TPRM Glossary
Plain-English definitions of the third-party risk management terms you'll run into — from inherent risk to FAIR.
- Annual Loss Expectancy (ALE)
- The expected cost of a risk over a year, calculated as loss event frequency × loss magnitude. It is a core output of quantitative risk models like FAIR and lets teams compare vendor risk in dollars rather than colors.
- Attestation
- A formal, independent statement that an organization meets a standard or that its controls operate as described — for example, a SOC 2 report signed by an auditor. Stronger evidence than a vendor's own self-assessment.
- Bridge letter (gap letter)
- A short statement from a vendor covering the period between the end date of a SOC 2 report and today, affirming that no material changes occurred. It is a stopgap, not a substitute for a current audited report.
- CMMC (Cybersecurity Maturity Model Certification)
- A U.S. Department of Defense framework that requires defense contractors — and their subcontractors — to meet defined cybersecurity levels in order to handle Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).
- Concentration risk
- The risk that many of your vendors rely on the same underlying provider (a shared fourth party), so a single outage or breach at that provider cascades across your supply chain at once.
- Continuous monitoring
- Ongoing surveillance of a vendor's risk signals — breach and fraud news, security posture, financial health — between formal assessments, rather than relying only on a point-in-time review.
- Control effectiveness
- How well a vendor's security controls actually reduce risk, usually expressed as a score derived from an assessment. It is distinct from whether a control merely exists on paper.
- Controlled Unclassified Information (CUI)
- Sensitive but unclassified U.S. government information that requires safeguarding under specific rules. Handling CUI is central to CMMC Level 2 requirements.
- Data classification
- Categorizing the types of data a vendor will handle — for example public, internal, confidential, or PII — by sensitivity, so you can gauge the impact a breach at that vendor would have.
- Due diligence
- The investigation of a vendor's security, privacy, financial, and operational risk before signing and throughout the relationship. Modern due diligence favors reviewing real evidence over sending long questionnaires.
- Exception (risk acceptance)
- A documented, time-bound decision to accept a known gap or risk rather than remediate it now, recorded with a reason, an owner, and a review date so it is auditable instead of forgotten.
- FAIR (Factor Analysis of Information Risk)
- A standard model for quantifying information risk in financial terms. Its core equation is Risk = Loss Event Frequency × Loss Magnitude, producing an annualized dollar figure for a given risk.
- Fourth party
- A vendor's own vendors. Your fourth parties are the subprocessors and providers your third parties depend on — a common source of hidden, cascading risk.
- Inherent risk
- The risk a vendor poses before any of their controls are taken into account, based on the data, access, and business dependency involved. It is the starting point for deciding how much scrutiny a vendor needs.
- ISO 27001
- An international standard for an information security management system (ISMS). Certification signals that a vendor runs a formally scoped, independently audited security program.
- Loss Event Frequency (LEF)
- In FAIR, how often a loss is expected to occur in a year — the product of threat event frequency and vulnerability. Controls generally reduce frequency rather than the size of a loss.
- Loss Magnitude
- In FAIR, the financial impact of a single loss event. Inherent risk (the data and access at stake) tends to drive magnitude, while controls drive how often losses happen.
- Penetration test (pen test)
- An authorized, simulated attack on a system to find exploitable weaknesses. A pen test summary is a common piece of vendor security evidence.
- Personally Identifiable Information (PII)
- Data that can identify an individual — name, Social Security number, email, and similar. A vendor handling PII carries higher risk and additional regulatory obligations (GDPR, CCPA, HIPAA, and others).
- Remediation
- The work a vendor performs to fix an identified security gap, often tracked against a deadline defined by a service-level agreement (SLA).
- Residual risk
- The risk that remains after a vendor's controls are taken into account — inherent risk reduced by control effectiveness. It reflects how bad things are likely to be given how well the vendor actually protects itself.
- Right to audit
- A contract clause that lets a customer inspect or audit a vendor's security controls, either directly or through an independent assessor.
- Security questionnaire
- A structured set of questions sent to a vendor to assess its security posture — for example the SIG or CAIQ. Increasingly supplemented, or replaced, by reviewing a vendor's existing audited evidence.
- SOC 2
- An AICPA audit report on a service organization's controls across the Trust Services Criteria. A Type 1 report assesses control design at a single point in time; a Type 2 report tests operating effectiveness over a period (typically 3–12 months) and is the stronger signal.
- Subprocessor
- A third party a vendor uses to process data on its behalf — for example their cloud host or an email provider. From your perspective, a vendor's subprocessors are your fourth parties.
- Third-Party Risk Management (TPRM)
- The practice of identifying, assessing, and monitoring the risks introduced by external vendors, suppliers, and partners across the entire relationship lifecycle — from onboarding through offboarding.
- Trust Services Criteria (TSC)
- The five categories a SOC 2 report can cover: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Reading which criteria a report includes tells you what it actually assessed.
- Two-axis risk framework
- A way of viewing vendor risk on two axes at once: how much damage a vendor could do (inherent risk) and how well they protect against it (control posture). It keeps high-impact, weakly-controlled vendors from hiding behind a single score.
- Vendor evidence
- The documents a vendor already produces to demonstrate its security — SOC 2 reports, ISO 27001 certificates, policies, pen test summaries, and prior questionnaires. Reviewing evidence is faster and more reliable than re-asking every question.
- Vendor tiering (criticality)
- Grouping vendors by risk and importance — for example critical, high, medium, or low — so that oversight effort, review depth, and reassessment frequency match each vendor's actual exposure.
- Vulnerability
- In FAIR, the probability that a threat event turns into an actual loss event. More broadly, a weakness in a system or process that an attacker could exploit.
Want to see these in action?
Docubark turns this vocabulary into an AI-native third-party risk program.