SmartSuite for the Third-Party Risk Manager
The Third-Party Risk Manager oversees vendor risk across the supplier lifecycle: tiering, due diligence, assessment, scoring, remediation and continuous monitoring. They make sure critical vendors are assessed before onboarding and re-assessed as their posture changes.
What you own
- Maintain the vendor inventory with criticality tiers
- Run due diligence and risk assessments at onboarding and renewal
- Score inherent and residual vendor risk
- Assign and track remediation of assessment gaps
- Monitor vendor performance, incidents and posture changes
- Coordinate with procurement, legal, security and privacy on vendor obligations
- Report third-party risk exposure to the CRO and committees
Where the role sits
Each name opens that role's page.
Reports to
Direct reports
Works closely with
GRC processes
The shared GRC process map, highlighted for this role.
Owns
accountable for the process
Touches
contributes or approves
Depends on
consumes its output
How SmartSuite helps, suite by suite
Each card is the persona record from that suite's Users tab.
How they use SmartSuite
Risk Assessments
Conducts and reviews vendor risk evaluations.
Issue Management
Tracks findings and remediation actions.
Risk Reporting
Provides leadership with vendor risk posture summaries.
How they use the Procurement Operations suite
Risk tiering
Classifies suppliers by inherent risk and assessment requirements.
Assessment oversight
Reviews questionnaires, evidence, and control requirements for vendors.
Remediation governance
Tracks corrective actions and validates risk mitigation before approval.
How they use SmartSuite
Vendor assessment workflow
Distributes and reviews due diligence questionnaires automatically.
Risk scoring
Calculates risk ratings based on responses and performance metrics.
Remediation tracking
Assigns and tracks corrective actions for vendors with identified gaps.
How they use the Third Party Risk Management suite
Risk assessment automation
Distributes surveys, scores responses, and monitors completion automatically.
Vendor risk scoring
Calculates inherent and residual risk based on maturity, impact, and likelihood.
Remediation tracking
Assigns corrective actions, tracks due dates, and escalates aging issues.
How they use SmartSuite
Suites that serve this role
Products this role uses most
How SmartSuite supports this role
Third-party risk. Distributes assessment surveys, scores responses and monitors completion automatically, with inherent and residual risk calculated from maturity, impact and likelihood.
Issues and actions. Assigns corrective actions to vendors, tracks due dates and escalates aging issues.
Compliance management. Maps vendor controls, documents and certifications to compliance frameworks.
Risk management. Rolls vendor risk into the enterprise register so supplier exposure is visible with other risk.
Reporting. Reports vendor risk by category, geography, business unit and tier.
Industry reference
NIST SP 800-161 Rev. 1 (supply chain risk management), ISO/IEC 27036 and the Shared Assessments framework describe the programme: a tiered inventory, due diligence before onboarding, assessment on a cycle and continuous monitoring. The 2023 US Interagency Guidance on Third-Party Relationships sets the banking standard, and the EU's DORA (from January 2025) adds contractual and register requirements for ICT providers to financial entities.
Healthcare organisations manage business associates under HIPAA (45 CFR 164.308(b)); public sector programmes follow NIST SP 800-53's supply chain controls and FedRAMP; technology companies answer customer SOC 2 and NIS2 supply-chain expectations.
In their words
Related roles
See SmartSuite for your role
Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.








