Governance, risk and compliance

SmartSuite for the Third-Party Risk Manager

The Third-Party Risk Manager oversees vendor risk across the supplier lifecycle: tiering, due diligence, assessment, scoring, remediation and continuous monitoring. They make sure critical vendors are assessed before onboarding and re-assessed as their posture changes.

What you own

  • Maintain the vendor inventory with criticality tiers
  • Run due diligence and risk assessments at onboarding and renewal
  • Score inherent and residual vendor risk
  • Assign and track remediation of assessment gaps
  • Monitor vendor performance, incidents and posture changes
  • Coordinate with procurement, legal, security and privacy on vendor obligations
  • Report third-party risk exposure to the CRO and committees

Where the role sits

Each name opens that role's page.

Reports to

Chief Risk Officer

Chief Risk Officer

See the role
Enterprise Risk Director

Enterprise Risk Director

See the role

Direct reports

Vendor Risk Analyst

Vendor Risk Analyst

See the role

Works closely with

Procurement Director

Procurement Director

See the role
Legal Operations Manager

Legal Operations Manager

See the role
Information Security Officer

Information Security Officer

See the role
Privacy Program Manager

Privacy Program Manager

See the role
Compliance Manager

Compliance Manager

See the role

GRC processes

The shared GRC process map, highlighted for this role.

Owns

accountable for the process

third-party

Touches

contributes or approves

issues-actions, compliance, risk, reporting, privacy

Depends on

consumes its output

resilience, audit

How SmartSuite helps, suite by suite

Each card is the persona record from that suite's Users tab.

How they use SmartSuite

Risk Assessments

‍Conducts and reviews vendor risk evaluations.

Issue Management

‍Tracks findings and remediation actions.

Risk Reporting

‍Provides leadership with vendor risk posture summaries.

How they use the Procurement Operations suite

Risk tiering

Classifies suppliers by inherent risk and assessment requirements.

Assessment oversight

Reviews questionnaires, evidence, and control requirements for vendors.

Remediation governance

Tracks corrective actions and validates risk mitigation before approval.

How they use SmartSuite

Vendor assessment workflow

Distributes and reviews due diligence questionnaires automatically.
‍

‍

Risk scoring

Calculates risk ratings based on responses and performance metrics.

‍

Remediation tracking

Assigns and tracks corrective actions for vendors with identified gaps.

‍

How they use the Third Party Risk Management suite

Risk assessment automation

Distributes surveys, scores responses, and monitors completion automatically.

Vendor risk scoring

Calculates inherent and residual risk based on maturity, impact, and likelihood.

Remediation tracking

Assigns corrective actions, tracks due dates, and escalates aging issues.

How they use SmartSuite

Suites that serve this role

How SmartSuite supports this role

Third-party risk. Distributes assessment surveys, scores responses and monitors completion automatically, with inherent and residual risk calculated from maturity, impact and likelihood.

Issues and actions. Assigns corrective actions to vendors, tracks due dates and escalates aging issues.

Compliance management. Maps vendor controls, documents and certifications to compliance frameworks.

Risk management. Rolls vendor risk into the enterprise register so supplier exposure is visible with other risk.

Reporting. Reports vendor risk by category, geography, business unit and tier.

Industry reference

NIST SP 800-161 Rev. 1 (supply chain risk management), ISO/IEC 27036 and the Shared Assessments framework describe the programme: a tiered inventory, due diligence before onboarding, assessment on a cycle and continuous monitoring. The 2023 US Interagency Guidance on Third-Party Relationships sets the banking standard, and the EU's DORA (from January 2025) adds contractual and register requirements for ICT providers to financial entities.

Healthcare organisations manage business associates under HIPAA (45 CFR 164.308(b)); public sector programmes follow NIST SP 800-53's supply chain controls and FedRAMP; technology companies answer customer SOC 2 and NIS2 supply-chain expectations.

In their words

Related roles

Chief Risk Officer

Chief Risk Officer

See the role
Enterprise Risk Director

Enterprise Risk Director

See the role

See SmartSuite for your role

Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.