaknesses. A pen test summary is a common piece of vendor security evidence.
Personally Identifiable Information (PII)
Data that can identify an individual — name, Social Security number, email, and similar. A vendor handling PII carries higher risk and additional regulatory obligations (GDPR, CCPA, HIPAA, and others).
Remediation
The work a vendor performs to fix an identified security gap, often tracked against a deadline defined by a service-level agreement (SLA).
Residual risk
The risk that remains after a vendor's controls are taken into account — inherent risk reduced by control effectiveness. It reflects how bad things are likely to be given how well the vendor actually protects itself.
Right to audit
A contract clause that lets a customer inspect or audit a vendor's security controls, either directly or through an independent assessor.
Security questionnaire
A structured set of questions sent to a vendor to assess its security posture — for example the SIG or CAIQ. Increasingly supplemented, or replaced, by reviewing a vendor's existing audited evidence.
SOC 2
An AICPA audit report on a service organization's controls across the Trust Services Criteria. A Type 1 report assesses control design at a single point in time; a Type 2 report tests operating effectiveness over a period (typically 3–12 months) and is the stronger signal.
Subprocessor
A third party a vendor uses to process data on its behalf — for example their cloud host or an email provider. From your perspective, a vendor's subprocessors are your fourth parties.
Third-Party Risk Management (TPRM)
The practice of identifying, assessing, and monitoring the risks introduced by external vendors, suppliers, and partners across the entire relationship lifecycle — from onboarding through offboarding.
Trust Services Criteria (TSC)
The five categories a SOC 2 report can cover: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Reading which criteria a report includes tells you what it actually assessed.
Two-axis risk framework
A way of viewing vendor risk on two axes at once: how much damage a vendor could do (inherent risk) and how well they protect against it (control posture). It keeps high-impact, weakly-controlled vendors from hiding behind a single score.
Unavailability impact (business impact)
How much a vendor's outage would disrupt your operations. Along with data sensitivity and volume, it is a key input to a vendor's inherent risk and criticality.
Vendor evidence
The documents a vendor already produces to demonstrate its security — SOC 2 reports, ISO 27001 certificates, policies, pen test summaries, and prior questionnaires. Reviewing evidence is faster and more reliable than re-asking every question.
Vendor tiering (criticality)
Grouping vendors by risk and importance — for example critical, high, medium, or low — so that oversight effort, review depth, and reassessment frequency match each vendor's actual exposure.
Vulnerability
In FAIR, the probability that a threat event turns into an actual loss event. More broadly, a weakness in a system or process that an attacker could exploit.

Want to see these in action?

Docubark turns this vocabulary into an AI-native third-party risk program.